Skip to content

Third-Party & Supply Chain Exploitation

Third-party and supply chain exploitation uses an established external relationship, authorised access path, logistics process, or software distribution relationship to influence action or extend attacker access. The relationship may be genuine, compromised, misused or falsely represented, and the relevant verification depends on the action being requested.

Pretext8 covers the human, relationship and workflow dimensions of third-party and supply-chain activity. It does not attempt to catalogue every technical supply-chain compromise. The retained techniques focus on logistics workflows, genuine external relationships, authorised third-party access paths, and human trust in software suppliers or update channels.

Third-party and supply chain exploitation can be assessed by asking:

  • What external relationship, access path, logistics process, or software source is being relied upon?
  • Is the relationship genuine, current, in scope, and owned by an accountable person?
  • What payment, access, delivery, installation, disclosure, or approval outcome is requested?
  • What supplier, contract, access, or software-assurance process should verify the action?

Third-Party & Supply Chain Exploitation includes the techniques below. Select a technique to open its behavioural method, common examples, relevant taxonomy boundaries, and control-domain orientation in the Technique Catalogue.


Third-party and supply chain exploitation activity may involve:

Relationship and supplier context

  • referencing legitimate suppliers, contractors, partners, vendors, service providers, logistics providers, consultants, auditors, or MSPs
  • using real or plausible contract names, supplier names, project references, purchase orders, support tickets, delivery details, or payment cycles
  • borrowing legitimacy from a known business relationship, portal, shared platform, managed service, or procurement workflow
  • using a genuine, compromised, coerced, or out-of-scope supplier, contractor, partner, delivery, or service-provider relationship

Request and workflow behaviour

  • requesting supplier bank-detail changes, payment updates, invoice redirection, onboarding changes, delivery redirection, remote access, portal access, document release, or sensitive information
  • presenting a supplier request as already approved, operationally necessary, contractually required, or time-sensitive
  • asking for exceptions to procurement, finance, IT, legal, logistics, or third-party access processes
  • using an established supplier channel, logistics workflow, access path, integration, or software distribution relationship to make the request appear legitimate
  • asking staff to use contact details, links, bank details, portal URLs, or support channels supplied inside the request

Pressure and dependency behaviour

  • creating urgency around service disruption, delivery failure, contract escalation, delayed payment, account suspension, compliance deadlines, or operational dependency
  • discouraging independent verification with the known supplier owner, contract manager, procurement contact, finance team, or security team
  • using the organisation’s reliance on a supplier or service to make delay feel risky
  • implying that refusing or slowing the request will cause business disruption, financial penalty, reputational harm, audit issue, or service outage

Technical and access behaviour

  • using compromised supplier accounts, authentic third-party channels, stale external access, or unexpected changes within an established relationship
  • requesting VPN, guest, contractor, MSP, remote administration, external sharing, delegated access, or app consent changes
  • asking for remote support sessions, tenant changes, backup recovery, access reactivation, or privileged actions outside the expected support workflow
  • using supplier compromise, third-party credentials, stale external accounts, or integrations to make activity appear legitimate
  • pushing a software update, package, dependency, plugin, or installer from a source that is trusted by default but whose provenance, signing, or integrity has not been verified