Form: Cost-of-Breach DisclosureSource: IBM Cost of a Data BreachFiled: 28 Apr 2026
DataBreachCost.comOpen calc
Vector File SC / Supply-Chain CompromiseIBM 2025, Figure 9

Attack vector

Supply-chain attacks cost $4.91M and take 267 days to contain.

A supply-chain compromise, where the attacker reaches an organisation through a trusted vendor, software update, or third-party service, averaged $4.91M per breach in the IBM Cost of a Data Breach Report 2025 and took 267 days to identify and contain. That is the longest lifecycle of any initial attack vector IBM tracks, 26 days above the 241-day all-breach average, because a breach that arrives through a legitimate trust relationship rarely looks malicious until the damage is done.

Average cost

$4.91M

IBM 2025, Figure 9

Time to contain

267 days

Longest of any vector

Cost premium

+11%

vs $4.44M all-breach avg

Share of breaches

15%

Initial-vector share, IBM 2025

Section SC.1

Why the supply-chain vector takes 267 days to contain

The all-breach average lifecycle fell to 241 days in 2025, the lowest in nine years of IBM research. A supply-chain compromise runs 26 days longer, at 267 days, and the reason is structural: the intrusion arrives on the one channel defenders are told to trust.

When an attacker enters through a vendor portal, a signed software update, or a managed-service connection, the initial activity is indistinguishable from normal business. The credentials are valid. The update is signed. The vendor connection is expected. There is no perimeter to breach because a trusted third party has already crossed it. Detection tooling calibrated to catch external intrusion frequently sees nothing, so the attacker accumulates dwell time that a direct attack would not enjoy.

That extended dwell is the cost driver. IBM's data is consistent across every edition: the longer a breach goes unidentified and uncontained, the more it costs. Breaches contained in under 200 days averaged $3.87M in 2025; those that ran beyond 200 days averaged $5.01M, a $1.14M (24%) premium. A supply-chain compromise, at a mean 267-day lifecycle, sits firmly in the expensive half of that distribution by construction.

Section SC.2

Supply chain against the other initial vectors

IBM's 2025 Figure 9 ranks initial attack vectors by average breach cost. Supply-chain compromise sits near the top, second only to malicious-insider incidents, and it is the vector that combines a high cost with the slowest containment.

Malicious Insider$4.92M
Supply Chain Compromise$4.91M
Phishing$4.80M
Credential Theft$4.67M
Denial-of-Service$4.41M
Vulnerability Exploitation$4.24M

Third-party vendor or software supply chain (15% of breaches). The dollar figures are the IBM 2025 initial-vector averages; the 267-day lifecycle is what sets supply chain apart from the vectors clustered near it on cost.

Primary source:IBM Cost of a Data Breach Report 2025, Figure 9 (average cost of a breach by initial attack vector) and the breach-lifecycle-by-vector data (supply-chain compromise 267 days to identify and contain).

Section SC.3

The blast radius: one vendor, thousands of victims

The IBM per-breach figure measures the cost to a single breached entity. The defining feature of a supply-chain attack is that a single compromise propagates to every downstream organisation that trusted the vendor, so the aggregate economic impact runs orders of magnitude above the per-victim average.

MOVEit 2023 / Cl0p

~$15.8B

Estimated aggregate across 2,700+ organisations

A single SQL-injection zero-day (CVE-2023-34362) in Progress Software's MOVEit Transfer let the Cl0p ransomware group exfiltrate data from 2,700+ organisations and ~95.8M individuals. Progress's own direct cost was roughly $20-30M; the aggregate downstream impact, modelled at IBM's $165 per record, dwarfs it. That gap between vendor cost and total impact is the supply-chain dynamic in one number.

SolarWinds 2020 / SUNBURST

18,000

Customers who downloaded the trojanised update

Russia's SVR inserted the SUNBURST backdoor into signed Orion updates delivered through the normal patch channel. Roughly 18,000 customers installed it; fewer than 100, plus nine US federal agencies, were actively exploited. SolarWinds disclosed roughly $90M in direct cost; the aggregate across victims was estimated well above $100M. It became the case that turned software-supply-chain security into national policy (US Executive Order 14028).

Section SC.4

The 2026 update

In the IBM Cost of a Data Breach Report 2026 (released 29 July 2026), the supply-chain-compromise initial vector averaged $4.76M (Figure 9), down slightly from $4.91M in 2025, even as the overall global average rose to a record $4.99M and the all-breach lifecycle lengthened to 247 days. The 267-day figure on this page is the 2025 report's per-vector lifecycle, the edition in which IBM published it most prominently, and the reason supply chain remains the vector defenders most consistently underestimate: it is not always the costliest per incident, but it is the hardest to see coming and the widest in blast radius.

Primary source:IBM Cost of a Data Breach Report 2026 (released 29 July 2026): supply-chain vector average $4.76M (Figure 9), global average $4.99M, mean time to identify and contain 247 days.

Cross-references

Schedule F / Reference Q&A

Frequently Asked Questions

Primary source:Attack-vector cost and 267-day supply-chain lifecycle from the IBM Cost of a Data Breach Report 2025; 2026 vector average from the IBM Cost of a Data Breach Report 2026 (Figure 9); third-party-involvement trend from the Verizon 2025 Data Breach Investigations Report; MOVEit and SolarWinds case figures as cited on their case files.