Third-party or contractor access
Supply chain attack
Also called: MSP compromise
A supply chain attack compromises a trusted supplier, such as a software vendor, managed service provider or open-source package, to reach that supplier's customers. Victims are breached through something they already trust and install, like a software update or a provider's remote access, so one intrusion can spread to many organizations at once.
How it works
The attacker breaks into the supplier's build system, update server, code repository or admin tools and plants malicious code or abuses existing access. Customers then receive the tampered update or connection through normal channels. The attacker chooses which downstream victims to pursue further, using the access and credentials the supplier's product already holds.
A real example
CISA's advisory on the SolarWinds Orion campaign said one initial access vector for an intrusion campaign against government agencies, critical infrastructure and private companies was a supply chain compromise of a DLL in SolarWinds Orion products.
Source: Advanced Persistent Threat Compromise of Government Agencies, Critical Infrastructure, and Private Sector Organizations (AA20-352A) — Cybersecurity and Infrastructure Security Agency (CISA), 2020-12-17
The Identity Attack Ledger holds 9 cited incidents for third-party or contractor access in California breach filings (January 1, 2023 – August 14, 2026), each quoted from its filed letter.
How to stop it
Give supplier software and service accounts only the access they need, review that access on a schedule, and monitor their identities for unusual activity as closely as employee accounts.
Related terms
Threat actors that use it
- APT29
Profile with government sources
Sources
- Advanced Persistent Threat Compromise of Government Agencies, Critical Infrastructure, and Private Sector Organizations (AA20-352A) — Cybersecurity and Infrastructure Security Agency (CISA), 2020-12-17
Last reviewed Oct 2, 2026