Supply Chain

Verified

·

High Consensus

Supply Chain Attack

In plain English

An attack where hackers compromise software or hardware before it ever reaches the buyer, so the tampered product is trusted and installed.

Definition

Attacks that allow the adversary to utilize implants or other vulnerabilities inserted prior to installation in order to infiltrate data, or manipulate information technology hardware, software, operating systems, peripherals (information technology products) or services at any point during the life cycle.

Also known asvalue chain attack · third-party attack · vendor chain attack · software supply chain attack · hardware supply chain attack
2 sources cited4 related termsReviewed by Martins Ogundare · Aug 10, 2026
Committee on National Security Systems Glossary CNSSI 4009-2015View source
Example

A voting system vendor's update server is breached, and a malicious code change is pushed to counties as a routine software update.

Why this term matters

A single compromised vendor or component can affect many election jurisdictions at once. Supply chain defenses, such as code review and signed updates, are essential because local officials cannot inspect every component themselves.

How it is used in election security

Election officials reduce supply chain risk by buying only certified voting systems, verifying software hashes, requiring signed updates, and coordinating with federal agencies on vendor risk assessments.

Understand more election terms clearly

Get one important election term explained each week, with named public sources, practical context and related definitions.

Free. One useful email each week. Unsubscribe anytime.Learn more about the ESG newsletter →
CNSSGC

High consensus

Attacks that allow the adversary to utilize implants or other vulnerabilities inserted prior to installation in order to infiltrate data, or manipulate information technology hardware, software, operating systems, peripherals (information technology products) or services at any point during the life cycle.

Committee on National Security Systems Glossary CNSSI 4009-2015 · 2024

Cite this term

Permanent URL · stable across revisions
Election Security Glossary. (2026). Supply Chain Attack. In Election Security Glossary. Retrieved September 14, 2026, from https://electionsecurityglossary.com/glossary/supply-chain-attack

Sources

2 cited · last checked Aug 10, 2026

01

Committee on National Security Systems Glossary CNSSI 4009-2015
Committee on National Security Systems Glossary CNSSI 4009-2015

High consensus

View source

02

The Cyber Glossary
The Cyber Glossary

High consensus

View source

Get the weekly election term

Receive one cited, source-backed election explanation in your inbox each week.

Get election terms explained weekly →
Free · Nonpartisan · Unsubscribe anytime.
Continue Research

Keep going from here

Three ways to go deeper on supply chain and adjacent terminology.