Attack vector
Supply-chain attacks cost $4.91M and take 267 days to contain.
A supply-chain compromise, where the attacker reaches an organisation through a trusted vendor, software update, or third-party service, averaged $4.91M per breach in the IBM Cost of a Data Breach Report 2025 and took 267 days to identify and contain. That is the longest lifecycle of any initial attack vector IBM tracks, 26 days above the 241-day all-breach average, because a breach that arrives through a legitimate trust relationship rarely looks malicious until the damage is done.
Average cost
$4.91M
IBM 2025, Figure 9
Time to contain
267 days
Longest of any vector
Cost premium
+11%
vs $4.44M all-breach avg
Share of breaches
15%
Initial-vector share, IBM 2025
Section SC.1
Why the supply-chain vector takes 267 days to contain
The all-breach average lifecycle fell to 241 days in 2025, the lowest in nine years of IBM research. A supply-chain compromise runs 26 days longer, at 267 days, and the reason is structural: the intrusion arrives on the one channel defenders are told to trust.
When an attacker enters through a vendor portal, a signed software update, or a managed-service connection, the initial activity is indistinguishable from normal business. The credentials are valid. The update is signed. The vendor connection is expected. There is no perimeter to breach because a trusted third party has already crossed it. Detection tooling calibrated to catch external intrusion frequently sees nothing, so the attacker accumulates dwell time that a direct attack would not enjoy.
That extended dwell is the cost driver. IBM's data is consistent across every edition: the longer a breach goes unidentified and uncontained, the more it costs. Breaches contained in under 200 days averaged $3.87M in 2025; those that ran beyond 200 days averaged $5.01M, a $1.14M (24%) premium. A supply-chain compromise, at a mean 267-day lifecycle, sits firmly in the expensive half of that distribution by construction.
Section SC.2
Supply chain against the other initial vectors
IBM's 2025 Figure 9 ranks initial attack vectors by average breach cost. Supply-chain compromise sits near the top, second only to malicious-insider incidents, and it is the vector that combines a high cost with the slowest containment.
Third-party vendor or software supply chain (15% of breaches). The dollar figures are the IBM 2025 initial-vector averages; the 267-day lifecycle is what sets supply chain apart from the vectors clustered near it on cost.
Primary source:IBM Cost of a Data Breach Report 2025, Figure 9 (average cost of a breach by initial attack vector) and the breach-lifecycle-by-vector data (supply-chain compromise 267 days to identify and contain).
Section SC.3
The blast radius: one vendor, thousands of victims
The IBM per-breach figure measures the cost to a single breached entity. The defining feature of a supply-chain attack is that a single compromise propagates to every downstream organisation that trusted the vendor, so the aggregate economic impact runs orders of magnitude above the per-victim average.
MOVEit 2023 / Cl0p
~$15.8B
Estimated aggregate across 2,700+ organisations
A single SQL-injection zero-day (CVE-2023-34362) in Progress Software's MOVEit Transfer let the Cl0p ransomware group exfiltrate data from 2,700+ organisations and ~95.8M individuals. Progress's own direct cost was roughly $20-30M; the aggregate downstream impact, modelled at IBM's $165 per record, dwarfs it. That gap between vendor cost and total impact is the supply-chain dynamic in one number.
SolarWinds 2020 / SUNBURST
18,000
Customers who downloaded the trojanised update
Russia's SVR inserted the SUNBURST backdoor into signed Orion updates delivered through the normal patch channel. Roughly 18,000 customers installed it; fewer than 100, plus nine US federal agencies, were actively exploited. SolarWinds disclosed roughly $90M in direct cost; the aggregate across victims was estimated well above $100M. It became the case that turned software-supply-chain security into national policy (US Executive Order 14028).
Section SC.4
The 2026 update
In the IBM Cost of a Data Breach Report 2026 (released 29 July 2026), the supply-chain-compromise initial vector averaged $4.76M (Figure 9), down slightly from $4.91M in 2025, even as the overall global average rose to a record $4.99M and the all-breach lifecycle lengthened to 247 days. The 267-day figure on this page is the 2025 report's per-vector lifecycle, the edition in which IBM published it most prominently, and the reason supply chain remains the vector defenders most consistently underestimate: it is not always the costliest per incident, but it is the hardest to see coming and the widest in blast radius.
Primary source:IBM Cost of a Data Breach Report 2026 (released 29 July 2026): supply-chain vector average $4.76M (Figure 9), global average $4.99M, mean time to identify and contain 247 days.
Cross-references
Case / MOVEit 2023
→~$15.8B aggregate, 2,700+ orgs. The largest supply-chain breach of the decade.
Case / SolarWinds 2020
→18,000 customers, SUNBURST backdoor. The defining software-supply-chain compromise.
Case / Change Healthcare 2024
→$2.45B+, a single vendor at the centre of US healthcare payments.
Industry / Technology
→Where supply-chain blast radius drives downstream-customer cost.
Reference / Global statistics
→Full attack-vector cost table, lifecycle data, year-over-year trends.
Cost / Per record
→The $165 per-record figure behind the MOVEit aggregate estimate.
Schedule F / Reference Q&A
Frequently Asked Questions
Primary source:Attack-vector cost and 267-day supply-chain lifecycle from the IBM Cost of a Data Breach Report 2025; 2026 vector average from the IBM Cost of a Data Breach Report 2026 (Figure 9); third-party-involvement trend from the Verizon 2025 Data Breach Investigations Report; MOVEit and SolarWinds case figures as cited on their case files.