logo

Top 10 Supply Chain Attacks of 2025

ID: 9049d039-a69f-50d2-a7ef-22032e18576e

STIX ID: report--9049d039-a69f-50d2-a7ef-22032e18576e

Feed Name: SOCRadar Blog

Threat Score
90/100

Date Published: 2026-01-06

Date Updated: 2026-04-30

Author: Ameer Owda

...
...

This report summarizes the ten most impactful supply‑chain cyber incidents of 2025, documenting coordinated ransomware attacks against major retailers and service providers, the Ingram Micro outage, widespread Salesforce-related OAuth/connected-app compromises (affecting hundreds of organizations), multiple npm ecosystem supply‑chain and worm campaigns that propagated malicious packages and stole developer secrets, exploitation of an Oracle E‑Business Suite zero‑day (CVE‑2025‑61882) used for data theft and extortion, F5 BIG‑IP source‑code exfiltration attributed to a nation‑state–linked actor, and other third‑party vendor breaches—demonstrating how trusted integrations and shared infrastructure can produce broad downstream harm and necessitating continuous monitoring and threat‑informed vendor risk management.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.