# What is a Supply-Chain Attack?

> A supply-chain attack uses a product, service, supplier, development or delivery process, trusted update path, or other upstream dependency as a route to affect downstream users.

- Canonical URL: https://yellowcube.eu/glossary/supply-chain-attack/
- Publisher: Yellow Cube
- Language: en
- Contact: hello@yellowcube.eu

## Content

The adversary exploits inherited trust or access across a lifecycle, for example by altering a component before delivery, compromising a provider, or abusing supplier access after deployment.

The attack can involve hardware, firmware, software, hosted services, maintainers, distributors, or build and signing systems. Harm may reach all or selected recipients. Investigation must establish where manipulation occurred, what crossed the trust boundary, and which downstream products, accounts, data, or organizations were affected.

### Key points

- **Attack paths:** Manipulated dependencies, source or build environments, signed artifacts, updates, hardware, service-provider systems, support channels, and privileged supplier connections can carry downstream impact.
- **Scoping:** Compare provenance, signatures, release records, supplier access, deployment history, network and identity activity, and verified versions across affected recipients.
- **Response:** Coordinate with suppliers and customers, protect essential operations, revoke exposed trust and access, stop unsafe distribution, provide verified recovery material, and address the original compromise.
- **Important limitation:** A supplier breach, vulnerable dependency, third-party outage, or unsafe product is not automatically a supply-chain attack. Evidence must show that an adversary used the supply relationship, lifecycle, deliverable, or inherited access as an attack path or means of downstream impact.

### Related terms

[Supply-chain security](<https://yellowcube.eu/glossary/supply-chain-security/>) · [Third-party cyber risk](<https://yellowcube.eu/glossary/third-party-cyber-risk/>) · [Software supply-chain security](<https://yellowcube.eu/glossary/software-supply-chain-security/>) · [Software bill of materials (SBOM)](<https://yellowcube.eu/glossary/software-bill-of-materials/>) · [Incident response (IR)](<https://yellowcube.eu/glossary/incident-response/>) · [Watering hole attack](<https://yellowcube.eu/glossary/watering-hole-attack/>)

### Sources

[NIST Glossary: Supply Chain Attack](https://csrc.nist.gov/glossary/term/supply_chain_attack) · [MITRE ATT&CK T1195: Supply Chain Compromise](https://attack.mitre.org/techniques/T1195/) · [NIST SP 800-161 Rev. 1 Update 1: Cybersecurity Supply Chain Risk Management](https://csrc.nist.gov/pubs/sp/800/161/r1/upd1/final)

## Attribution and scope

This Markdown representation is generated from the same approved content records as the canonical HTML page. Cite the canonical URL above when referencing this material. Product and service descriptions are informational; confirm project-specific requirements with Yellow Cube.

