The revelation was found by the company in its Q2 2023 Threat Landscape Report due largely to the notorious Cl0p ransomware gang.
Quarter 2 saw a 33% surge in activity from the gang compared to Q1 of 2023. The company also noticed a surge in email compromise attacks which contributed to the rise.
Supply chain attacks happen when a threat actor targets vendors or suppliers of materials rather than end-user organisations. One recent example is the Clop gang’s zero-day vulnerability attack on the UK HR provider ,Zellis , which handled personal identifiable information of many large companies such as Boots, the BBC, and British Airways. This breach known as the MOVEit cloud vulnerability is still claiming victims.
A report from Gartner noticed that 84% of organisations had disruptions in business operations because of third-party ‘misses.’ In the UK alone, between 55% and 60% of small to large organisations outsourced their cybersecurity to an external supplier for a service last year, according to a government survey.
“A majority of organisations are also using third parties for new-in-kind-services and have become more reliant on them to conduct their operations. While increased use of third parties can improve business operations in many ways, it also introduces risks that are causing notable impacts on organisations,” said Chris Matlock, vice president of research in the Gartner Legal Risk & Compliance Practice.
Kroll also observed an 8% increase in email compromise attacks in Q2, while another report predicts a 43% increase over the course of the next 12 months. This is largely due to the proliferation of AI technology among threat actors, increasing both the volume and quality with which they can carry out phishing campaigns.
Recommended reading
- LinkedIn Number One Brand to be Faked in Phishing Attempts
- Virgin Media O2 to Cut 2,000 UK Jobs Amid Decline in Customers
- European GDPR Fines Skyrocket in Third Quarter
Industry wise, the highest growing impacted industries this quarter were financial services, healthcare, telecommunications and technology. Healthcare, after having attacks increase by merely 2% is not in the top five most targeted industries for the first time in two quarters. Financial services were uniquely impacted this quarter, in that its growth in cyberattacks was impacted by its association with Cl0p victims.
The price tag for the rise in software supply chain attacks on businesses is expected to cost the global economy roughly £54.04 billion annually by 2026 according to Juniper Research.





