Supply Chain Attack

Noun · Security & Infosec · Origin: 2013

Definitions

  1. An attack that targets an organization indirectly by compromising a trusted third-party vendor, library, or update mechanism — hijacking the trust chain rather than attacking the target directly.

    In plain English: Instead of attacking a company directly, hackers compromise a tool or supplier that the company trusts, so the malware sneaks in through the front door.

    Example: "SolarWinds proved that if you compromise the supply chain, every customer becomes your victim."

Etymology

2017
NotPetya spreads via compromised Ukrainian accounting software update
2020
SolarWinds Orion compromise affects 18,000+ organizations
2024
XZ Utils backdoor discovered just before it ships in major Linux distros

Related Terms