HeadlinesBriefing favicon HeadlinesBriefing.com

Supply Chain Attacks Rise as Weakest Link

Financial Times Companies •
×

Supply chain breaches, where hackers infiltrate a company via a trusted third party, have become an increasingly common attack route. Verizon analysed more than 22,000 breaches in 2024‑25 and found about half involved third‑party compromise – a 60 per cent rise from the prior year.

High‑profile incidents illustrate the danger. In 2020 Russian SVR hackers compromised SolarWinds’ Orion software, exposing roughly 18,000 customers including US defence agencies. Last year the Scattered Spider group hit Marks & Spencer through a supplier, costing the retailer £131mn.

Open‑source platforms add risk. In May Team PCP attacked GitHub, compromising nearly 4,000 software projects. Researchers warn that AI will let attackers analyse code faster, expanding the speed and scale of such attacks.

Experts urge deeper supply‑chain visibility: create a software bill of materials, limit supplier access, and continuously monitor attack surfaces. The UK’s new cyber resilience pledge and forthcoming legislation aim to make supply‑chain security mandatory.