Supply Chain Attack
A supply chain attack is a cyberattack that reaches its intended target indirectly, by first compromising a less secure outside vendor, supplier, or partner that has access to the target's data, systems, or software. Rather than attacking an organization head-on, the attacker exploits a trusted relationship to gain entry. Because the compromised element is trusted, such attacks can be difficult to detect.
A supply chain attack is a cyberattack that targets a less secure element within an organization's supply chain, commonly a trusted third-party vendor or supplier of software, services, or hardware, in order to gain access to the primary target's systems or data. The attack typically leverages the trust and access relationships between an organization and its external providers or partners, propagating from the compromised upstream component to downstream victims. Note that definitions in the evidence vary in emphasis, some focusing on software and service providers, others noting the physical integrity of hardware; this entry does not address organizational governance controls or defensive frameworks, which are out of scope here.
Why it matters
Supply chain attacks matter because they exploit the trust relationships that organizations must maintain with vendors, suppliers, and partners in order to operate. As the evidence indicates, an outside provider or partner with access to an organization's data and systems can become the pathway an attacker uses to reach the intended target. This indirect route is significant precisely because the compromised element is trusted, which, as the definition notes, can make such attacks difficult to detect.
For risk and governance professionals, the relevance lies in the fact that an organization's security posture is not solely a function of its own controls. When a less secure element within the supply chain is compromised, the effects can propagate downstream to organizations that had no direct fault in the initial breach. This challenges the boundaries of conventional risk assessments, which often focus on an organization's internal systems rather than the access relationships extended to third parties.
The evidence sources vary in emphasis, with some focusing on software and service providers and at least one noting the physical integrity of hardware. This variation is itself meaningful: the attack surface described under this term is broad, and professionals should be cautious about assuming a single, narrow definition. Defensive frameworks and organizational governance controls for supply chain risk are beyond the scope of this entry.
Who it's relevant to
Inside Supply Chain Attack
Common questions
Answers to the questions practitioners most commonly ask about Supply Chain Attack.