News alert: Reflectiz study finds most third-party web apps access sensitive data without justification
The report also exposes a dramatic surge in malicious web activity across critical public?sector infrastructure. Government websites saw malicious activity rise from 2% to 12.9%, while 1 in 7 Education websites now show active compromise, quadrupling year-over-year. Budget constraints and limited manpower were cited as primary obstacles by public?sector security leaders.
The research identifies several widely used third-party tools as top drivers of unjustified sensitive-data exposure, including Google Tag Manager (8%), Shopify (5%), and Facebook Pixel (4%), which were frequently found to be over?permissioned or deployed without adequate scoping.
Key findings include:
•64% of apps accessing sensitive data have no valid justification.
•47% of applications running in payment frames (checkout environments) are unjustified.
•Compromised sites connect to 2.7× more external domains, load 2× more trackers, and use recently registered domains 3.8× more often than clean sites.
•Marketing and Digital departments account for 43% of all third-party risk
The 2026 report includes:
•Sector-by-sector breakdowns of web exposure risk
•Full list of high-risk third-party applications
•Year-over-year industry trends
•Technical indicators of compromise
•Best-practice controls for security and digital teams
The complete 43-page analysis is available for download:
https://www.reflectiz.com/learning-hub/web-exposure-2026-research/
About Reflectiz:
Reflectiz empowers organizations to secure their websites and digital assets against modern web threats. Its award-winning, agentless platform provides continuous visibility into all client-side activity, detecting and prioritizing security, privacy and compliance risks. Reflectiz is trusted by global enterprises across financial services, e-commerce, and healthcare to protect their data, users, and brand reputation.
Media contact: Daniel Sharabi, VP Marketing, Reflectiz, daniel.s@reflectiz.com
Editor’s note: This press release was provided by CyberNewswire as part of its press release syndication service. The views and claims expressed belong to the issuing organization
The post News alert: Reflectiz study finds most third-party web apps access sensitive data without justification first appeared on The Last Watchdog.
INDIANAPOLIS, Ind. (WOWO) — A man connected to a fatal shooting from last month has…
More than two years after U.S. Rep. Andy Ogles' phone was seized amid an investigation…
Demolition work continued where the East Wing once stood at the White House on Dec.…
Full spoilers follow for Daredevil: Born Again Season 2, Episode 8, “The Southern Cross," which…
I first got into reading romantasy books after a friend of mine recommended Fourth Wing…
IO Interactive has assured fans that there will be more Hitman adventures, and the team…
This website uses cookies.