# Supply Chain Compromise **Domain:** Cybersecurity / Software / Third-Party Risk **Doc Type:** Canonical Threat Node **Maturity:** Foundational ## Definition A **supply-chain compromise** reaches a target by subverting a trusted supplier, update mechanism, service provider, dependency or distribution channel. ## Strategic Context Trust in the intermediary becomes the access mechanism. A single compromised provider can propagate risk across many downstream organizations that did not interact directly with the original attacker. ## Historical Context The [[wiki/SolarWinds Compromise|SolarWinds compromise]] weaponized a trusted software update. The 2021 Kaseya incident propagated ransomware through managed service providers. ## See Also [[wiki/Log4j|Log4j]], [[wiki/Advanced Persistent Threat|Advanced Persistent Threat]], [[wiki/Incident Response|Incident Response]]