The adversary exploits inherited trust or access across a lifecycle, for example by altering a component before delivery, compromising a provider, or abusing supplier access after deployment.
The attack can involve hardware, firmware, software, hosted services, maintainers, distributors, or build and signing systems. Harm may reach all or selected recipients. Investigation must establish where manipulation occurred, what crossed the trust boundary, and which downstream products, accounts, data, or organizations were affected.
Key points
Attack pathsManipulated dependencies, source or build environments, signed artifacts, updates, hardware, service-provider systems, support channels, and privileged supplier connections can carry downstream impact.
ScopingCompare provenance, signatures, release records, supplier access, deployment history, network and identity activity, and verified versions across affected recipients.
ResponseCoordinate with suppliers and customers, protect essential operations, revoke exposed trust and access, stop unsafe distribution, provide verified recovery material, and address the original compromise.
Important limitationA supplier breach, vulnerable dependency, third-party outage, or unsafe product is not automatically a supply-chain attack. Evidence must show that an adversary used the supply relationship, lifecycle, deliverable, or inherited access as an attack path or means of downstream impact.