Provides real-time trend data on the doubling of supply chain attacks in 2025 and identifies IT service providers as the highest-value targets for coordinated ransomware campaigns.
Software supply chain attacks doubled in frequency between April and August 2025, reaching a near-daily occurrence with an average of 26 major incidents per month. Ransomware groups such as Cl0p, Qilin, and SafePay are driving this surge by exploiting critical vulnerabilities in IT infrastructure (e.g., Citrix NetScaler, Microsoft SharePoint) to gain access to sensitive downstream customer data. One attack on a global technology services provider allegedly yielded 3.5TB of stolen data, while another impacted over 41,000 customers, including the U.S. Department of Defense. IT and IT services companies are targeted far more than other sectors due to their massive 'force-multiplier' reach into thousands of municipal, university, and corporate networks.
The surge in attacks in 2025 is driven by ransomware groups exfiltrating sensitive data and disrupting distribution, licensing, and API infrastructure.
deployment of compromised packages that have been infected with ransomware or data-stealing payloads
the doubling of supply chain attacks validates that active malware detection is the most urgent requirement for modern package evaluation.
Software supply chain attacks have been occurring at twice their long-term average in recent months... targeting suppliers and service providers and their customers.
Risk Guard evaluates package security but does not track the 'Incident History' or 'Breach Reputation' of the commercial organizations behind the packages.
Risk Guard would be better if it integrated a 'Vendor Incident Feed' to flag packages maintained by companies that have recently suffered major supply chain breaches.