Supply chain cyberattacks have become a significant concern for cybersecurity professionals, as hackers increasingly infiltrate companies through trusted third-party suppliers. These attacks leverage malicious code placed in software or hardware used by a company, granting attackers access to potentially hundreds of other customer and company networks downstream. Scott McKinnon of Palo Alto Networks notes that this strategy allows hackers to "leap from one organization into . . . a larger one, or a more high-profile one," offering a high return on investment for attackers. This rise is evident in recent data: out of over 22,000 breaches analyzed by Verizon in 2024-25, approximately half involved third-party compromise, marking a 60% increase from the previous year. Another report indicates that about 30% of 7,965 cyberattacks in 2024 originated via a third party, doubling from 14.9% of 7,268 attacks in 2023.
Prominent examples highlight the severity of these attacks. In 2020, Russian intelligence agency SVR breached IT company SolarWinds, injecting malicious code into its Orion software. This exposed around 18,000 of SolarWinds' customers, including US government agencies like the Department of Defense and Department of Justice. More recently, in 2023, the British retailer Marks and Spencer incurred costs of £131 million after a breach through a third-party supplier. In May, hacker group TeamPCP attacked GitHub, compromising nearly 4,000 software projects through one of its coding tools. McKinnon emphasizes that while organizations protect their own perimeters, ensuring the same level of protection across the entire supply chain is increasingly challenging. Aiden Sinnott of Sophos adds that the increased reliance on open-source software within company environments has made developer platforms a frequent target.
In response to these growing threats, governments are implementing new measures. The UK government launched a cyber resilience pledge on July 7, urging businesses to enforce Cyber Essentials, a government-backed cybersecurity scheme, across their supply chains. Companies like M&S and Microsoft UK have signed up. Additionally, the UK's Cyber Security and Resilience Bill is advancing through parliament, expected to make government guidance on supply chain security mandatory and bring managed service providers under regulation. In the EU, the NIS2 directive, introduced in 2023, already requires entities in sectors like energy, transport, and banking to manage risks from suppliers. Experts like Stuart McKenzie of Mandiant Consulting recommend that companies meticulously catalog their supply chains using a software bill of materials, continuously monitor for threats, and limit supplier access to only essential systems and data to mitigate the impact of a breach.