Cyber attacks are typically thought of as a direct breach of a company’s immediate security perimeters. But supply chain breaches, where hackers infiltrate a company via a trusted third party, have become an increasingly common attack route and cause for concern among cyber security professionals.
In a supply chain attack, hackers put malicious code into a piece of software or hardware used by a company. This gains them access to many more networks, with potentially hundreds of other customers and companies becoming targets downstream.
“If you pop one, you get access to a thousand,” says Nathaniel Jones, vice-president of security and AI strategy at cyber security group Darktrace.
Supply chain attacks are on the rise. Of more than 22,000 breaches analysed by US mobile operator Verizon in 2024-25, about half involved third-party compromise — a 60 per cent increase from the previous year.
Scott McKinnon, chief security officer for the UK and Ireland at cyber security company Palo Alto Networks, attributed the surge to the value that supply chain attacks can return for hackers. Supply chain attacks enable hackers to “leap from one organisation into . . . a larger one, or a more high-profile one”, he says.
Several prominent cyber attacks in recent years have cast supply chains as the soft underbelly of companies.
In 2020, hackers working for SVR, Russia’s foreign intelligence agency, breached the IT company SolarWinds, placing malicious code in its Orion software product. The attack was significant for its scale and scope, with about 18,000 of SolarWinds’ customers exposed. The hackers infiltrated the networks of US government agencies, including the Department of Defense and Department of Justice. The incident “gives me PTSD”, says Jones at Darktrace.
Supply chain attacks can be costly for companies too. Last year hackers from the group Scattered Spider infiltrated the British retailer Marks and Spencer via a third-party supplier, which cost the UK retailer £131mn.
Supply chains are companies’ “weakest link”, says McKinnon. “Whilst organisations can focus on protecting their own house . . . it’s becoming increasingly challenging to make sure that the same sets of protections and controls . . . are in place completely across all of the supply chains.”
Cyber security researchers say that all sectors and parts of the supply chain are at risk of attacks via this route. However, the increasing use of open-source software platforms has further exposed companies.
In May the hacker group TeamPCP attacked GitHub, the world’s biggest source software development platform that hosts open-source projects, via one of its coding tools. The attack reportedly compromised nearly 4,000 software projects hosted on GitHub.
“We’ve seen more of these kinds of supply chain attacks that focus on developer platforms . . . because so many companies now are using open-source software within their environments,” says Aiden Sinnott, principal threat researcher at the cyber security company Sophos.


Cyber security professionals say that artificial intelligence could be transformative for supply chain attacks, allowing hackers to analyse code more quickly, potentially increasing the speed and scale of attacks.
The risk of a supply chain breach is always what keeps chief information security officers awake at night, says Jones.
Companies need to understand their supply chain in depth, extending security awareness beyond their immediate perimeter, says Stuart McKenzie, a managing director at Google-owned cyber security group Mandiant Consulting.
In 2021 there was a major compromise of the open-source logging library Log4j. Many affected organisations, however, did not know that they had the software installed in their systems, says McKenzie.
He recommends creating a catalogue of supply chains through a software bill of materials: an inventory of all the components and libraries that make up a company’s software.
“If you can catalogue what your supply chain looks like, then you can use threat intelligence to monitor malicious actors,” says McKenzie. This way companies can understand which software packages are being targeted and identify if they are using a compromised component.
Sinnott says that Sophos has seen companies build tools to show not only third-party threats to their supply chains, but also fourth and fifth-party risks.
But companies must also take defensive measures, says Jones. “Assuming that due diligence fails, what backstop do you have to . . . use and understand what’s in your environment?”
Companies should limit the access granted to suppliers and software packages, says McKenzie, giving them access only to the systems and data they need, so that a “small compromise . . . doesn’t provide access to everything”.
Businesses should also be continuously looking for potential cyber threats — a process known as attack surface monitoring — in order to identify a breach early. If a malicious software attack is identified, companies should continue to closely monitor any areas affected by the breach after removing it, to assess whether attackers gained access to their systems, McKenzie says.
Governments are introducing new, more enforceable legislation to help companies defend against sophisticated cyber attacks.
The UK government announced the cyber resilience pledge in April at the CyberUK conference. The pledge, launched on July 7, asks that businesses enforce Cyber Essentials, a government-backed cyber security scheme, across their supply chain. Companies including M&S and Microsoft UK have signed up to the pledge.
Additionally, the cyber security and resilience bill is moving through parliament and is expected to make government guidance on supply chain security mandatory.
As companies become more aware of threats they will get better at defending their supply chains, says McKenzie.
But they must remain vigilant, he warns: “We will just expect to see the attackers evolve and find a new way to target organisations.”
