What it is
Vendor sprawl accumulates over time. A vendor onboarded five years ago for a campaign that ended four years ago often remains contracted (a small monthly line item nobody flagged) and still holds an export of the customer list from the original engagement. When that vendor is later breached, the customer data in scope includes the original list, regardless of whether the vendor is still actively used.
Why it matters
Attackers don't distinguish between a vendor's active data flow and its dormant archive. If the vendor is breached, everything they hold is in scope. Firms that rotate CRM platforms, analytics tools, or e-sign vendors every few years are compounding exposure with every rotation unless they explicitly de-provision and demand data deletion from the retired vendor.
How anyone can check it
List every outside service that holds client or staff data and when it was last used.
Remediation direction
Annual vendor inventory that includes historical vendors currently under contract or with live API integrations. For every vendor no longer in active use: revoke API keys, remove OAuth grants, request written data-deletion confirmation, and cancel the contract. Track deletion confirmations in the vendor inventory itself.
LeakTrace does not perform the fix. In an assessment, every finding carries a step-by-step remediation for the firm’s IT provider.