supply-chain attack
termsecuritygovernance & risk
Compromising a product or system through something it depends on - a supplier, a standard, a shipment, a maintainer - rather than attacking it directly. The payload can be code, or it can be physical.
The cases in this catalogue sort into seven routes, and only one of them is affected by choosing a different vendor. One: own the manufacturer - Crypto AG sold cipher machines to 120 governments while belonging to two intelligence services. Two: use the maintenance channel - a camera lived inside the Soviet embassy's Xerox 914 because the repairman was the one American allowed in. Three: write a weapon for the product that is simply the standard - Stuxnet targeted Siemens controllers because that is what the plant ran. Four: intercept the shipment - the NSA fitted beacon firmware to network equipment in transit and resealed the boxes. Five: compromise the upstream volunteer - a two-year campaign against a burnt-out maintainer put a backdoor in XZ Utils. Six: compromise the standard itself - Dual_EC_DRBG sat in the NIST recommendation, so every compliant product inherited it. Seven: pass through one vendor to reach another - a retired app from a trading-software company opened 3CX's build servers, whose customers were the target. And the payload need not be information: the 2024 pager detonations carried explosive through an ordinary brand-licensing chain. Defences - provenance, pinning, reproducible builds, audit logs kept where an insider cannot reach them - address some routes and not others, which is why the routes are worth knowing by name.
Also known as: supply-chain attack, software supply chain, dependency attack