How they happen
Attackers insert malicious code into legitimate software updates, as in the SolarWinds case in 2020. They compromise IT service providers and use their remote management tools to reach customers, as in the 2021 attack on Kaseya, which spread ransomware to up to around 1,500 businesses. They publish poisoned open source packages, or exploit a vulnerability in widely used software, such as the MOVEit file transfer tool in 2023, to steal data from many organisations at the same time.
Why they are effective
Customers trust their suppliers' updates and access by default. A single compromise gives the attacker many victims, and the activity often looks legitimate because it comes through an approved channel.
Reducing the risk
Know which suppliers have access to systems and data, and limit that access to what is necessary. Assess critical suppliers through third party risk management and security questionnaires. Monitor supplier access and remote tools. Keep an inventory of software components with an SBOM where possible. Include supplier compromise scenarios in incident response plans.
Regulation
NIS2 requires entities in scope to address supply chain security, including the security practices of their direct suppliers. DORA sets detailed rules for ICT third party risk in the financial sector, and the Cyber Resilience Act raises security requirements for the products themselves.




