← All terms

Supply Chain Attack

A supply chain attack compromises a trusted vendor, software update, or service provider to reach that supplier's customers — trust as the attack vector.

A supply chain attack compromises an organization indirectly, by first breaching something it trusts: a software vendor, a managed service provider, an open-source library, a hardware supplier, or a business partner. Instead of attacking a hardened target head-on, the attacker poisons an upstream dependency and lets the victim's own trust — automatic updates, signed software, an established vendor relationship — deliver the payload.

How it works

Technical supply chain attacks typically insert malicious code into a legitimate product before it reaches customers: a tampered software update pushed through the vendor's own distribution channel, a poisoned package in a public code repository, or a compromised build pipeline that signs malware with the vendor's certificate. Because the artifact arrives through a trusted, expected route, it sails past controls that would block the same code from a stranger.

The human-layer version is just as common and needs no code at all. Attackers compromise a supplier's mailbox and exploit the commercial relationship — the trusted-thread tactics of vendor email compromise and invoice fraud are supply chain attacks on your payment process. A related move targets the people: impersonating an MSP's help desk, or phishing staff at a small contractor to pivot into their far larger customer. In each case the economics are the same — one upstream breach fans out into dozens or thousands of downstream victims.

How to defend against it

  • Inventory your dependencies. You cannot defend a supply chain you have not mapped: know your critical vendors, software components, and who has standing access into your environment.
  • Constrain vendor trust. Give suppliers and their software the least privilege that works, segment their access, and monitor it like any other account — trust the relationship, verify the behavior.
  • Keep human verification in the loop. Payment changes, unusual requests, and "urgent" messages from partners deserve out-of-band confirmation regardless of how legitimate the thread looks — the playbook in our BEC defense guide applies to every vendor touchpoint.
  • Train and rehearse. Teams that handle vendor relationships should see supplier-impersonation pretexts in simulations before attackers provide the live exercise.

Related terms

Vendor Email Compromise (VEC)Vendor email compromise hijacks a supplier's real email account or thread to redirect customer payments — BEC's hardest-to-spot variant.Watering Hole AttackA watering hole attack compromises a website a target group already trusts and visits, infecting visitors instead of approaching them directly.Insider ThreatAn insider threat is the risk that employees, contractors, or partners with legitimate access cause harm — maliciously, negligently, or after being compromised.SpoofingSpoofing is the falsification of an identity signal — sender address, caller ID, domain, or website — to make an attack appear to come from a trusted source.
See your Human Risk Score

NOUSEC simulates attacks across 8 channels and turns the results into one number your board can read.

Book a demo