Supply chain attack
A type of attack in which the attacker reaches the real target not directly but through software, a library, a service provider or a supplier that the target uses.
- 01
Why it matters
An update you trust, or an agency's admin access, can be an easier way in for an attacker than your own front door. Compromising a single supplier can affect hundreds of customers at once. Limiting suppliers' access and keeping an inventory of the components you use reduce the risk.
- 02
Example
The service hosting a popular script library used on a site is compromised, and code that collects card details is added to the library. Sites that serve the library from their own server, with a pinned version and an integrity check, are not affected.
- 03
Common mistake
Giving suppliers broad, open-ended access and never reviewing it. When a project ends, agency and consultant access should be closed, and what remains limited to the least privilege.
- 04
Related terms
Related services and guides
Let's talk about your project.
Tell us what you need; we will define the scope together.