Connect with us

NEWS

Supply Chain Hack Defenses Now Rest on a Handful of Tech Giants

UK regulators now directly oversee Amazon, Google, Microsoft and Oracle as banking’s single points of failure, even as supply chain hacks keep multiplying.

Published

on

Britain’s financial regulators began directly supervising four American cloud giants on July 13, naming Amazon, Google, Microsoft and Oracle as single points of failure for its banking system. The designation itself is new. The vulnerability behind it has been building for years, as hackers increasingly turn to supply chain attacks, breaching one trusted supplier to open a path into thousands of networks at once.

The fix carries its own irony. Pushing companies toward a shorter list of certified, too big to fail vendors is supposed to make supply chains safer. It also rebuilds, in plain sight, the exact kind of concentration that made SolarWinds, Marks & Spencer and a run of 2026 software hacks so damaging in the first place.

Third-Party Breaches Double in a Single Year

The shift shows up clearly in the numbers. Verizon’s 2025 Data Breach Investigations Report, built from more than 22,000 security incidents and 12,195 confirmed breaches, found that third-party involvement in breaches doubled to 30 percent, up from 15 percent the year before. Exploitation of software vulnerabilities jumped 34 percent over the same stretch.

The pattern already had a face before Verizon put a number on it. In 2020, hackers working for Russia’s SVR intelligence service compromised SolarWinds by planting malicious code inside its Orion software. The breach exposed about 18,000 customers and reached into the US Department of Defense and Department of Justice.

Last year, the Scattered Spider cybercriminal group broke into Marks & Spencer through a third-party supplier, a hit that cost the British retailer 131 million pounds (about $170 million). The toll is not limited to famous names. Supply chain compromises now average $4.91 million per breach and take 267 days to identify and contain, the longest lifecycle of any category tracked in IBM’s 2025 Cost of a Data Breach Report.

Britain Puts Its Banks in Four Companies’ Hands

The Bank of England, the Prudential Regulation Authority and the Financial Conduct Authority (FCA) began joint oversight of the UK’s first four Critical Third Parties, or CTPs, on July 13. HM Treasury designated Amazon Web Services EMEA SARL, Google Cloud EMEA Limited, Microsoft Ireland Operations Ltd and Oracle Corporation UK Limited, the entities that keep much of the UK financial system running.

A disruption at any of the four could affect multiple firms or markets at the same time, regulators warned, given how many lenders and insurers now depend on them for the same infrastructure. Sarah Breeden, the Bank’s deputy governor for financial stability, put the logic in her own words.

As critical third parties become increasingly embedded in the operations of financial institutions, they can introduce new forms of systemic risk.

Nikhil Rathi, chief executive of the FCA, made the arithmetic explicit: “when the same providers serve thousands of firms, a single failure can reverberate across the financial system.” The 2024 CrowdStrike software update that grounded flights and froze hospitals worldwide involved no attacker at all. It taught regulators the same lesson anyway: a handful of vendors sitting underneath thousands of companies means one bad update can do an attacker’s work for free.

The worry itself predates the new regime by years. The Bank’s Financial Policy Committee has tracked the danger since 2017, and by 2018 it was watching cloud providers specifically after flagging how concentrated that market had become. A 2021 review named that concentration a key driver of systemic risk, years before regulators had the legal power to act on it.

An HM Treasury policy statement on the regime found that more than 65 percent of UK firms were already using the same four cloud providers for infrastructure back in 2020. That share has almost certainly grown since. The European Union is building a parallel regime under its own Digital Operational Resilience Act, so the same four companies face similar scrutiny on both sides of the Channel.

Parliament’s Bigger Swing at Suppliers

The financial sector rules are narrow by design, covering a handful of firms in a single industry. A broader bill moving through Parliament, which reached its final Lords stages in mid-July, would pull data centers and managed service providers into the same legal category as power stations and hospitals: critical infrastructure.

Once it clears the Lords and receives royal assent, expected later this year, the bill will update Britain’s 2018 Network and Information Systems Regulations for the first time since they were written. Among its core provisions:

  • Faster reporting: a 24 hour initial notification of a significant incident, followed by a full report within 72 hours
  • Wider scope: data centers and medium to large managed service providers regulated for the first time, alongside existing essential service operators
  • Steeper fines: 10 million pounds or 2 percent of global turnover as standard, rising to 17 million pounds or 4 percent for the worst breaches, plus daily penalties up to 100,000 pounds for violations that continue

One proposed amendment went further than the government’s own draft. During Commons debate, Liberal Democrat MPs pushed a new clause targeting dominant suppliers directly. It would force a “relevant managed service provider” to shed customers once its footprint crossed a defined critical risk threshold, even if that meant ending contracts. The goal: stop any single supplier from running the technology for an entire sector.

Other Liberal Democrat amendments raised the opposite worry, that smaller suppliers, not the giants, would be squeezed hardest by compliance costs they cannot absorb. Advisers at the law firm Taylor Wessing, who track the bill for technology clients, expect a version of that squeeze regardless. A certain standard of cyber compliance will soon be needed just to keep serving key customers, they note, an advantage that tends to favor large, well resourced vendors over smaller rivals who cannot as easily prove they meet it.

Open Source Carries the Same Weak Point

The concentration problem is not confined to regulated finance. It shows up just as clearly in the code libraries sitting underneath almost every piece of modern software, and 2026 has been a rough year for proving it.

On March 30, an attacker hijacked the npm publishing account of the lead maintainer behind axios, one of the most widely used JavaScript libraries, and pushed two poisoned versions live. The attacker disguised the payload as a fake dependency that executed a hidden installation script to deliver the malware.

Axios handles roughly 100 million downloads a week and sits underneath more than 174,000 dependent packages. The damage reached a huge slice of the internet’s software supply before the poisoned versions were pulled, roughly three hours after they went live. Researchers later linked the intrusion to a North Korean state-backed hacking group.

The axios incident was not an outlier. Researchers at Sonatype, which monitors open-source package registries, count a rapidly worsening trend:

  • 454,600-plus new malicious packages identified across open-source registries in 2025 alone, a 75 percent jump from the year before
  • 1.23 million packages now sit in Sonatype’s cumulative list of known malicious open-source code
  • 100 million weekly downloads is the reach of axios alone, the library compromised in March
  • 2.6 billion weekly downloads is the combined reach of chalk and debug, two logging packages hit by a separate phishing attack on a maintainer that same year

The pattern repeats at the infrastructure layer too. On June 1, attackers compromised the automated pipeline that builds and publishes packages under Red Hat’s cloud services namespace on npm. Researchers at Palo Alto Networks’ Unit 42 threat intelligence team say the breach tainted 32 packages across 96 versions, racking up more than 116,000 downloads before it was caught.

Roughly six weeks later, attackers used a near identical payload to compromise four GitHub repositories tied to the AsyncAPI project. This time, Unit 42 said the attackers slipped malicious commits past review through unprotected pre-release branches.

Several of the year’s worst incidents trace back to one actor. Sophos threat researcher Aiden Sinnott told the Financial Times that the hacking group TeamPCP compromised close to 4,000 software projects in a May attack on a GitHub coding tool. Unit 42’s own research since then has tied the same group, or close copycats, to further npm waves in April, May, June and July. Sinnott attributes the escalation partly to how deeply companies now lean on open-source code. Artificial intelligence, he added, is speeding up how fast attackers can comb that code for weaknesses.

One Playbook, Four Very Different Victims

The mechanics repeat even when the targets look nothing alike. A software vendor, a retailer, an open-source maintainer and a cloud namespace all fell to the same basic move: an attacker gets inside one trusted link in a chain, then rides it downstream.

Incident When How Attackers Got In Reported Impact
SolarWinds 2020 Malicious code planted in an Orion software update About 18,000 customers exposed, including two US federal departments
Marks & Spencer 2025 Scattered Spider entered through a third party supplier 131 million pounds (about $170 million) hit to profit
Axios npm package March 2026 Hijacked publishing account of the lead maintainer Reached roughly 100 million weekly downloads before removal
Red Hat npm namespace June 2026 Compromised automated package release pipeline 32 packages and 96 versions tainted, 116,000-plus downloads

Four incidents, four industries, one shared weakness: trust extended to a supplier rarely gets checked as carefully as trust extended to an employee.

Why Do Hackers Keep Picking the Supplier Over the Target?

A single successful supplier breach can hand over dozens or thousands of victims at once, for a fraction of the effort a direct attack on each one would take. Attackers effectively trade a single lock for a master key.

Nathaniel Jones, vice president of security and AI strategy at Darktrace, told the Financial Times the appeal for attackers is simply scale. Scott McKinnon, chief security officer for the UK and Ireland at Palo Alto Networks, said these attacks let hackers jump from a smaller organization straight into a larger or more prominent one, using the smaller company as a stepping stone.

Aiden Sinnott of Sophos points to a further accelerant. Open-source platforms are attractive precisely because so many companies now build on the same shared code, he said, and artificial intelligence is making it faster for attackers to analyze that code for exploitable weaknesses at scale.

The Fix Still Leans on a Few of the Same Vendors

Security advisers largely agree on the remedy, at least in outline. Stuart McKenzie, a managing director at Google-owned Mandiant Consulting, told the Financial Times that companies should build a software bill of materials, a running catalogue of every component and library inside their systems, so they can quickly tell whether they are running something compromised.

The advice extends further. Limit supplier and software access strictly to what a job requires. Watch the attack surface continuously for early signs of trouble. And keep checking systems even after malicious code is removed, since a cleanup does not prove an attacker went no further.

That advice runs into the same wall it is meant to fix. A bill of materials mostly catalogues a company’s dependence on the same small set of registries everyone else relies on too. Those are exactly the platforms the National Cyber Security Centre has flagged as attackers’ highest value targets.

Regulators know it too. FCA guidance is direct about the limits: designation does not remove a firm’s own duty to manage risk, the same due diligence obligation that existed before Amazon, Google, Microsoft and Oracle got their new label.

For now, Britain’s financial system runs on a simple bet: that Amazon, Google, Microsoft and Oracle do not all have a bad day at the same time.

Logan Pierce is a writer and web publisher with over seven years of experience covering consumer technology. He has published work on independent tech blogs and freelance bylines covering Android devices, privacy focused software, and budget gadgets. Logan founded Oton Technology to publish clear, no nonsense tech news and reviews based on real hands on testing. He has personally tested and reviewed dozens of mid range and budget Android phones, written extensively about app privacy, and built and managed multiple WordPress publications over the past decade. Logan holds a bachelor's degree in English and studied digital marketing at a certificate level.

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Trending