Documented vendor pathways
The dependency can be large or very small.
These cases show different ways a supplier or connected service became part of the
attack path. They support continuous vendor assurance, but they do not imply that a
certificate assessment alone would have prevented every incident.
2013Vendor credentials
Target and a small HVAC contractor
A U.S. Senate staff analysis reported that attackers stole credentials from Fazio
Mechanical Services, a small Pennsylvania HVAC contractor with remote access for
billing and project work. The attackers used vendor access as a foothold into
Target, where information relating to as many as 110 million customers was taken.
Control lesson: supplier access,
multifactor authentication, least privilege, segmentation, and continuous review
must match the risk created by the connection.
U.S. Senate staff report
2018Embedded third-party code
Ticketmaster and Inbenta
The UK Information Commissioner's Office found that an attacker inserted malicious
code into a third-party chatbot hosted by Inbenta. Because Ticketmaster placed that
code on payment pages, it could collect names, payment-card details, CVVs, usernames,
and passwords entered by customers.
Control lesson: externally loaded
scripts and services operate inside the customer experience and require inventory,
integrity controls, monitoring, and removal when their risk exceeds their value.
UK ICO penalty notice
2021MSP management software
Kaseya and downstream businesses
Attackers exploited zero-day vulnerabilities in Kaseya VSA and used normal product
functionality to deploy ransomware. Kaseya reported fewer than 60 directly affected
customers, many of them service providers, and fewer than 1,500 downstream businesses.
Control lesson: one privileged
management platform can concentrate risk across many smaller organizations that may
never contract directly with the original software vendor.
Kaseya technical overview
2020Trusted software update
SolarWinds Orion
CISA documented that an advanced actor added malicious code to multiple versions of
the SolarWinds Orion platform. Selected government, critical-infrastructure, and
private-sector customers then experienced persistent access, identity compromise,
and sensitive-data exfiltration.
Control lesson: vendor approval is
not permanent. Trusted software, signing systems, update channels, and externally
visible changes require continuing verification and incident coordination.
CISA incident guidance