Daspren LogoDaspren
Solution
PartenairesContact
Planifiez une démo
Daspren LogoDaspren
  1. Accueil
  2. Blog
  3. Supply Chain Security Risks
Daspren LogoDaspren

Révolutionner la cybersécurité grâce à une technologie centrée sur les données.

1179 Av. des Champs Blancs, 35510 Cesson-Sévigné
LinkedIn

Produit

  • Solution

Cas d'utilisation

  • Cartographie
  • Classification
  • Contrôle
  • Prévention des ransomwares
  • Prévention de l'exfiltration de données
  • DSPM
  • DLP
  • Protection Zero-day

Secteurs

  • Santé
  • Finance
  • Logistique
  • Gouvernement
  • PME

Ressources

  • Blog
  • Événements
  • Glossaire

Entreprise

  • L'entreprise
  • Carrières
  • Partenaires
  • Contact
© 2026 Daspren. Tous droits réservés.
Politique de confidentialitéConditions d'utilisationPolitique de cookies
Supply Chain Attacks: When Trust Becomes an Entry Point

Supply Chain Attacks: When Trust Becomes an Entry Point

7/24/2026 • 5 min read

CybersecurityThreat Intelligence

Supply chain attacks do not break in—they walk through the front door.

By compromising a trusted vendor, software library, or application, attackers gain legitimate credentials and valid access to their target's environment. That is precisely what makes these attacks so difficult to detect: traditional security defenses are designed to identify abnormal behavior, while malicious activity in a supply chain attack often follows entirely legitimate and authorized paths.


What Is a Supply Chain Attack?

Rather than attacking an organization directly, adversaries compromise a link in its ecosystem—such as a software vendor, service provider, open-source library, or software update mechanism—to reach the final target through a channel that is considered trusted.

> Infographic illustrating the stages of a supply chain attack, from compromising a vendor to exfiltrating victims' data.


An Attack Model That Continues to Gain Momentum

In 2024, breaches involving third parties accounted for 30% of all incidents documented by Verizon, up from 15% the previous year (DBIR 2025, based on more than 22,000 analyzed incidents). This sharp increase reflects cybercriminals' growing interest in vendors, service providers, and business partners. By compromising a single intermediary connected to multiple customers, attackers can dramatically amplify the impact of a single intrusion.

Supply chain attacks are not a new category of cyberattack. Rather, they are an established technique that has become increasingly profitable as organizations rely on ever-growing networks of interconnected services. The more deeply a supplier is integrated into its customers' environments, the more attractive it becomes as a target.

Key takeaway: A supply chain attack does not only compromise a vendor. It turns every trusted relationship into a potential pathway to an organization's systems and sensitive data.


Three Attacks, One Common Lesson

SolarWinds: When Software Updates Become the Attack Vector

In September 2019, operators linked to Russian intelligence compromised the development environment of SolarWinds, the company behind the Orion network monitoring platform used by thousands of organizations worldwide.

Over several months, the attackers studied the build environment before discreetly inserting a backdoor known as SUNBURST into legitimate software updates. Beginning in March 2020, these updates were distributed normally to approximately 18,000 customers, who installed them without suspicion.

Confirmed victims included nine U.S. federal agencies—including the Treasury Department, the Department of State, and the Department of Homeland Security—as well as Microsoft, Intel, Cisco, and Deloitte (CISA). The compromise remained undetected for more than eight months until FireEye uncovered it in December 2020.

Target: When a Service Provider Becomes the Front Door

In 2013, attackers did not target Target directly. Instead, they compromised the credentials of Fazio Mechanical Services, an HVAC contractor responsible for maintaining the retailer's heating and cooling systems.

Using these legitimate credentials, they gained access to Target's internal network, moved laterally to point-of-sale systems, and deployed the BlackPOS malware. Over several weeks, the malware harvested payment card data before exfiltrating it.

The breach resulted in the theft of nearly 40 million payment card records and the personal information of approximately 70 million customers.

British Airways: When the Weakest Link Is a Third Party

In 2023, the Cl0p ransomware group exploited a zero-day vulnerability in MOVEit Transfer, a managed file transfer solution used by thousands of organizations.

British Airways itself was not directly compromised. Instead, attackers breached the systems of its payroll provider Zellis, a MOVEit customer. Through this compromise, cybercriminals gained access to employee data belonging to several major UK organizations, including British Airways, the BBC, and Boots.

Key takeaway: The realistic objective is not to guarantee that no supplier will ever be compromised. The goal is to ensure that a supplier compromise does not automatically grant access to all of an organization's sensitive data.


What Vendor Risk Management Cannot Prevent

Security questionnaires, contractual audits, dependency inventories, and Software Bills of Materials (SBOMs) remain essential. They significantly reduce risk—but they cannot eliminate it.

The three incidents above illustrate this reality from different angles.

  • SolarWinds was a well-established and widely trusted software vendor.
  • Target's contractor required legitimate access to perform its operational duties.
  • Zellis legitimately processed payroll data and relied on MOVEit as part of its normal business operations.

None of these organizations would have appeared, on paper, to be suppliers that should automatically fail a standard vendor assessment.

The challenge therefore extends beyond evaluating a vendor's security posture or reputation. It also concerns what that vendor is able to access, process, or transfer if it is eventually compromised.


Visibility and Control: The Value of Data-Centric Security

Traditional supply chain security measures primarily focus on preventing compromise before it occurs.

Data-centric security approaches address a different challenge: they limit what attackers can discover, access, copy, or exfiltrate even after they have obtained legitimate access.

DSPM: Understanding Data Exposure

Preventive controls aim to reduce the likelihood of a supplier or third-party account being compromised. However, they often provide only limited visibility into the sensitive data that could ultimately be exposed.

Data Security Posture Management (DSPM) complements these controls by helping organizations identify where sensitive data resides, who has access to it, and under which conditions.

This visibility makes it easier to assess data exposure both proactively and after a security incident.

DLP: Monitoring How Data Is Used

Complementing DSPM, Data Loss Prevention (DLP) focuses on how data is actually being used.

DLP solutions can detect unusual transfers, downloads, or access patterns—even when they originate from legitimate accounts or authorized applications.

As a result, DLP provides an additional monitoring layer that helps reduce the risk of data exfiltration and inappropriate use of sensitive information.


Assess Your Exposure Before an Incident Occurs

Consider the following questions to evaluate how much control your organization truly has over its data supply chain:

  • Have we identified every vendor and software component that handles sensitive data, including our suppliers' subcontractors?
  • Do we know exactly which categories of data each third party can access, and are those permissions still justified?
  • Are copies of sensitive data stored by suppliers identified, limited, and governed by clear retention policies?
  • Can we detect unusual downloads or exports performed using legitimate user accounts?
  • Can we prevent sensitive documents from being transferred to unauthorized destinations?
  • If a supplier is compromised, can we quickly determine which data was exposed, who accessed it, and for how long?

Conclusion

Preventive security measures remain essential, but they address only part of the problem.

Vendor assessments, SBOMs, dependency management, and secure update policies all strengthen supply chain security without eliminating risk entirely.

When one link in the supply chain is inevitably compromised, an organization's ability to maintain visibility and control over the sensitive data entrusted to third parties becomes the decisive factor in limiting the impact of the breach.

This evolution of the threat landscape also challenges the very notion of implicit trust. Supply chain attacks demonstrate that a trusted vendor, a digitally signed software update, or an authorized application can all become vectors for compromise. In this context, Zero Trust is built on a simple principle: no identity, device, application, or connection should be trusted by default. Every access request is continuously verified, evaluated in context, and restricted to the minimum level of access required.

← Previous article
Healthcare Cybersecurity: Balancing Patient Care and Security Requirements