A supplier's access is taken over
The attacker compromises a supplier — or a supplier's account — that holds legitimate access to the organisation, whether a remote connection, a portal, or an integration.
Control access that the organisation has granted to a third party.
- MFA and Conditional Access on all third-party access
- Dedicated, least-privilege accounts for suppliers with expiry
- Contractual security requirements and monitoring of supplier access
- Supplier logins from new locations or at unusual times
- Supplier accounts touching systems beyond their remit
- Dormant supplier access becoming active
- Review what each supplier account can actually reach
- Test MFA and Conditional Access on third-party access
- Audit stale and over-scoped supplier accounts
The attacker enters through a connection the organisation implicitly trusts.