X-Force Threat Intelligence Index 2026

Supply chain and third party compromises

Throughout 2025, supply chain and third-party compromises took the form of coordinated, multi-stage campaigns targeting the core of modern open-source ecosystems, CI/CD platforms and cloud infrastructure. These attacks exploited developer trust, automation workflows and cloud interfaces. They enabled adversaries to infiltrate development environments, harvest credentials, exfiltrate sensitive data and maintain persistence across environments, often pivoting into cloud services.

IBM X-Force has been tracking an increase in attacks against developer platforms such as GitHub, GitLab and npm, alongside growing intrusions into cloud service providers and high-value SaaS platforms. These supply chain compromises in 2025 highlight a clear shift: attackers are targeting the environments where software is built—and increasingly the SaaS ecosystems that support those workflows—rather than traditional endpoints. These campaigns exploit trust relationships and automation within development workflows, often beginning in open-source registries or CI/CD platforms and extending into cloud infrastructure. By leveraging stolen credentials and configuration data, adversaries achieve persistence and lateral movement across interconnected systems, amplifying the impact of a single compromise.

Supply chain attack vectors

The software supply chain is no longer a single link, but an interconnected stack of dependencies, automation and identity. Modern supply chain compromises increasingly exploit this interconnectedness.

Open-source registries such as npm and PyPI packages remain high-risk due to their scale and decentralized governance—a single compromised account can propagate malicious updates across thousands of projects. Attackers often embed payloads in post-install scripts or build hooks, leveraging weak package signing and complex dependency chains to accelerate propagation.

There has been a nearly 4-fold increase in major supply chain or third-party compromises over the last 5 years. Often, a single breach at a trusted supplier spread to many downstream customers, leading to widespread infiltration, disruption or data theft.


CI/CD platforms like GitHub Actions and GitLab CI have become prime targets for credential theft and workflow abuse. Malicious automation scripts harvest tokens, API keys and cloud credentials directly from build developer pipelines, while compromised personal access tokens provide long-term access across repositories and cloud environments. The deep integration of these cloud platforms with registries and cloud services indicates a single breach can expose the entire development lifecycle.

Cloud environments broadly represent the ultimate objective for many threat actor campaigns. Once attackers obtain developer or CI/CD credentials, they can easily pivot into cloud platforms using legitimate API calls to enumerate assets, create unauthorized admin accounts and extract sensitive data. Misconfigured IAM roles and exposed backups amplify this systemic risk, turning service providers into second-order supply chain targets while escalating overall impact across entire customer environments.

Implications

Supply chain attacks no longer rely solely on zero-day exploits or endpoint compromise. Instead, adversaries manipulate software delivery, deployment and management processes independently, exploiting trust and automation at scale. This evolution underscores a critical reality that the supply chain is now an interconnected stack of dependencies and identity rather than a single link, making integrity across these layers foundational to operational resilience.

Notably, there has been a nearly 4-fold increase in major supply chain or third-party compromises over the last 5 years. These compromises created a largescale, cascading impact: a single breach at a trusted supplier spread to many downstream customers, often leading to widespread infiltration, disruption or data theft. Once reserved for highly sophisticated nation‑state campaigns, these supply‑chain attack techniques are now increasingly leveraged by financially motivated and other criminal threat groups, contributing to the rise observed over the last several years.

Line graph showing growth in major supply chain and third-party ompromises from 2015 through 2025.
The growth of major supply chain or third-party compromises since 2015 (see Appendix for details). Source: IBM X-Force.

Notable threat actors

The X-Force team observed cybercriminal campaigns looking to exploit supply-chain and third-party vendor relationships in 2025. Three of the more prolific groups are Scattered Spider, LAPSUS$ and ShinyHunters. Each represent well-documented, high-impact criminal actors whose tactics heavily influenced today’s supply-chain and third-party threat landscape.

  • Scattered Spider is confirmed in multiple industry and government reports as a social-engineering-driven intrusion crew that exploits help desks, identity providers and cloud access pathways—allowing them to compromise not just a primary target but also downstream customers through federated IAM and managed service relationships.

  • LAPSUS$ is widely reported as an extortion group that targets telecoms, outsourcing firms and identity providers, using MFA reset abuse and insider recruitment to pivot into interconnected organizations reliant on those vendors.

  • ShinyHunters is consistently profiled as a prolific data-theft collective breaching SaaS platforms and consumer services, stealing large datasets that are later weaponized for credential-stuffing, account takeover and secondary compromises across the victim’s customer ecosystem.

Together, these groups highlight how modern cybercrime leverages identity weaknesses, vendor trust relationships and SaaS interconnectivity to cause cascading supply-chain and third-party risk. In mid-2025, the three groups formed an alliance, signaling a new level of organization in cybercrime. This development combined advanced social engineering, data theft and extortion tactics into coordinated, multi-stage attacks against high-value enterprise targets.

3d sphere and cube shapes surrounded by locks
Related solutions
Identity and access management (IAM) services

Strengthen security and compliance with IBM IAM services, streamlining identity across hybrid cloud environments.

Explore IAM services
Threat detection and response services

Optimize your security program with IBM’s global, vendor-independent threat response services.

Explore threat detection services
IBM Verify

Build a secure identity foundation with IBM Verify to simplify access, improve authentication, and scale with confidence.

Explore IBM Verify
Take the next step

Book a personalized discovery briefing to explore how IBM X-Force® can help you reduce cyber risk, validate your defenses and build lasting cyber resilience with offensive and defensive expertise.

  1. Schedule a discovery session with X-Force
  2. Explore IBM X-Force