
Dr Niklas Hellemann at SoSafe describes the most common hacking methods in supply chain attacks, and explains how security awareness plays into it
Cyber-criminals are increasingly developing new methods and techniques to carry out cyber-attacks. Therefore, in order to detect and repel these attacks, companies need to be constantly aware of the latest cyber-attack trends.
One of these trends is the increasing popularity of attacks through the supply chain. In this type of attack, hackers first look for vulnerabilities in a company’s supply chain, such as service providers with lower security standards. They then exploit technical flaws in the service provider’s systems to gain access to the actual target.
To guard against this, it is important to know what kind of attacks to expect. The following methods are currently the most common:
Most supply chain attacks start with a malware infection. Cyber-criminals secretly put malicious software on a company’s systems, which slowly spreads throughout the supply chain.
There are different types of malware, which in turn perform different processes. Spyware, for example, monitors employees’ activities and retrieves their confidential login details. Ransomware is used to collect and encrypt data so that cyber-criminals can demand a ransom. Backdoor malware, such as a Trojan Horse, allows remote control of programmes and can also serve as the starting point of a supply chain attack.
These malware infections exploit technical security flaws and other vulnerabilities in the supply chain.
No software is perfect. Manufacturers test their products extensively, but there is no such thing as an absolute security guarantee. Cyber-criminals look for vulnerabilities that they can exploit, and often only need temporary flaws that they can use for zero-day exploits, such as manipulating and running updates.
We saw an example of this last January when authentication service Okta was attacked by hacker group Lapsus$; the attackers managed to exploit a vulnerability at Sitel, one of Okta’s service providers. They used software intended for remote maintenance by logging into an employee’s laptop, and only disclosed themselves to the public two months later.
This clearly shows how long hackers can remain undetected in systems and how quickly - and extensively - malware can spread through supply chains.
Not just technology, but humans are also constantly put to the test by cyber-criminals. With social engineering, hackers play on human traits such as trust and fear, leading to victims disclosing confidential information, disabling security features or getting tricked into installing malware.
There are various different types of social engineering attacks, including phishing or smishing (phishing via SMS or other messages). Users are often more careless with smishing messages and respond to them faster than e-mails.
Last July, for example, attackers tried to trick Christine Lagarde, the president of the European Central Bank, into revealing her confirmation code for WhatsApp. To do so, they used former German Chancellor Angela Merkel’s real mobile number - no one knows how the cyber-criminals got their hands on it. Fortunately, Lagarde was suspicious and called Merkel to ask about the message, and the danger was averted.
Cyber-criminals also use so-called ‘brute-force’ attacks to get their hands on sensitive data like internal login details. These attacks are based on trial and error, with cyber-criminals testing many possibilities to guess an employee’s password using tools that automatically test all possible combinations. Once they have successfully cracked it, criminals can easily infect the company’s systems with malware.
The wide variety of attacks demonstrates that security breaches and vulnerabilities can have serious consequences for organisations. Despite - or perhaps because of – the numerous technical security systems in use today, cyber-criminals are becoming increasingly persistent in their attempts to access systems through people. After all, people are always vulnerable to one thing: emotional manipulation.
It’s vital to further integrate employees into coherent cyber-security strategies to reduce the risk of chain and other cyber-attacks to ensure every member of an organisation is alert and aware of attackers’ methods.
But a simple explanation on paper or training is not enough, because passive knowledge is rarely applied and can be difficult to remember. Active knowledge can be put into practice in the real world, and reflected in secure behaviour. This can be achieved with modern security awareness training; practical exercises and realistic simulations.
The focus should always be on the learner’s needs. Leveraging behavioural science and learning psychology is key. Gamification, for example, is highly effective, and can increase user activation by 54%.
If employees learn through simulations what to do in case of an emergency, they know how to handle it when it happens in real life. The risk of cyber-attacks can be reduced by up to 90% with these kinds of systematic and individual training measures. Awareness is a major step towards cyber-security for the entire organisation.
Dr Niklas Hellemann is CEO at SoSafe
Main image courtesy of iStockPhoto.com
Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543