Avatier

Third-party or contractor access

Supply chain attack

Also called: MSP compromise

A supply chain attack compromises a trusted supplier, such as a software vendor, managed service provider or open-source package, to reach that supplier's customers. Victims are breached through something they already trust and install, like a software update or a provider's remote access, so one intrusion can spread to many organizations at once.

How it works

The attacker breaks into the supplier's build system, update server, code repository or admin tools and plants malicious code or abuses existing access. Customers then receive the tampered update or connection through normal channels. The attacker chooses which downstream victims to pursue further, using the access and credentials the supplier's product already holds.

A real example

CISA's advisory on the SolarWinds Orion campaign said one initial access vector for an intrusion campaign against government agencies, critical infrastructure and private companies was a supply chain compromise of a DLL in SolarWinds Orion products.

Source: Advanced Persistent Threat Compromise of Government Agencies, Critical Infrastructure, and Private Sector Organizations (AA20-352A) — Cybersecurity and Infrastructure Security Agency (CISA), 2020-12-17

The Identity Attack Ledger holds 9 cited incidents for third-party or contractor access in California breach filings (January 1, 2023 – August 14, 2026), each quoted from its filed letter.

How to stop it

Give supplier software and service accounts only the access they need, review that access on a schedule, and monitor their identities for unusual activity as closely as employee accounts.

Related terms

Threat actors that use it

  • APT29

    Profile with government sources

Sources

  1. Advanced Persistent Threat Compromise of Government Agencies, Critical Infrastructure, and Private Sector Organizations (AA20-352A) — Cybersecurity and Infrastructure Security Agency (CISA), 2020-12-17

Last reviewed Oct 2, 2026