By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
World of SoftwareWorld of SoftwareWorld of Software
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Search
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
Reading: New Research Shows 64% of Third-Party Applications Access Sensitive Data Without Authorization | HackerNoon
Share
Sign In
Notification Show More
Font ResizerAa
World of SoftwareWorld of Software
Font ResizerAa
  • Software
  • Mobile
  • Computing
  • Gadget
  • Gaming
  • Videos
Search
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Have an existing account? Sign In
Follow US
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
World of Software > Computing > New Research Shows 64% of Third-Party Applications Access Sensitive Data Without Authorization | HackerNoon
Computing

New Research Shows 64% of Third-Party Applications Access Sensitive Data Without Authorization | HackerNoon

News Room
Last updated: 2026/01/22 at 8:40 AM
News Room Published 22 January 2026
Share
New Research Shows 64% of Third-Party Applications Access Sensitive Data Without Authorization | HackerNoon
SHARE

Boston, MA, USA, January 21st, 2026, CyberNewsWire/–Reflectiz today announced the release of its 2026 State of Web Exposure Research, revealing a sharp escalation in client‑side risk across global websites, driven primarily by third‑party applications, marketing tools, and unmanaged digital integrations.

According to the new analysis of 4,700 leading websites, 64% of third‑party applications now access sensitive data without legitimate business justification, up from 51% last year — a 25% year‑over‑year spike highlighting a widening governance gap.

The report also exposes a dramatic surge in malicious web activity across critical public‑sector infrastructure. Government websites saw malicious activity rise from 2% to 12.9%, while 1 in 7 Education websites now show active compromise, quadrupling year‑over‑year. Budget constraints and limited manpower were cited as primary obstacles by public‑sector security leaders.

The research identifies several widely used third‑party tools as top drivers of unjustified sensitive‑data exposure, including Google Tag Manager (8%), Shopify (5%), and Facebook Pixel (4%), which were frequently found to be over‑permissioned or deployed without adequate scoping.

“Organizations are granting sensitive‑data access by default rather than exception — and attackers are exploiting that gap,” said VP of Product at Reflectiz, Simon Arazi. “This year’s data shows that marketing teams continue to introduce the majority of third‑party risk, while IT lacks visibility into what’s actually running on the website.”

Key findings include:

  • 64% of apps accessing sensitive data have no valid justification.

  • 47% of applications running in payment frames (checkout environments) are unjustified.

  • Compromised sites connect to 2.7× more external domains, load 2× more trackers, and use recently registered domains 3.8× more often than clean sites.

  • Marketing and Digital departments account for 43% of all third‑party risk

The report also introduces updated Security Leadership Benchmarks, highlighting the very small group of organizations meeting all eight criteria. Only one website — ticketweb.uk — achieved a perfect score across the framework.

The 2026 report includes:

  • Sector‑by‑sector breakdowns of web exposure risk
  • Full list of high‑risk third‑party applications
  • Year‑over‑year industry trends
  • Technical indicators of compromise
  • Best‑practice controls for security and digital teams

The complete 43‑page analysis is available for download:

https://www.reflectiz.com/learning-hub/web-exposure-2026-research/

About Reflectiz

Reflectiz empowers organizations to secure their websites and digital assets against modern web threats. Its award-winning, agentless platform provides continuous visibility into all client-side activity, detecting and prioritizing security, privacy and compliance risks. Reflectiz is trusted by global enterprises across financial services, e-commerce, and healthcare to protect their data, users, and brand reputation.

Contact

VP Marketing

Daniel Sharabi

Reflectiz

[email protected]

:::tip
This story was published as a press release by Cybernewswire under HackerNoon’s Business Blogging Program. Do Your Own Research before making any financial decision.

:::

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Twitter Email Print
Share
What do you think?
Love0
Sad0
Happy0
Sleepy0
Angry0
Dead0
Wink0
Previous Article We Asked Cybersecurity Experts for their Predictions for 2026 We Asked Cybersecurity Experts for their Predictions for 2026
Next Article Venture Capitalists Tap Out On Funding Our Fitness Goals Venture Capitalists Tap Out On Funding Our Fitness Goals
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Stay Connected

248.1k Like
69.1k Follow
134k Pin
54.3k Follow

Latest News

Google Is Hoping 'Personalized' AI Will Make Search Results More Relevant for You
Google Is Hoping 'Personalized' AI Will Make Search Results More Relevant for You
News
Your First Interactive Plot in Python: A Hands-On Plotly Guide | HackerNoon
Your First Interactive Plot in Python: A Hands-On Plotly Guide | HackerNoon
Computing
This Deal Is a Clean Sweep: Shark’s Robot Vacuum Is Now Over 50% Off
This Deal Is a Clean Sweep: Shark’s Robot Vacuum Is Now Over 50% Off
News
January 22, 2026 – Siri AI chatbot, Apple AI pin
January 22, 2026 – Siri AI chatbot, Apple AI pin
News

You Might also Like

Your First Interactive Plot in Python: A Hands-On Plotly Guide | HackerNoon
Computing

Your First Interactive Plot in Python: A Hands-On Plotly Guide | HackerNoon

12 Min Read
Critical GNU InetUtils telnetd Flaw Lets Attackers Bypass Login and Gain Root Access
Computing

Critical GNU InetUtils telnetd Flaw Lets Attackers Bypass Login and Gain Root Access

3 Min Read
Andela bolsters AI talent marketplace with Woven acquisition
Computing

Andela bolsters AI talent marketplace with Woven acquisition

3 Min Read
A Step-by-Step Framework for Stress-Testing Trading Strategies | HackerNoon
Computing

A Step-by-Step Framework for Stress-Testing Trading Strategies | HackerNoon

18 Min Read
//

World of Software is your one-stop website for the latest tech news and updates, follow us now to get the news that matters to you.

Quick Link

  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact

Topics

  • Computing
  • Software
  • Press Release
  • Trending

Sign Up for Our Newsletter

Subscribe to our newsletter to get our newest articles instantly!

World of SoftwareWorld of Software
Follow US
Copyright © All Rights Reserved. World of Software.
Welcome Back!

Sign in to your account

Lost your password?