AI is the New Service Provider and Attack Vector

Wednesday, July 22nd, 2026

Most businesses now understand the importance of protecting their own systems. They invest in firewalls, endpoint protection, access controls, staff training and monitoring tools. But some of the most damaging data breaches in recent years have started somewhere else: with the suppliers, platforms and third party services that businesses rely on every day.

The breaches involving Lidl and Ticketmaster show how quickly customer data can be exposed even when an organisation’s own systems are not the direct point of compromise. In both cases, risk entered through the wider digital supply chain.

That matters because AI is becoming part of the same supply chain. As AI tools connect to emails, documents, customer records and business systems, they create new opportunities for productivity and new routes for data exposure. In this article, Geraint Williams, Chief Information Security Officer, Modern Networks, looks at what recent third party breaches can teach us about using AI safely.

When a Supplier Becomes the Weak Link

Lidl recently disclosed a data breach affecting customers of its online store in Germany, Belgium and the Netherlands. The breach did not originate within Lidl’s own retail systems. Instead, attackers gained access to customer information held through an external IT service provider.

According to Lidl, the exposed data included customer names, email addresses, telephone numbers, dates of birth and customer identification numbers. Passwords, payment information and bank details were not affected.

The incident shows how organisations can become exposed through suppliers that process or store customer information on their behalf. Customers may never interact with those suppliers directly, but their data still depends on the supplier’s security controls.

For the customers affected, the greatest risk is likely to be from phishing and social engineering attacks. Criminals can use personal information to create convincing but fraudulent emails, text messages and phone calls designed to extract even more personal information.

The Ticketmaster Example

The Ticketmaster incidents show how third party services can create serious security risks for large, trusted brands.

In 2018, Ticketmaster UK disclosed a breach linked to a chatbot service supplied by a third party and embedded within its payment pages. Attackers compromised the external code and captured customer information during transactions.

The Information Commissioner’s Office later fined Ticketmaster £1.25 million, stating that the company had failed to put appropriate measures in place to protect customer data. The breach affected customers across Europe and exposed personal and payment-related information. The company has also been the subject of several class action lawsuits.

Ticketmaster faced another major incident in 2024, when the hacking group ShinyHunters claimed it had stolen a large volume of customer data from Ticketmaster and its parent company, Live Nation. Reports said the data included names, addresses, phone numbers, email addresses, ticket purchase details and some payment-related information.

Different Breaches, Same Lesson

The Lidl and Ticketmaster incidents involved different technologies and different methods of attack.

Lidl’s exposure centred on customer data bring held by an external provider. Ticketmaster’s exposure came through third party code running within a customer transaction process.

Despite those differences, the lessons remain the same. Third party services are part of the attack surface.

Many organisations rely on external providers for customer communications, data storage, cloud hosting, support platforms, analytics tools and countless other business functions. Every one of those relationships introduces a potential security dependency.

Customers usually hold the organisation responsible when something goes wrong, regardless of whether the root cause sits with a supplier

Why AI Changes the Conversation

AI services have quickly become embedded in everyday business processes. Staff use them to write content, analyse data, summarise meetings, review documents and automate routine work.

The challenge is that many AI platforms handle large volumes of business information.

A modern AI assistant may connect to email systems, document libraries, customer relationship management platforms, service desks, collaboration tools and knowledge bases. It often has access to information from multiple departments in one place.

That makes AI more than just another software tool. It becomes a pivotal point where data is gathered, processed and shared.

If an AI provider, its infrastructure or one of its connected services is compromised, sensitive information could be exposed, even if the organisation’s own systems remain secure.

The Unique Risks of AI Platforms

AI introduces several risks that extend beyond traditional supplier relationships.

Data Concentration

AI tools often become central processing points for sensitive information across a business. Customer records, contracts, financial information, meeting notes and internal documents can all pass through the same platform.

Hidden Data Flows

Many users do not fully understand where prompts are stored, how logs are retained, or how information moves between integrated systems.

A simple prompt may involve far more data than the user realises.

Integration Risks

AI services are increasingly connected to other business platforms. If permissions are overly broad, an AI tool may access information well beyond the scope of a single request.

Prompt Injection

Attackers can attempt to manipulate AI systems through malicious content hidden within emails, websites, support tickets or documents. The goal may be to influence the AI’s behaviour or expose information that should remain protected.

Automated Actions

Some AI agents can send emails, update records, create tickets, access files and trigger workflows. If those permissions are misused or compromised, the impact can spread quickly across multiple systems.

Organisations Still Remain Accountable

One point connects Lidl, Ticketmaster and AI related risk. Responsibility does not disappear when data leaves the organisation.

Customers expect businesses to protect their information regardless of whether it sits on an internal server, a cloud platform, a software provider’s environment or an AI service. Regulators take a similar view. Organisations remain responsible for understanding how customer and business data is processed, stored and protected throughout their supplier ecosystem.

Using AI Safely

The answer is not to avoid AI. Most organisations are already seeing real value from AI powered tools.

The challenge is adopting them safely.

Businesses should understand what data AI systems can access, what information users are allowed to submit, how data is retained, and what controls exist around integrations and automated actions.

Access permissions should be kept to the minimum necessary. Supplier assessments should include AI providers in the same way they would include any other critical third party. Incident response plans should also account for AI related scenarios, including data exposure and unauthorised access.

Recommendations

At Modern Networks we strongly recommend that our clients treat AI services as high-risk suppliers when those tools can access business, customer, operational or regulated data. The main risk is not only the AI model itself. It also includes the data the service can reach, the systems it connects to, the actions it can automate and the wider supplier ecosystem behind it.

That means AI adoption should sit within a clear governance and security framework. Clients should know which AI tools are approved, what data staff can use with them and what controls are in place before the tools connect to business systems.

  • Create an AI acceptable use policy and define which AI tools are approved for business use.
  • Block or restrict unsanctioned AI services, risky browser extensions and unmanaged AI applications.
  • Classify data before allowing AI use, with clear rules for customer, employee, financial, legal and security information.
  • Assess AI suppliers before adoption, including how they handle data retention, training, logging, subcontractors, breach notification and data deletion.
  • Review Microsoft 365, SharePoint, Teams, OneDrive and service desk permissions before enabling Copilot-style tools or AI connectors.
  • Apply least privilege to AI integrations, plugins, agents and workflow automations, so tools only access what they need.
  • Monitor AI usage for data leakage, risky uploads, shadow AI and unusual access patterns.
  • Include AI compromise scenarios in incident response plans and tabletop exercises.
  • Update supplier contracts with AI-specific security, privacy, breach notification, audit and data deletion clauses.

These steps help clients benefit from AI while keeping control of sensitive information, supplier risk and regulatory obligations.

The Bigger Picture

The Lidl and Ticketmaster breaches show that cyber security no longer stops at the edge of a company’s own network.

Business data now flows through cloud platforms, software suppliers, outsourced services and AI tools. Each connection creates new opportunities for productivity, but it can also introduce new risks.

AI is becoming another trusted service provider in that ecosystem. As organisations give AI access to more systems and more information, they need to treat it with the same scrutiny they apply to any other critical supplier, and maybe even more.

Security today is about more than protecting internal infrastructure. It is about understanding every organisation, platform and service that handles your data, and making sure they are protected too.

Talk to Modern Networks About AI Security

If you are already using AI tools, or planning to introduce them, now is the time to review how they access, process and protect your data. Modern Networks can help you assess supplier risk, tighten permissions, set clear usage policies and build practical controls around AI adoption.

Contact us to learn how we can help your organisation use AI securely, reduce third party risk and protect sensitive business and customer information.

About the Author

Geraint Williams is Chief Information Security Officer at Modern Networks and a cybersecurity specialist with more than 20 years’ experience in information security, ethical hacking, and digital risk management. He leads the company’s security strategy, helping commercial property organisations navigate an increasingly complex threat landscape. Prior to joining Modern Networks, Geraint held senior positions at GRCI Group and IT Governance, where he played a key role in developing CREST-accredited penetration testing services and delivering cybersecurity compliance programmes. A published author, educator, and regular industry speaker, Geraint is recognised for combining deep technical expertise with practical insights into digital resilience and cyber risk.