Supply chain attacks: lessons from major incidents
SolarWinds, Kaseya, MOVEit, 3CX, XZ Utils, Collins Aerospace: how attackers get in through your suppliers, and what each incident teaches about protecting yourself.
· 12 min read
Supplier
Customer 1
Customer 2
Customer 3
A supply chain attack compromises a supplier (software vendor, managed service provider, service provider, open source component) in order to reach its customers. The attacker uses a trusted channel, an official update or administrative access, and hits dozens or thousands of organisations at once. Nine documented incidents, from NotPetya to Shai-Hulud, show how these attacks work and how to reduce their reach. They are one of the main reasons for third-party risk management.
01
What is a supply chain attack?
ENISA, the European Union Agency for Cybersecurity, defines a supply chain attack as a two-stage operation: the attacker first compromises one or more suppliers, then uses that access to reach the final target, the customer. The supplier is not the target: it is the stepping stone.
Three reasons explain why this approach works so well:
Leverage: compromising a vendor or an MSP gives access to all its customers at once.
Trust: an update signed by the vendor, a connection from the MSP's tool or an exchange with a usual provider trigger no alert.
The blind spot: most organisations do not know precisely which suppliers access what, let alone who their suppliers' suppliers are.
02
Why supply chain attacks are increasing
In its 2021 study of 24 attacks, ENISA found that 66% targeted the supplier's code and that, in 58% of cases, the final aim was to access customer data, including personal data and intellectual property. It expected these attacks to quadruple within a year.
The calculation is simple for an attacker: rather than breaking through the defences of a thousand companies, it goes around a single, less protected one that already has legitimate access to all the others. Business software vendors, MSPs serving small businesses and platforms that pool data for an entire sector are therefore prime targets.
More recent data confirms the trend. Verizon's 2025 DBIR finds that third-party involvement in breaches doubled, to 30%. In France, ANSSI notes in its 2025 cyber threat overview that some data exfiltrations follow the compromise of a service provider, devotes part of its analysis to the targeting of subcontractors as a compromise vector, and cites the attack on Collins Aerospace that disrupted several European airports. It even mentions a new form: the compromise of an artificial intelligence system that generates code.
“
The supplier is not the target: it is the stepping stone.
03
Types of supply chain attack
Five ways in through a supplier
Type
Mechanism
Examples
Compromised software vendor
Malicious code inserted into the product or its update, often signed by the vendor.
NotPetya, SolarWinds, 3CX
MSPs and admin tools
The attacker uses the provider's access or remote management tool to reach its customers.
Kaseya VSA
Provider processing your data
The provider, or software it uses, is compromised; your data goes with its own.
MOVEit, Viamedis and Almerys, Collins Aerospace
Open source library
A free component is trojanised by a malicious contributor or through stolen maintainer accounts.
XZ Utils, Shai-Hulud
Hardware and firmware
A device or its firmware is modified before delivery or during maintenance.
Risk described by NIST (SP 800-161), rarely documented publicly
Hardware attacks are harder to document publicly than the others, but NIST SP 800-161 on supply chain risk management treats them on an equal footing: component provenance, integrity on delivery, third-party maintenance.
04
Nine supply chain attacks that made their mark
Trojanised vendors: NotPetya, SolarWinds, 3CX
On 27 June 2017, NotPetya spread through a trojanised update of M.E.Doc, a Ukrainian accounting package whose backdoor ESET analysed. This local software was enough to paralyse global groups: Saint-Gobain put the impact at about €220 million in sales and €65 million in operating income for the first half of 2017 alone. In December 2020, SolarWinds revealed that updates of its Orion software released between March and June 2020 contained malicious code; the vendor estimated that fewer than 18,000 customers were affected. In March 2023, the 3CX phone app was trojanised in turn, and Mandiant found that the vendor had itself been compromised by another trojanised application, X_Trader: the first “cascading” attack observed.
A managed service tool: Kaseya
On 2 July 2021, the REvil group exploited a vulnerability in Kaseya VSA, the remote management tool used by many MSPs. According to the vendor, fewer than 60 direct customers and fewer than 1,500 downstream businesses were encrypted, and a $70 million ransom was demanded for a universal decryptor.
Providers that concentrate data: MOVEit, Viamedis and Almerys, Collins Aerospace
From 27 May 2023, the Cl0p group exploited an unknown flaw in the MOVEit Transfer file transfer software. Emsisoft counted 2,773 organisations and nearly 96 million people affected, often through a payroll or insurance provider using the software. In France, in late January 2024, two third-party payment operators for health insurers, Viamedis and Almerys, were attacked: more than 33 million people were affected according to the CNIL. On 19 September 2025, ransomware at Collins Aerospace, supplier of the MUSE check-in software, disrupted Heathrow, Brussels and Berlin.
Open source: XZ Utils, Shai-Hulud
On 29 March 2024, a backdoor was discovered in the XZ Utils compression library from version 5.6.0: it targeted the SSH service of many Linux distributions, with a severity score of 10 out of 10, and was caught before reaching most stable releases. In September 2025, the Shai-Hulud worm stole developer tokens and republished trojanised npm packages: more than 500 packages compromised according to CISA.
The timeline below covers each incident, with its vector, impact and lesson.
Timeline · 9 incidents
Software vendor
Managed service tool
Service provider
Open source
Pick an incident
201720182019202020212022202320242025
NotPetya
27 June 2017 · Software vendor
Vector
A trojanised update of M.E.Doc, an accounting software package widely used in Ukraine.
Impact
Worldwide data destruction. Saint-Gobain put the impact at about €220M in sales and €65M in operating income for the first half of 2017.
Lesson
A local business application in a single subsidiary can open the door to an entire group: segment.
SolarWinds
December 2020 · Software vendor
Vector
Malicious code inserted into updates of the Orion monitoring software released between March and June 2020.
Impact
According to SolarWinds, fewer than 18,000 customers may have installed a compromised version; a few were then targeted in depth.
Lesson
An update signed by the vendor is no proof of safety: monitor the behaviour of your most privileged tools.
Kaseya VSA
2 July 2021 · Managed service tool
Vector
The REvil group exploits a vulnerability in the VSA remote management tool installed at managed service providers.
Impact
Fewer than 60 direct customers, mostly MSPs, and fewer than 1,500 downstream businesses encrypted; a $70M ransom demanded.
Lesson
The tool that manages all your endpoints is your single point of failure: limit its rights and monitor it.
3CX
March 2023 · Software vendor
Vector
A trojanised 3CX phone app, after a vendor workstation was compromised by an X_Trader package that was itself trojanised.
Impact
The first cascading attack observed by Mandiant: one supply chain compromise led to another.
Lesson
Your supplier's supplier matters, and one outdated application on a workstation is enough.
MOVEit Transfer
From 27 May 2023 · Service provider
Vector
Cl0p exploits an unknown SQL injection (CVE-2023-34362) in a file transfer software.
Impact
2,773 organisations and nearly 96 million people counted by Emsisoft, often hit through a provider (payroll, insurance, training).
Lesson
Your data is exposed to your providers' software: ask which, and where.
Viamedis and Almerys
Late January 2024 · Service provider
Vector
A cyberattack on two third-party payment operators handling flows for many French health insurers.
Impact
More than 33 million people affected according to the CNIL: civil status, social security number, insurer and cover.
Lesson
A few shared providers concentrate the data of an entire sector.
XZ Utils
29 March 2024 · Open source
Vector
A backdoor slipped by a contributor into the xz compression library, from version 5.6.0, targeting the SSH service.
Impact
Maximum severity (CVSS 10), but discovered by chance before reaching most stable distributions.
Lesson
A free component maintained by one or two people can be targeted for years.
Collins Aerospace
19 September 2025 · Service provider
Vector
Ransomware at the supplier of the MUSE check-in and bag-drop software.
Impact
Heathrow, Brussels and Berlin disrupted for several days; ENISA confirmed ransomware at this provider.
Lesson
A dependency shared by several airports becomes a systemic risk: plan for degraded mode.
Shai-Hulud
September 2025 · Open source
Vector
A worm that steals developer tokens and republishes trojanised npm packages, spreading on its own.
Impact
More than 500 packages compromised according to CISA.
Lesson
Pin your dependencies, protect developer accounts with strong authentication.
05
What these incidents teach
Signing does not protect you from the vendor itself. SolarWinds and 3CX shipped signed versions: only monitoring software behaviour can spot the anomaly.
Admin tools are prime targets. Kaseya showed it: the tool that runs every endpoint must have limited rights and be monitored like an administrator account.
Your data lives at your providers. MOVEit and Viamedis-Almerys are reminders that a leak can happen without your own system being touched.
Fourth parties matter. 3CX was compromised through another vendor's software; MOVEit reached organisations through their providers.
Concentration creates systemic risk. A few payment operators or a single check-in system are enough to hit an entire sector.
Continuity makes the difference. Airports that could switch to manual check-in limited the disruption: that is the role of a business continuity plan.
06
How to protect yourself against a supply chain attack
No organisation can audit all its suppliers. The aim is to reduce the likelihood of a compromise and, above all, its reach.
Know and assess your suppliers
Inventory your suppliers, the access and data you entrust to them, rank them by criticality, and assess the most critical with an evidence-based supplier security questionnaire. Build these scenarios into your risk analysis: the EBIOS Risk Manager method devotes a workshop to the ecosystem and the stakeholders an attacker can go through.
Govern provider access
ANSSI's outsourcing guide stresses remote interventions: multi-factor authentication, named accounts, access through a gateway or bastion controlled by your teams, need-to-know rights, logging and regular review. These requirements go into the contract, ideally in a security assurance plan.
Control updates and components
Roll out updates in waves, starting with a test environment.
Protect your developers' accounts and publishing pipelines with phishing-resistant authentication.
Detect, contain, keep running
Segment the network so a compromised tool does not see everything, filter outbound traffic, monitor abnormal behaviour of admin software. Involve your critical suppliers in your incident response plan and exercises, and plan a degraded mode for every essential service. The diagram below shows how these measures reduce the reach of the same compromise.
Responding when a supplier announces a compromise
The day a vendor or provider publishes a security advisory, every hour counts. Prepare the sequence in advance:
Assess your exposure: do you use the product or service, which version, on which systems, with what data? An up-to-date inventory answers in minutes rather than days.
Cut or restrict the affected supplier's access, suspend its automatic updates and isolate the servers hosting its tool.
Hunt for traces of exploitation using the indicators published by the vendor, national CERTs or ENISA, over the whole exposure period and not just since the announcement.
Notify where required: the data protection authority within 72 hours for a personal data breach, the national cybersecurity or sector authority under your obligations.
Review the relationship: require an incident report from the supplier, reassess its criticality and commitments, and decide whether to continue, tighten oversight or exit.
Diagram · Propagation
1. Supplier compromised
2. Spread through the update or remote access
3. Effect on each customer
Customer A : No measures → Compromised ; With measures → Blocked (MFA and bastion)
Customer B : No measures → Compromised ; With measures → Contained (Detection, fast isolation)
Customer C : No measures → Compromised ; With measures → Blocked (Update tested before rollout)
Customer D : No measures → Compromised ; With measures → Blocked (Outbound traffic filtered)
Customer E : No measures → Compromised ; With measures → Contained (Network segmentation)
Customer F : No measures → Compromised ; With measures → Blocked (Least privilege for the tool)
Teaching illustration: no single measure guarantees an attack is stopped, but each one reduces its reach.
07
What NIS 2, DORA and the Cyber Resilience Act say
European regulation has taken this risk on board. NIS 2 makes supply chain security a minimum measure (Article 21), and DORA requires the financial sector to keep a register of its ICT providers, contract clauses and exit strategies: we detail these obligations in our article on third-party risk, NIS 2 and DORA. The Cyber Resilience Act (Regulation (EU) 2024/2847) acts upstream, on manufacturers of products with digital elements: since 11 September 2026 they must report actively exploited vulnerabilities, and from 11 December 2027 all requirements will apply, including documenting the components of their products.
To manage this risk day to day, Phinasoft brings together risk analysis and assessment of your providers on a dedicated portal: questionnaires based on your requirements, feedback on non-conformities, indicators and history for each provider, and export of requirements to your security assurance plans. You can see a demo.
Summary
01
One to many
A supply chain attack compromises a supplier to reach its customers: a single entry point, hundreds or thousands of victims.
02
Always trust
Signed update, managed service tool, data processor, open source library: the attacker uses a channel the victim already trusts.
03
Reducing the reach
Inventory your suppliers, limit and monitor their access, verify updates, know your components and prepare for degraded mode.
Frequently asked questions
What is a supply chain attack?
It is an attack that first compromises a supplier, software vendor, service provider or component, in order to reach its customers, who are the real target. ENISA describes it as a two-stage attack. It is dangerous because it goes through a trusted channel: an official update, managed service access, a hosted service.
What is the best-known example of a supply chain attack?
SolarWinds, revealed in December 2020, is the most cited: updates of the Orion monitoring software released between March and June 2020 contained malicious code, and the vendor estimated that fewer than 18,000 customers may have installed the compromised version. NotPetya in 2017, Kaseya in 2021 and MOVEit in 2023 are also textbook cases.
How do you protect yourself against a supply chain attack?
Inventory and rank your suppliers, assess the most critical ones with evidence, write requirements into contracts, enforce strong authentication, a bastion and least privilege for their access, test updates before rolling them out widely, keep an inventory of your software components and prepare to operate in degraded mode.
What is the difference between a supply chain attack and third-party risk?
Third-party risk covers everything a supplier can cause you: outage, bankruptcy, data leak, non-compliance. A supply chain attack is its malicious form, where an attacker deliberately uses the supplier as a stepping stone. Third-party risk management is therefore one of the main defences against these attacks.
Is open source a supply chain risk?
Yes, like any component you did not write. The XZ Utils case in 2024 and Shai-Hulud in 2025 show that an attacker can trojanise a widely used library. The answer is not to give up open source, but to inventory your dependencies, pin their versions and watch for alerts.
Does NIS 2 require addressing supply chain risk?
Yes. Article 21 of NIS 2 lists supply chain security among the minimum measures for essential and important entities, taking into account each direct supplier's vulnerabilities and practices. DORA goes further for the financial sector, and the Cyber Resilience Act places new obligations on manufacturers of digital products.