Skip to content

Software supply chain attacks surge, as ransomware groups escalate and industrial sectors ...

Industrialcyber.Co November 7, 2025

New data from Cyble shows software supply chain attacks surged in October 2025, setting a new record more than 30% higher than the peak in April. Tracking incidents claimed by threat actors on dark web leak sites, Cyble recorded 41 attacks in October, 10 more than the earlier high. Since April, supply chain attacks have stayed at elevated levels, averaging more than 28 per month, more than twice the 13 monthly attacks seen between early 2024 and March 2025. Sectors such as energy and utilities, healthcare, and manufacturing each recorded between 20 and 30 supply chain attacks.

Data published this week identified ransomware groups Qilin and Akira have led the activity this year, each responsible for a sizable of these incidents. Moving to a sectoral distribution, IT was the most targeted sector, with nearly 120 attacks, accounting for a significant of the total. Finance follows with over 80 attacks, representing approximately 70% of the IT sector’s figure. Other sectors, such as transportation , technology, and government, experience moderate attack rates, with each sector reporting between 30 and 50 attacks. The food and beverage industry sees a similar trend, with just under 40 incidents.

Cyble reported that retail, consumer goods, and automotive industries have fewer attacks, each ranging from 10 to 20 incidents. Sectors such as aerospace/defense, media/entertainment, hospitality, and construction show a relatively low frequency of attacks, with fewer than 10 in each case. Education, chemicals, agriculture/livestock, real estate, pharma/biotech, and metals/mining face the least number of supply chain attacks, each sector experiencing fewer than 5 incidents.

The latest trend reinforces a critical shift in the attack surface, away from direct network intrusions toward indirect compromises through third-party technology partners. This expanding dependency chain, spanning cloud service providers, software vendors, and industrial integrators, demands a renewed focus on software assurance, vendor transparency, and incident response collaboration.

As adversaries refine their strategies to exploit trust relationships, the line between IT and OT (operational technology) exposure continues to blur, heightening the urgency for unified governance, supply chain visibility, and resilience planning across operational ecosystems.

Akira recently claimed responsibility for a cyberattack targeting a major open-source software project,” Cyble revealed. “The group claims to possess 23GB of data, including sensitive employee information as well as financial documents, internal confidential files, and reports related to software issues and internal operations.”

The post added that Akira also claimed multiple attacks on IT service providers, including a company that develops software solutions for government and law enforcement agencies, a provider of compliance and environmental data management software for industrial and energy clients, and a U.S.-based company providing IT, cybersecurity , and consulting solutions for government, intelligence, and defense sectors. In the latter case, the group claims to possess more than 19GB of data, including financial records, sensitive employee and customer data, confidential documents, NDAs, and other files containing personal and corporate data.

Qilin claimed responsibility for breaching a U.S.-based financial technology company that provides integrated software and services for payment processing, transaction management, and financial infrastructure solutions. Stolen data allegedly includes confidential hardening reports, internal SharePoint directories, and a list of IT infrastructure employees from a major financial services company.

Cyber noted that Qilin also claimed an attack on a U.S.-based company providing technology solutions for law enforcement, criminal justice, public safety, and security sectors, and source code for proprietary software products was among the allegedly stolen data, in addition to accounting and HR data and client payment information from various law enforcement agencies.

Qilin claimed attacks on three U.S. energy cooperatives, including the theft of project information, obsolescence equipment details, contractual agreements with U.S. government entities, and customer billing information.

Another claimed Qilin breach involved a U.S.-based cybersecurity and cloud services provider offering IT infrastructure, managed services, and compliance solutions for healthcare and dental organizations. The threat actors claimed they gained access to downstream customer environments through clear-text credentials stored in Word and Excel documents hosted on the company’s systems. The stolen data reportedly includes customers’ personal information, financial records, and medical documentation. Posted samples include unencrypted passwords from client systems, financial documents, and medical reports.

A newly identified ransomware group, Kyber , leaked data allegedly stolen from a major U.S.-based defense and aerospace contractor that provides communication, surveillance, and electronic warfare systems. The group leaked over 141GB of data consisting of project files, internal builds, databases, and backup archives.

The BlackShrantac hacking group claimed responsibility for a breach of a South Korean cybersecurity and physical security services provider. According to the hacking group, approximately 24GB of data was stolen, containing customer information and requirements, network and infrastructure data, HR and payroll data, e-commerce information, and cybersecurity technical documentation, including website source code, API keys, and configuration files.

To substantiate their claims, BlackShrantac released several sample files, which appear to show access to internal documentation, technical blueprints, Excel sheets with configuration details, and other sensitive company data.

Another ransomware group, Cl0p , claimed several victims from its exploitation of Oracle E-Business Suite vulnerabilities, including a major global energy technology company and a major U.S. university.

Cyble also mentioned another threat group, Crimson Collective, that claimed to have compromised a GitLab instance of a major U.S. technology provider, including the theft of 800 Customer Engagement Reports. The threat actors allegedly gained access to a client infrastructure using credentials and tokens found within the stolen repositories.

Clearly, it is important to protect against software supply chain attacks can be challenging because these partners and suppliers are, by nature, trusted, but security audits and assessing third-party risk should become standard cybersecurity practices.

Organizations should build in controls and resilience wherever possible to limit the impact of potential attacks. This includes implementing network microsegmentation and enforcing strong access controls that grant only the necessary permissions, verified regularly. Establishing a strong source of user identity and authentication is also essential, combining multi-factor authentication and biometrics for users with machine authentication that includes device compliance and health checks.

Data should be encrypted both at rest and in transit. Ransomware-resistant backups must be immutable, air-gapped, and isolated to ensure recovery capabilities. Deploying honeypots can help lure attackers to fake assets, providing early breach detection.

Furthermore, organizations should also ensure proper configuration of API and cloud service connections, while monitoring for unusual activity through SIEM systems, Active Directory monitoring, and data loss prevention tools. Regular audits, vulnerability scans, and penetration tests are vital to confirm that controls remain effective and current.

Earlier this year, the World Economic Forum (WEF) highlighted growing challenge of securing software supply chains, emphasizing the rising need to safeguard against hidden dependencies. As businesses increasingly rely on third-party software suppliers and open-source solutions, they face significant hurdles in ensuring the security and integrity of their software ecosystems. Also, these challenges extend beyond IT to OT and industrial systems , heightening risks for critical infrastructure installations.