What is a supply-chain compromise?¶
A supply-chain compromise is an incident in which an offender reaches a target through a trusted supplier, product, service, update, dependency or business relationship.
Evidential caution: that the affected organisation was directly attacked first.
What this means¶
The route may involve:
a software vendor;
managed service provider;
cloud platform;
contractor;
code library;
update server;
hardware supplier;
identity provider;
business partner;
shared support tool.
which supplier or service was involved;
what trust relationship existed;
how access was transferred;
which accounts, updates or tools were affected;
when the compromise occurred;
which customers or systems received the malicious activity;
whether the supplier knew.
A trusted product or service may deliver malicious code or access without the provider intending it.
Likewise, a broad supplier compromise may still be used selectively against only some customers.
Relevant evidence may exist in update records, software signatures, provider logs, deployment systems, account activity, support channels and customer-side execution records.
A supply-chain route may affect customers at different times and through different technical paths. One customer may receive a compromised update, another may be reached through provider remote access and a third may remain unaffected. Preserve customer-specific deployment, execution and session evidence rather than assuming uniform compromise across the supplier’s estate.
Where the supplier is itself investigating, obtain the basis for any customer-impact list and preserve versioned updates to that assessment. Early notifications may be incomplete, and later conclusions may depend on telemetry unavailable to the customer. Record what the supplier knew at each stage rather than treating the final account as contemporaneous. The operational takeaway is:
================================================================================
What to check or do next¶
- Investigators should establish:
- Identify the trusted relationship that carried the compromise, and separate supplier victimhood, service delivery and offender control from one another.
Evidential limits¶
It may not have been.
Do not assume that every affected customer was targeted individually.