Overview
A supply chain attack is a cyber-attack that seeks to damage an organization by targeting less secure elements in the supply chain. A supply chain attack can occur in any industry, from the financial sector, oil industry, to a government sector. A supply chain attack can happen in software or hardware. Cybercriminals typically tamper with the manufacturing or distribution of a product by installing malware or hardware-based spying components. Symantec's 2019 Internet Security Threat Report states that supply chain attacks increased by 78 percent in 2018.
A supply chain is a system of activities involved in handling, distributing, manufacturing, and processing goods in order to move resources from a vendor into the hands of the final consumer. A supply chain is a complex network of interconnected players governed by supply and demand.
Although supply chain attack is a broad term without a universally agreed upon definition, in reference to cyber-security, a supply chain attack can involve physically tampering with electronics (computers, ATMs, power systems, factory data networks) in order to install undetectable malware for the purpose of bringing harm to a player further down the supply chain network.
Alternatively, the term can be used to describe attacks exploiting the software supply chain, in which an apparently low-level or unimportant software component used by other software can be used to inject malicious code into the larger software that depends on the component.
9 sources for this section
- 1Supply chain attack — Wikipedia, revision 1375165497
- 2"Supply chain attacks show why you should be wary of third-party providers". CSO Online.
- 3"Next Generation Cyber Attacks Target Oil And Gas SCADA | Pipeline & Gas Journal". www.pipelineandgasjournal.com. Archived from the original on 9 February 2015. Retrieved 27 October 2015.
- 4"Supply chain attacks". docs.microsoft.com. Retrieved 10 April 2022.
- 5"New malware hits ATM and electronic ticketing machines". SC Magazine UK. 28 November 2014. Retrieved 29 October 2015.
- 6"2019 Internet Security Threat Report Executive Summary". Broadcom. Retrieved 23 November 2021.
- 7"Supply Chain Definition | Investopedia". Investopedia. Retrieved 4 November 2015.
- 8Kuchler, Hannah (28 May 2014). "Cyber attackers 'target healthcare and pharma companies'". Financial Times. ISSN 0307-1766. Retrieved 27 October 2015.
- 9Goodin, Dan (24 June 2024). "Backdoor slipped into multiple WordPress plugins in ongoing supply-chain attack". Ars Technica. Retrieved 25 June 2024.
Attack framework
Generally, supply chain attacks on information systems begin with an advanced persistent threat (APT) that determines a member of the supply network with the weakest cyber security in order to affect the target organization. Hackers don't usually directly target a larger entity, such as the United States Government, but instead target the entity's software. The third-party software is often less protected, leading to an easier target. According to an investigation produced by Verizon Enterprise, 92% of the cyber security incidents analyzed in their survey occurred among small firms.
Supply chain networks are considered to be particularly vulnerable due to their multiple interconnected components.
APTs can often gain access to sensitive information by physically tampering with the production of the product. In October 2008, European law-enforcement officials "uncovered a highly sophisticated credit-card fraud ring" that stole customer's account details by using untraceable devices inserted into credit-card readers made in China to gain access to account information and make repeated bank withdrawals and Internet purchases, amounting to an estimated $100 million in losses.
7 sources for this section
- 1Supply chain attack — Wikipedia, revision 1375165497
- 10BRAD D. WILLIAMS (July 01, 2021) US-UK Warn Of New Worldwide Russian Cyberespionage
- 11CERT-UK (2015). "Cyber-security risks in the supply chain" (PDF). Archived from the original (PDF) on 18 February 2015. Retrieved 27 October 2015.
- 12"Software Supply Chain Attacks, a Threat to Global Cybersecurity: SolarWinds' Case Study | IIETA". www.iieta.org. doi:10.18280/ijsse.110505. Retrieved 2 December 2024.
- 13"2014 Data Breach Investigations Report" (PDF). Verizon Enterprise. 2014. Retrieved 27 October 2015.
Risks
The threat of a supply chain attack poses a significant risk to modern day organizations and attacks are not solely limited to the information technology sector; supply chain attacks affect the oil industry, large retailers, the pharmaceutical sector and virtually any industry with a complex supply network.
The Information Security Forum explains that the risk derived from supply chain attacks is due to information sharing with suppliers, it states that "sharing information with suppliers is essential for the supply chain to function, yet it also creates risk... information compromised in the supply chain can be just as damaging as that compromised from within the organization".
While Muhammad Ali Nasir of the National University of Computer and Emerging Sciences, associates the above-mentioned risk with the wider trend of globalization stating "…due to globalization, decentralization, and outsourcing of supply chains, numbers of exposure points have also increased because of the greater number of entities involved and that too are scattered all around the globe… [a] cyber-attack on [a] supply chain is the most destructive way to damage many linked entities at once due to its ripple effect."
5 sources for this section
- 1Supply chain attack — Wikipedia, revision 1375165497
- 3"Next Generation Cyber Attacks Target Oil And Gas SCADA | Pipeline & Gas Journal". www.pipelineandgasjournal.com. Archived from the original on 9 February 2015. Retrieved 27 October 2015.
- 8Kuchler, Hannah (28 May 2014). "Cyber attackers 'target healthcare and pharma companies'". Financial Times. ISSN 0307-1766. Retrieved 27 October 2015.
- 16"Security Form" (PDF).
- 17Nasir, Muhammad Ali (June 2015). "Potential cyber-attacks against global oil supply chain". 2015 International Conference on Cyber Situational Awareness, Data Analytics and Assessment (CyberSA). pp. 1–7. doi:10.1109/CyberSA.2015.7166137. ISBN 978-0-9932-3380-7. S2CID 18999955.
Compiler attacks
Wired reported a connecting thread in recent software supply chain attacks, as of 3 May 2019. These have been surmised to have spread from infected, pirated, popular compilers posted on pirate websites. That is, corrupted versions of Apple's Xcode and Microsoft Visual Studio. (In theory, alternating compilers might detect compiler attacks, when the compiler is the trusted root.)
4 sources for this section
- 1Supply chain attack — Wikipedia, revision 1375165497
- 18Greenberg, Andy (3 May 2019). "A Mysterious Hacker Group Is On a Supply Chain Hijacking Spree". Wired. ISSN 1059-1028. Retrieved 16 July 2019.
- 19Cox, Joseph (18 September 2015). "Hack Brief: Malware Sneaks Into the Chinese iOS App Store". Wired. ISSN 1059-1028. Retrieved 16 July 2019.
- 20"Fully Countering Trusting Trust through Diverse Double-Compiling". dwheeler.com. Retrieved 16 July 2019.
Target
At the end of 2013, Target, a US retailer, was hit by one of the largest data breaches in the history of the retail industry.
Between 27 November and 15 December 2013, Target's American brick-and-mortar stores experienced a data hack. Around 40 million customers' credit and debit cards became susceptible to fraud after malware was introduced into the POS system in over 1,800 stores. The data breach of Target's customer information saw a direct impact on the company's profit, which fell 46 percent in the fourth quarter of 2013.
Six months prior the company began installing a $1.6 million cyber security system. Target had a team of security specialists to monitor its computers constantly. Nonetheless, the supply chain attack circumvented these security measures.
4 sources for this section
- 1Supply chain attack — Wikipedia, revision 1375165497
- 21"Target data breach: Why UK business needs to pay attention". ComputerWeekly. Retrieved 27 October 2015.
- 22Harris, Elizabeth A. (26 February 2014). "Data Breach Hurts Profit at Target". The New York Times. ISSN 0362-4331. Retrieved 27 October 2015.
- 23"Missed Alarms and 40 Million Stolen Credit Card Numbers: How Target Blew It". Bloomberg.com. 17 March 2014. Retrieved 30 October 2015.
The source notesEvidence & further reading23 sources
- Supply chain attack — Wikipedia, revision 1375165497 Wikipedia contributors · Reference source · accessed 2026-09-22
- "Supply chain attacks show why you should be wary of third-party providers". CSO Online. csoonline.com · Reference source · link imported 2026-09-22
- "Next Generation Cyber Attacks Target Oil And Gas SCADA | Pipeline & Gas Journal". www.pipelineandgasjournal.com. Archived from the original on 9 February 2015. Retrieved 27 October 2015. pipelineandgasjournal.com · Reference source · link imported 2026-09-22
- "Supply chain attacks". docs.microsoft.com. Retrieved 10 April 2022. docs.microsoft.com · Reference source · link imported 2026-09-22
- "New malware hits ATM and electronic ticketing machines". SC Magazine UK. 28 November 2014. Retrieved 29 October 2015. scmagazineuk.com · Reference source · link imported 2026-09-22
- "2019 Internet Security Threat Report Executive Summary". Broadcom. Retrieved 23 November 2021. docs.broadcom.com · Reference source · link imported 2026-09-22
- "Supply Chain Definition | Investopedia". Investopedia. Retrieved 4 November 2015. investopedia.com · Reference source · link imported 2026-09-22