Skip to content
Skip to main content
Cyber Incidents & Offender Methods Foundation Explainer

What is a supply-chain compromise?

A supply-chain compromise reaches a target through a trusted supplier, product, update, dependency, service or business relationship. The customer may not have been the first system attacked, and the supplier may itself be a victim.

Identify the trust path

Establish the supplier or service, relationship, affected account, update or tool, transfer mechanism, timing and customer-side execution or session. Evidence may sit in build and update records, signatures, provider logs, deployments, support channels and endpoint processes.

Different customers can be reached by different routes and at different times. Preserve customer-specific delivery and effect rather than assuming uniform compromise.

Track evolving supplier assessments

Obtain the basis and versions of impact lists and notifications. Early information may be incomplete, while later conclusions may rely on telemetry unavailable to customers.

Separate supplier victimhood, service delivery, malicious modification, selective targeting and offender control. A trusted product carrying activity does not prove provider intent.

Key takeaway

Reconstruct the specific trusted relationship that carried access, proving customer impact separately from supplier compromise, knowledge and offender control.

Reference: CIM-255Cyber Incidents & Offender Methods