Supply Chain Attack
A supply chain attack compromises a trusted vendor, software update, or service provider to reach that supplier's customers — trust as the attack vector.
A supply chain attack compromises an organization indirectly, by first breaching something it trusts: a software vendor, a managed service provider, an open-source library, a hardware supplier, or a business partner. Instead of attacking a hardened target head-on, the attacker poisons an upstream dependency and lets the victim's own trust — automatic updates, signed software, an established vendor relationship — deliver the payload.
How it works
Technical supply chain attacks typically insert malicious code into a legitimate product before it reaches customers: a tampered software update pushed through the vendor's own distribution channel, a poisoned package in a public code repository, or a compromised build pipeline that signs malware with the vendor's certificate. Because the artifact arrives through a trusted, expected route, it sails past controls that would block the same code from a stranger.
The human-layer version is just as common and needs no code at all. Attackers compromise a supplier's mailbox and exploit the commercial relationship — the trusted-thread tactics of vendor email compromise and invoice fraud are supply chain attacks on your payment process. A related move targets the people: impersonating an MSP's help desk, or phishing staff at a small contractor to pivot into their far larger customer. In each case the economics are the same — one upstream breach fans out into dozens or thousands of downstream victims.
How to defend against it
- Inventory your dependencies. You cannot defend a supply chain you have not mapped: know your critical vendors, software components, and who has standing access into your environment.
- Constrain vendor trust. Give suppliers and their software the least privilege that works, segment their access, and monitor it like any other account — trust the relationship, verify the behavior.
- Keep human verification in the loop. Payment changes, unusual requests, and "urgent" messages from partners deserve out-of-band confirmation regardless of how legitimate the thread looks — the playbook in our BEC defense guide applies to every vendor touchpoint.
- Train and rehearse. Teams that handle vendor relationships should see supplier-impersonation pretexts in simulations before attackers provide the live exercise.
Related terms
NOUSEC simulates attacks across 8 channels and turns the results into one number your board can read.
Book a demo