Supply chain cyber attacks raise costs and risks across corporate networks

Supply chain cyber attacks raise costs and risks across corporate networks
Supply chain attack risks

Third-party breaches are becoming a more prominent route for cyber attackers to penetrate corporate systems and reach multiple victims through a single compromise. The trend is increasing pressure on businesses to tighten oversight of suppliers, software dependencies and access controls across their wider networks.

Highlights

  • Verizon found that in 2024-25, about half of 22,000+ breaches involved third-party compromise, marking a 60 percent increase over the prior year.
  • Hackers targeting supply chains triggered incidents like the 2020 SolarWinds breach affecting 18,000 customers and a 131 million pound loss for Marks and Spencer last year.
  • The UK launched a cyber resilience pledge in July 2024 requiring firms such as M&S and Microsoft UK to enforce Cyber Essentials across supply chains, with mandatory regulations pending.

Rising exposure through suppliers and software

As reported by Financial Times, cyber security specialists say supply chain attacks are gaining ground because infiltrating one trusted provider can open a path into many customer networks. In these attacks, hackers insert malicious code into software or hardware used by a company, allowing them to move downstream to other organisations connected to the same product or service.

Verizon's analysis of more than 22,000 breaches in 2024-25 shows that about half involved third-party compromise, up 60 per cent from the previous year. Nathaniel Jones, vice-president of security and AI strategy at Darktrace, says the appeal for attackers is scale, while Scott McKinnon, chief security officer for the UK and Ireland at Palo Alto Networks, says hackers use these attacks to jump from one organisation to a larger or more prominent target.

Recent incidents highlight the operational and financial damage. In 2020, hackers working for Russia's SVR compromised SolarWinds by placing malicious code in its Orion software, exposing about 18,000 customers and penetrating U.S. government agencies including the Department of Defense and Department of Justice. Last year, the Scattered Spider group infiltrated Marks and Spencer through a third-party supplier, costing the UK retailer 131 million pounds.

Researchers also point to rising risks from open-source software and developer platforms. In May, hacker group TeamPCP attacked GitHub through one of its coding tools, reportedly compromising nearly 4,000 software projects. Aiden Sinnott, principal threat researcher at Sophos, says these platforms are increasingly attractive targets because many companies now rely on open-source software in their environments, and artificial intelligence could further accelerate code analysis and the scale of attacks.

Defensive measures and regulatory response

Cyber security advisers say companies need a deeper understanding of every layer in their supply chains, including third, fourth and fifth-party dependencies. Stuart McKenzie, a managing director at Google-owned Mandiant Consulting, says businesses should create a software bill of materials so they can catalogue components and libraries, track threats and identify whether they are using compromised packages.

Companies are also being urged to limit supplier and software access to only the systems and data required, reducing the chance that a small breach opens the rest of the network. Attack surface monitoring remains important to detect threats early, while businesses should continue checking affected systems after removing malicious software to assess whether attackers gained broader access.

Governments are also tightening requirements. The UK government announced a cyber resilience pledge in April at the CyberUK conference, and the pledge launched on July 7 asks businesses to enforce Cyber Essentials across their supply chains. Companies including M&S and Microsoft UK have signed up, while the cyber security and resilience bill is moving through parliament and is expected to make government guidance on supply chain security mandatory.

Security professionals say awareness is improving, but they warn that attackers continue to adapt. That leaves supply chains as a persistent area of corporate risk, particularly as software ecosystems become more interconnected and businesses depend more heavily on outside providers.

UK CFOs’ rising optimism about artificial intelligence was the focus of our earlier coverage, based on a Deloitte survey showing a larger share of finance leaders expect AI to improve business performance. We also noted that while geopolitical and energy worries have eased, companies remain focused on cost control and competitiveness as they weigh technology-led efficiency gains.

This material may contain third-party opinions, none of the data and information on this webpage constitutes investment advice according to our Disclaimer. While we adhere to strict Editorial Integrity, this post may contain references to products from our partners.
Weekly Top Bonuses
up to $2,500
deposit bonus for all clients
CLAIM BONUS
Your capital is at risk.