Digital supply chain compromises have been responsible for major incidents in New Zealand in the last year affecting business operations and potentially resulting in loss of personal information and identify data for hundreds of thousands of users.
Digital supply chain breaches happen when software, hardware or other services provided by third-party vendors are compromised by cybercriminals or other malicious actors. The compromise then allows an attacker to access data or systems used by a target organisation. Targeting supply chain vendors is a strategy used by both financially motivated criminals and state-sponsored actors to access multiple targets.
Why does this matter?
Many organisations are now reliant on a mix of platforms, suppliers, outsourced services and digitally controlled technologies to run their operations. Many of these suppliers will be based overseas and it’s unlikely that many New Zealand organisations have visibility of their cyber security settings such as access controls, patching cycles or data encryption.
A single security failure at the vendor level, here or overseas, can cascade to potentially multiple compromises of data and operational systems in New Zealand. These compromises might be unexpected and significant.
Supply chains are an attractive target
Attacks via third-party suppliers are an attractive vector for cybercriminals. One reason is that successfully infiltrating the defences of a service provider may allow the attacker to circumvent the defences of a client, who is their main target. Secondly, compromising the systems of a supplier may provide access to many client organisations, greatly expanding the scale of a breach.
Supply chain risks also apply to Operational Technologies (OT) controlling industrial processes and physical operations. These systems are increasingly connected directly to the internet and can also be connected to internal networks creating a new vector for compromise. The software and control systems for OT can be vulnerable if not protected and managed at the same level as corporate systems. In the past year sabotage and disruption of OT systems in the energy sectors of several countries has been attributed to Russian state actors.
Complex supply chains also create broader attack surfaces for malicious cyber actors, with third party applications managing data, finances and other valuable information offering potential targets. When these applications have data interfaces within an organisation, this creates pathways that could be exploited to infiltrate ransomware or malware into networks.
Another attack vector observed in large data breaches is customer service or IT support services provided by third parties. These services have access to networks and data and have been targeted by malicious actors to gain access to internal systems. The Qantas data breach in 2025 was the result of a sophisticated attack on an IT support service, combined with the infiltration of malware into a third-party system.
What's the current landscape?
In the past year several New Zealand organisations have been victims of attacks by cybercriminals exploiting third party suppliers or systems. The healthcare sector has been targeted on multiple occasions with a focus on accessing and stealing sensitive personal information held on third party applications for the purpose of extortion. It is also likely that data stolen in these exploits is retained by the criminals involved, or sold to other actors, for the purposes of mining credentials and other information, or for secondary extortion of victims.
A developing risk lies with the unsanctioned or unintended exposure of data through the use of Artificial Intelligence (AI) tools. Data leakage can result from the storage of information in locations lacking appropriate security controls, limiting defender oversight and ability to respond.
The compromise of third-party vendors or software providers as part of a broader campaign of espionage or disruption by state-sponsored actors is a realistic possibility as the global environment becomes more contested. New Zealand organisations may not be the primary target of such activity, but compromise in the digital supply chain may affect availability of networks or services or could compromise information irrespective of whether there was a deliberate intention to impact us.
Across many cyber incidents the common factors are lack of authentication (e.g. not using multifactor authentication), over-permissioned access to systems (i.e. more people have access than necessary), and poor separation or segmentation of data. Implementing the following basic security controls provides a strong basis for protection from common attacks:
- Enabling appropriate firewall protection
- Encrypting data
- Enforcing multifactor authentication on all systems, accounts and profiles
- Setting access limitations on accounts, or adhering to the principle of least privilege (limiting who is authorised to access what)
- Enabling data loss prevention solutions for data at rest (to help prevent personal information from getting out)
- Patch management
- Network segmentation
Case study 4: Canvas learning management system
In May 2026 a US-owned cloud-hosted learning management system called Canvas suffered a security breach in which cybercriminals accessed user information and then posted messages on users’ login pages demanding ransom payments.
Implications for organisations
Supply chain threats are difficult to avoid and therefore basic cyber security requirements remain essential, as well as specific control measures such as Software Bill of Materials and assessing cyber security as a component of awarding supplier contracts.
For organisations where third-party suppliers or applications hold sensitive data, operate essential equipment or are business critical, a strong understanding of the cyber security risks in the supply chain is essential. Developing this understanding can be done when services are contracted and form part of the discovery and assessment process during procurement.
Questions leaders should be asking:
- When you contract third-party suppliers do you assess their cyber security as part of the procurement process?
- Have you exercised or planned a response to a data breach or operational compromise of a thirdparty application?
- Do we have ongoing assurance that suppliers are maintaining agreed levels of cyber security?
- Do you have specific contractual clauses with your supplier that establish clear data protection and cyber security expectations
Resources
For further information, refer to the following guidance:
- Responding to third-party data breaches
- Supply Chain Cyber Security: In Safe Hands
- Keeping personal information safe: a guide for organisations and their suppliers
- Artificial intelligence and machine learning: Supply chain risks and mitigations
- A Shared Vision of Software Bill of Materials (SBOM) for Cybersecurity
Key cyber security terms and their definitions can be found in our glossary: