An attack that compromises a trusted supplier or component in order to reach, by ricochet, all of its customers.
A supply chain attack consists of compromising not the final target directly but a trusted link upstream, a software vendor, a service provider or an integrated component, in order to reach, by a cascade effect, all of its customers. Rather than forcing a thousand doors, the attacker compromises a single one, that of a player whose products or access are widely distributed, and exploits the relationship of trust to propagate the intrusion. This strategy is formidably effective, because it exploits precisely the modern technological dependencies in which every organization relies on a multitude of third parties. For insurance, it is one of the most worrying accumulation scenarios, since a single compromise can generate simultaneous losses across a large number of insureds that shared the same supplier, with no apparent link between them. The underwriting difficulty lies in the opacity of these chains, since an insurer rarely knows the full set of its insureds' software dependencies, and therefore rarely knows its own exposure to a common event hidden behind a second or third-tier provider.
The SolarWinds attack, revealed in late 2020, inserted a backdoor into a legitimate update of the Orion software, then distributed to thousands of organizations, including US government agencies. A single compromised point opened access to the entire customer base.
supply chain attack, attaque sur la chaîne logicielle, compromission de la chaîne d'approvisionnement, attaque chaîne logistique numérique, trusted relationship attack, Attaque supply chain