---
title: The Growth of Third-Party Software Supply Chain Cyber Attacks
description: An in-depth look at social engineering testing by Mitnick Security.
image: https://www.mitnicksecurity.com/hubfs/Understand%20the%20Growth%20of%20Software%20Supply%20Chain%20Attacks.jpg
---

# The Growth of Third-Party Software Supply Chain Cyber Attacks

[Supply Chain](https://www.mitnicksecurity.com/blog/tag/supply-chain), [Cyber Attack](https://www.mitnicksecurity.com/blog/tag/cyber-attack)

[ Mitnick Security| ](https://www.mitnicksecurity.com/blog/author/mitnick-security)  07.03.2024| 3 MIN READ TIME

In the past several years, we've seen an uptick in cyber threat activity. In fact, many cyber-espionage groups, such as [Dragonfly](https://www.ncsc.gov.uk/collection/supply-chain-security/third-party-software-providers), are becoming especially bold when attacking an organization’s weakest links: their third-party supply chains.  

Let’s discuss why supply chain cyber attacks are gaining momentum so you can prepare for and prevent a similar exploit against your company.

 

## Why Are Third-Party Supply Chain Attacks Increasing?

The software supply chain has many touch points, from app development to product deployment. This includes any open-source code, your development team’s contributions, and — of course — any components provided by third parties. 

First, let’s be clear: threat actors will look for and target any weak points in your software supply chain. Even if you already have a cybersecurity plan in place for your organization, your third-party components may not have the same protection, which could result in a [data breach](https://www.mitnicksecurity.com/blog/data-breach-recovery) if left unchecked. The top reasons why third-party supply chain attacks are increasing, as well as supply chain cyber attacks in general, include:

### Amplification

Businesses everywhere trust third-party solutions to make operations easier. From the reporting tools you use to quantify your metrics to the vendor who manages your cybersecurity needs, we all trust software solutions or service providers and share a certain level of access to our data with them.

Threat actors recognize this — and have been increasingly targeting suppliers in digital attacks, knowing they can gain access to a deep chain of associated companies with just one breach. By compromising the right supplier, a bad actor amplifies their reach, not only gaining access to their target’s data but also the partner data they possess. 

### Deep, High-Profile Connections

Not only can threat actors access more companies than the single supplier they target, but they can also often gain access to higher-payout victims. While the bad actors may not be able to compromise the security defenses of these highly protected organizations on their own, supply chain attacks mean they really don’t need to.

Instead, threat actors only need to find a way in through an organization’s partner and capitalize on the trust that the company has in its current partners to launch secondary cyber attacks.

### Attributional Ambiguity

Threat actors continue to find new and creative ways to wipe their digital footprints and cover their attacks. Incident responders can often trace the indicator of compromise (IOC) of a supply chain attack and see the path the bad actors took to amplify their reach, but it can be hard to attribute the threat actor behind the breach. 

While malicious code can be analyzed and reviewed for signs of technique based on previously investigated cyber attacks, sophisticated bad actors know how to throw investigators off track.

 

## Recent Examples of Supply Chain Attacks

While there have been a number of supply chain attacks over the past several years, here are two examples that stand out:

### Change Healthcare

Change Healthcare is a medical tech company and operates the largest clearinghouse in the U.S regarding insurance billing and payment.

On February 21, 2024, [Change Healthcare had to shut down](https://www.techtarget.com/whatis/feature/The-Change-Healthcare-attack-Explaining-how-it-happened) its services due to a supply chain attack caused by the infamous hacker group, BlackCat. The group was able to compromise credentials and access Change Healthcare’s private portal. The downtime caused many businesses and customers to experience detrimental consequences, including the inability to bill insurance providers and collect revenue. Unfortunately, Change Healthcare has suffered the [true cost of the data breach](https://www.mitnicksecurity.com/blog/cost-of-a-data-breach) in that they are still ([as of June 2024](https://www.hipaajournal.com/change-healthcare-responding-to-cyberattack/#:~:text=UHG%20said%20pharmacy%20services%20and,functionality%20has%20now%20been%20restored.)) not operating at full capacity.  

### Toyota

In December of 2023, [Toyota Financial Services in Germany](https://www.iotworldtoday.com/security/toyota-ransomware-attack-compromised-personal-data) was shut down after being hit with a [ransomware attack](https://www.mitnicksecurity.com/blog/ransomware-attacks).

The ransomware gang, known as Medusa, compromised sensitive data and held it for an $8 million ransom. It’s suspected that they used a vulnerability in a third-party application, [Citrix NetScaler](https://support.citrix.com/article/CTX579459/netscaler-adc-and-netscaler-gateway-security-bulletin-for-cve20234966-and-cve20234967), to gain data access. Toyota had to notify customers that over two million customer records were exposed to the threat actors behind the ransomware attack.

## Protect Your Organization’s Third-Party Supply Chains

Bad actors look for trusted vendors and leverage that access to compromise companies. To safeguard against these types of breaches, it’s crucial to understand the security measures of suppliers — not just your own.

For more actionable advice, [download our 5-1/2 Easy Steps to Avoid Cyber Threats](https://www.mitnicksecurity.com/lp-easy-steps-to-avoid-cyber-threats) today.

[![New call-to-action](https://no-cache.hubspot.com/cta/default/3875471/7f9b1de1-cf7c-4700-8892-cdf9402b32cf.png)](https://cta-redirect.hubspot.com/cta/redirect/3875471/7f9b1de1-cf7c-4700-8892-cdf9402b32cf)

 

# Related Resources

[![](https://www.mitnicksecurity.com/hs-fs/hubfs/included-in-pentesting-report.jpeg?width=350&name=included-in-pentesting-report.jpeg)

by Mitnick Security  | 06.30.2026  | 8 min

#### What Does a Pentest Report Look Like? Inside the Results

If your last pentest report was a spreadsheet of CVE numbers with color-coded severity ratings, here is an uncomfortable truth: you did not get a penetration test. You got a vulnerability scan with a ...

 Continue Reading

Global Ghost Team, Penetration Testing 

](https://www.mitnicksecurity.com/blog/penetration-test-report)

[![](https://www.mitnicksecurity.com/hs-fs/hubfs/Mitnick-Security-071-Enhanced-NR-Copy1.jpg?width=350&name=Mitnick-Security-071-Enhanced-NR-Copy1.jpg)

by Mitnick Security  | 06.08.2026  | 8 min

#### Choosing a Pentesting Company That Thinks Like an Adversary

5 Questions to Vet Any Penetration Testing Company Finding a pentesting partner that can produce a deep dive pentest is harder than knowing what one should look like. When evaluating vendors, seasoned...

 Continue Reading

Penetration Testing 

](https://www.mitnicksecurity.com/blog/best-penetration-testing-company)

[![](https://www.mitnicksecurity.com/hs-fs/hubfs/Person%20reading%20book.jpeg?width=350&name=Person%20reading%20book.jpeg)

by Mitnick Security  | 05.11.2026  | 5 min

#### 4 Essential Cybersecurity Books to Harden Your Mindset (and Your Network)

Offense is the best defense. If you want to stop a hacker, you have to read like one.

 Continue Reading

Cyber Security 

](https://www.mitnicksecurity.com/blog/best-cybersecurity-books)

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Mitnick Security",
    "url" : "https://www.mitnicksecurity.com/blog/author/mitnick-security"
  },
  "dateModified" : "2024-11-04T18:28:08.282Z",
  "datePublished" : "2024-07-03T13:48:06.000Z",
  "headline" : "The Growth of Third-Party Software Supply Chain Cyber Attacks",
  "image" : [ "https://www.mitnicksecurity.com/hubfs/Understand%20the%20Growth%20of%20Software%20Supply%20Chain%20Attacks.jpg" ],
  "mainEntityOfPage" : {
    "@id" : "https://www.mitnicksecurity.com/blog/supply-chain-cyber-attacks",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://www.mitnicksecurity.com/hubfs/Mitnick-Security-Logo-White-H.png"
    },
    "name" : "Mitnick Security Consulting, LLC"
  }
}
```