coststatisticsmalwaresupply-chaintrends

DeepStrike — Supply Chain Attack Statistics 2025

Benchmarks the 30% prevalence and 267-day containment time for supply chain breaches while documenting the 1,300% growth in open-source malware threats.

Summary

Supply chain breaches doubled in 2025 to account for 30% of all data breaches, while the average global cost of a breach hit $4.44 million ($10.22 million in the U.S.). Supply chain incidents are uniquely damaging, taking an average of 267 days to identify and contain—a full week longer than malicious insider attacks—allowing for prolonged data exfiltration. Open-source malware has exploded, with malicious threats in repositories growing by 1,300% since 2020 and over 704,000 malicious packages logged since 2019. High-profile cases like SolarWinds and 3CX demonstrate that attackers are increasingly weaponizing trusted build systems and digital signatures to bypass Strong perimeter defenses, pushing the projected global annual cost of supply chain attacks to $60 billion in 2025.

Related Checks

PACKAGE_ACTIVE_MALWARE

The report documents a 1,300% growth in malicious threats in open source repositories, with over 704,000 packages logged since 2019.

Adverse Outcome

inclusion of intentionally malicious code that exfiltrates data or provides unauthorized remote access

Because

the explosive growth in malicious package volume validates that active malware detection is a baseline requirement for software supply chain security.

VULN_SLOW_REMEDIATION

Supply chain breaches take an average of 267 days to identify and contain, the longest dwell time of any initial attack vector.

Adverse Outcome

prolonged exposure and escalating data loss due to a failure to rapidly detect and respond to third-party compromises

Because

measuring the delta between vulnerability disclosure and containment is the only way to mitigate the $4.44M average cost of these long-dwell-time breaches.

Gaps Analysis

Evidence

Supply chain cases cost more + last longer... taking an average of 267 days to identify and contain... breaches from the supply chain are uniquely damaging.

Blind Spot

Risk Guard reports technical scores but does not estimate the 'Containment Time Risk' (dwell time) associated with a specific complex dependency.

Actionable Capability

Risk Guard would be better if it provided an 'Estimated Containment Difficulty' score to help security teams prioritize vulnerabilities that are historically hard to detect (high dwell time).

← Previous Next →