Back to all lessons
Awareness Lessons
7 months ago

Supply Chain Attack Compromises Critical Infrastructure and Backup Systems

Ethiopia's National Oil Corporation suffered a devastating breach where attackers compromised both their primary security tools (Kaspersky) and backup infrastructure (Veeam), before deploying ransomware and exfiltrating 800GB of sensitive ERP data. This attack demonstrates how sophisticated threat actors can exploit trusted security and backup solutions as attack vectors, turning protective measures into weapons. The comprehensive nature of the breach, affecting both operational systems and recovery mechanisms, left the organization with severely limited options for restoration and incident response.

Tactical Insight

Immediate actions

  • This attack could have been prevented through rigorous supply chain security practices including multi-vendor security approaches to avoid single points of failure, proper network segmentation to isolate backup systems from production networks, and implementing zero-trust principles for all third-party tools

Long-term improvements

  • implementing defense-in-depth strategies with multiple layers of security controls from different vendors would have made such a comprehensive compromise significantly more difficult

Detection measures

  • Organizations should maintain offline, air-gapped backup copies that cannot be accessed through network connections, regularly audit and monitor all third-party security tools for anomalous behavior, and establish incident response procedures that don't rely solely on potentially compromised security infrastructure