supply chain attack
A supply chain attack is like a criminal sneaking a poisoned ingredient into a trusted food supplier's warehouse so that when you buy your regular groceries, you unknowingly bring the poison into your own home.
A supply chain attack occurs when an adversary compromises a trusted third-party component, software dependency, or update mechanism to gain unauthorized access to a downstream target, bypassing the target's direct perimeter defenses.
A supply chain attack is a vector-based compromise wherein an adversary subverts the integrity of a trusted upstream entity—such as a software dependency, build pipeline, or distribution channel—to inject malicious code or artifacts into a target environment, effectively leveraging the implicit trust established between the vendor and the consumer to facilitate unauthorized access or exfiltration.
evolution
- 1984 · historyKen Thompson's Trusting Trust
Ken Thompson demonstrated how a compiler could be subverted to insert backdoors into software, establishing the theoretical basis for supply chain compromise.
- 2013 · historyTarget Corporation Breach
Attackers gained access to Target's network by compromising the credentials of a third-party HVAC vendor, highlighting the risk of trusted partner access.
- 2020 · historySolarWinds Orion Compromise
State-sponsored actors injected malicious code into the SolarWinds Orion software update mechanism, affecting thousands of downstream government and corporate customers.
- 2021 · historyKaseya VSA Ransomware Attack
The REvil ransomware group exploited a vulnerability in Kaseya's remote management software to push malicious updates to hundreds of managed service providers simultaneously.