Supply chain attacks: the preferred vector for APT groups in 2025-2026
Supply chain attacks represent today the most effective and hardest to detect compromise vector. Instead of directly attacking the target, adversaries compromise a supplier, software component, or third-party service, gaining indirect — and often privileged — access to the real target's infrastructure.
The most significant cases
The SolarWinds attack in 2020 demonstrated that even the most protected organizations in the world are vulnerable when the threat comes from a trusted supplier.
— CISA Advisory
- SolarWinds SUNBURST (2020): backdoor inserted in a legitimate software update, compromising 18,000 organizations including US federal agencies.
- Kaseya VSA (2021): REvil ransomware distributed through a remote management tool, hitting over 1,500 companies.
- XZ Utils (2024): sophisticated backdoor inserted in an open source library after years of social engineering against maintainers.
- 3CX Compromise (2023): cascading supply chain — an attack on a trading vendor then compromised 3CX communication software.
Why critical infrastructure is particularly vulnerable
Critical infrastructure (energy, water, transport, healthcare) depends on numerous OEM vendors for remote maintenance and monitoring. These vendors often have privileged access to operational networks through permanent VPNs, with shared credentials and insufficient audit trails. A single compromised vendor can open the door to the entire OT network.
NIS2 (Art. 21) explicitly mandates supply chain security. Organizations must implement zero-trust controls for vendor access: strong authentication, granular authorization, timed sessions, and complete logging.
The zero-trust approach as defense
The only effective defense against supply chain attacks is a zero-trust model systematically applied to all third-party access. Every session must be authenticated, authorized, time-limited, monitored, and logged. No vendor should have permanent or untracked access to the operational network.
AEGIDA Framework implements this model with zero-trust access for OEM vendors: every session is certificate-authenticated, time-limited, scoped to authorized assets only, and fully tracked in an immutable audit trail. In case of vendor compromise, the impact is automatically contained.