Supply Chain Attack
Noun · Security & Infosec · Origin: 2013
Definitions
An attack that targets an organization indirectly by compromising a trusted third-party vendor, library, or update mechanism — hijacking the trust chain rather than attacking the target directly.
In plain English: Instead of attacking a company directly, hackers compromise a tool or supplier that the company trusts, so the malware sneaks in through the front door.
Example: "SolarWinds proved that if you compromise the supply chain, every customer becomes your victim."
Etymology
- 2017
- NotPetya spreads via compromised Ukrainian accounting software update
- 2020
- SolarWinds Orion compromise affects 18,000+ organizations
- 2024
- XZ Utils backdoor discovered just before it ships in major Linux distros