# Supply Chain Compromise
**Domain:** Cybersecurity / Software / Third-Party Risk
**Doc Type:** Canonical Threat Node
**Maturity:** Foundational
## Definition
A **supply-chain compromise** reaches a target by subverting a trusted supplier, update mechanism, service provider, dependency or distribution channel.
## Strategic Context
Trust in the intermediary becomes the access mechanism. A single compromised provider can propagate risk across many downstream organizations that did not interact directly with the original attacker.
## Historical Context
The [[wiki/SolarWinds Compromise|SolarWinds compromise]] weaponized a trusted software update. The 2021 Kaseya incident propagated ransomware through managed service providers.
## See Also
[[wiki/Log4j|Log4j]], [[wiki/Advanced Persistent Threat|Advanced Persistent Threat]], [[wiki/Incident Response|Incident Response]]