Skip to content
BreachPathAttack Path LibraryStart
AdvancedData theftRansomware

Supplier account to internal network

A compromised supplier's access is used to enter the organisation through a trusted connection, then to move from the supplier's limited footprint toward internal systems and data.

Technologies
On-premises Active Directory, SaaS (generic), Azure
Entry points
Supplier compromise
Sectors
Manufacturing, Retail, Healthcare
Stages
3
01

A supplier's access is taken over

The attacker compromises a supplier — or a supplier's account — that holds legitimate access to the organisation, whether a remote connection, a portal, or an integration.

Attacker objective

Control access that the organisation has granted to a third party.

Controls that should stop this
  • MFA and Conditional Access on all third-party access
  • Dedicated, least-privilege accounts for suppliers with expiry
  • Contractual security requirements and monitoring of supplier access
What defenders should see
  • Supplier logins from new locations or at unusual times
  • Supplier accounts touching systems beyond their remit
  • Dormant supplier access becoming active
What a pentest validates
  • Review what each supplier account can actually reach
  • Test MFA and Conditional Access on third-party access
  • Audit stale and over-scoped supplier accounts
Business impact

The attacker enters through a connection the organisation implicitly trusts.

02

The trusted foothold is used to pivot inward

From the trusted entry point, the attacker explores what the supplier connection can reach and looks for weakly segmented paths, shared credentials or over-broad access that lead deeper into the environment.

Attacker objective

Move from the supplier's limited access toward broader internal systems.

Controls that should stop this
  • Strong network segmentation isolating supplier access
  • No shared or reused credentials between supplier and internal systems
  • Monitoring lateral movement from third-party entry points
What defenders should see
  • Connections from the supplier segment into internal systems
  • Use of internal credentials sourced from a supplier foothold
  • Lateral-movement alerts originating in third-party access zones
What a pentest validates
  • Assumed-breach test starting from supplier-level access
  • Validate segmentation between supplier and internal networks
  • Test for shared credentials bridging the trust boundary
Business impact

The attacker crosses from a limited supplier footprint into the internal estate.

03

Internal systems and data are reached

Having pivoted inward, the attacker reaches internal repositories, applications or infrastructure and pursues the objective — extracting data or positioning for disruption.

Attacker objective

Reach the internal data or systems that are the ultimate target.

Controls that should stop this
  • Least-privilege access to internal data, independent of network position
  • DLP and egress controls on internal repositories
  • Detection tuned for internal reconnaissance and collection
What defenders should see
  • Access to internal data stores from unexpected sources
  • Bulk collection or egress from internal systems
  • Reconnaissance activity within the internal network
What a pentest validates
  • Test whether supplier-origin access reaches sensitive internal data
  • Validate internal DLP and egress controls
  • Confirm detection of internal collection and reconnaissance
Business impact

Internal data or systems are compromised via a third party — a breach with contractual and regulatory fallout.

ATT&CK techniques in this chain

If this chain completes

Trusted third-party access becomes an attacker's route into the organisation, bypassing perimeter defences and exposing internal systems that assumed the supplier connection was safe.

Should you test this against your environment?

Turn this chain into a scoped red-team brief — objective, systems and identities in scope, testing assumptions and the questions to answer before commissioning.