Site navigation

Supply Chain is a Prime Ransomware Target, Report Says

Michael Edgar

,

rabsomware profits ransomware report
A new third-party breach report highlights the software supply chain as the prime target for ransomware attacks. 

This revelation comes from SecurityScorecard’s Global Third-Party Cybersecurity Breach Report, which sheds light on the escalating threats faced by organisations worldwide.

The report found that an overwhelming three quarters (75%) of third-party breaches took aim at the software and technology supply chain. The vulnerabilities in this sector offer lucrative opportunities for threat actors to expand their operations with minimal effort, according to the report. 

“The supplier ecosystem is a highly desirable target for ransomware groups. Third-party breach victims are often not aware of an incident until they receive a ransomware note, allowing time for attackers to infiltrate hundreds of companies without being detected,” said Ryan Sherstobitoff, senior vice president of threat research and intelligence at SecurityScorecard.

Alarmingly, the report noted that as of 2021, 75% of organisations at the highest levels of maturity still relied on manual third-party risk programs, underscoring the urgent need for automation in vendor identification and cyber risk management.

Approximately 29% of breaches in 2023 had third-party attack vectors, with healthcare organisations bearing the brunt at 35%. Financial services followed closely behind, comprising 16% of total breaches. 

The report also looked into different cyber-crime groups, and noted that C10p (CLOP) emerged as the primary perpetrator, responsible for 64% of attributable third-party breaches in 2023. Their dominance was fuelled by extensive attacks exploiting a critical zero-day vulnerability in MOVEit software, showcasing the sophistication and persistence of modern cyber-threats.


Recommended reading


MOVEit’s CVE-2023-34362 vulnerability, along with vulnerabilities in CitrixBleed and Proself, were implicated in 77% of all third-party breaches. The MOVEit zero-day, in particular, facilitated compromises not only in third-party organisations but also cascaded to fourth and fifth-party entities, amplifying the scale and impact of the attacks.

As organisations grapple with the escalating threat landscape, the report emphasises the importance of proactive cyber-risk management. With the average cost of a data breach soaring to $4.45 million in 2023, organisations cannot afford to overlook the imperative of safeguarding their digital ecosystems.

“In the digital age, trust is synonymous with cybersecurity. Companies must improve resilience by implementing continuous, metrics-driven, business-aligned cyber-risk management across their digital and third-party ecosystems,” said Dr. Aleksandr Yampolskiy, CEO and Co-Founder, SecurityScorecard.

Michael Edgar

Staff Writer, DIGIT

Latest News

AI Infrastructure

Scottish Parliament Votes to Pause All AI Data Centre Applications

Cybersecurity Editor's Picks Security

Cyber Essentials Certifications Rise as SME Uptake Remains Limited

AI Editor's Picks Funding

Edinburgh Graduates’ AI Infrastructure Firm Expanse Raises $5.3m

Featured Finance

Fintech Summit 2026 Countdown Enters Final Three Weeks