{"id":17494,"date":"2021-01-12T17:34:08","date_gmt":"2021-01-12T17:34:08","guid":{"rendered":"https:\/\/one.sightlinemg.com\/c4isrnet\/uncategorized\/2021\/01\/12\/reports-had-warned-about-supply-chain-hacks\/"},"modified":"2026-08-08T18:00:14","modified_gmt":"2026-08-08T18:00:14","slug":"reports-had-warned-about-supply-chain-hacks","status":"publish","type":"post","link":"https:\/\/one.sightlinemg.com\/c4isrnet\/newsletters\/daily-brief\/2021\/01\/12\/reports-had-warned-about-supply-chain-hacks\/","title":{"rendered":"Reports had warned about supply chain hacks"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">WASHINGTON \u2013 Twice in the last four years, the national security community warned that hacks through IT suppliers posed grave threats to <a href=\"https:\/\/www.c4isrnet.com\/cyber\/2020\/12\/17\/its-going-to-take-a-lot-of-digging-the-pentagons-long-search-to-see-if-anyones-hiding-in-its-networks\/\" target=_blank>defense and intelligence agencies<\/a>. Last month, those warnings proved prescient after suspected Russian hackers <a href=\"https:\/\/www.c4isrnet.com\/cyber\/2020\/12\/14\/reported-russian-hack-of-us-systems-has-implications-for-dod-network-security-plans\/\" target=_blank>infiltrated federal agencies<\/a> through a contractor\u2019s software.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">While intelligence officials said Jan. 5 the hack is an espionage campaign, confirming Russia as the likely source, the two recent reports alerted the community that hackers could disrupt weapons systems by attacking through the supply chain. Those reports suggested the Pentagon must quickly develop methods to reduce risk from its suppliers.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">But the steps the department took to strengthen contractor cybersecurity, including its <a href=\"https:\/\/www.c4isrnet.com\/cyber\/2020\/12\/16\/dod-announces-cybersecurity-certification-pilots\/\" target=_blank>Cybersecurity Maturity Model Certification risk audits,<\/a> did not come in time to prevent breaches of some DoD offices that media reports have disclosed. The Pentagon says its investigation, expected to take significant time, has not turned up signs so far that hackers entered through SolarWinds software that was compromised at various federal offices and large companies.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Despite the warnings and a budding audit system, government agencies had difficulty fending off the latest intrusion. The problem was not a case of identifying the Pentagon\u2019s vulnerabilities. Instead, the difficulty came in part because military leaders haven\u2019t figured out a comprehensive plan to gauge and eliminate risks from contractors, experts said. The solution isn\u2019t simple.<\/p>\n\n\n\t<aside class=\"smg-interstitial-link wp-block-smg-interstitial-link\">\n\t\t<a href=\"https:\/\/one.sightlinemg.com\/c4isrnet\/battlefield-tech\/it-networks-battlefield-tech\/2020\/12\/27\/very-difficult-to-defend-what-happens-if-hackers-are-inside-the-pentagons-networks\/\" class=\"smg-interstitial-link__inner\">\n\t\t\t\t\t\t\t<div class=\"smg-interstitial-link__media\">\n\t\t\t\t\t<img loading=\"lazy\" decoding=\"async\" width=\"300\" height=\"169\" src=\"https:\/\/one.sightlinemg.com\/wp-content\/uploads\/2026\/08\/GettyImages-1204799734.jpg.jpg?w=300\" class=\"smg-interstitial-link__image wp-post-image\" alt=\"\" \/>\t\t\t\t<\/div>\n\t\t\t\t\t\t<div class=\"smg-interstitial-link__content\">\n\t\t\t\t<span class=\"smg-interstitial-link__kicker\">Related<\/span>\n\t\t\t\t<h3 class=\"smg-interstitial-link__title\">\u2018Very difficult to defend\u2019: What happens if hackers are inside the Pentagon\u2019s networks?<\/h3>\n\t\t\t\t\t\t\t\t\t<p class=\"smg-interstitial-link__excerpt\">Suspected Russian hackers&#039; ability to burrow into Pentagon networks through lateral movement after the SolarWinds breach poses tremendous challenges for the department.<\/p>\n\t\t\t\t\t\t\t<\/div>\n\t\t<\/a>\n\t<\/aside>\n\t\n\n\n<p class=\"wp-block-paragraph\">Now, some of the department\u2019s former IT leaders and industry officials suggest that the DoD has to do more with the tools it has, as well as seek new ones. For example, lawmakers recently told the Pentagon in the annual defense policy law to explore the possibility of a threat-hunting program with the defense industrial base.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u201cIt\u2019s been a focus area for us for some time,\u201d said Jan Tighe, former commander of 10th Fleet\/Fleet Cyber Command and deputy chief of naval operations for information warfare. \u201cI think both the public and the private side have not completely solved for how we\u2019re going to deal with hardening our supply chain.\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The recent breach allowed hackers to access networks and move laterally, posing a heightened threat if network connections don\u2019t have comprehensive security controls to prevent burrowing into sensitive systems. To mitigate supply chain risk, experts told C4ISRNET that the Department of Defense and other government agencies need greater insight into potential risks from vendors and stronger tools to defend against these types of attacks.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">As the DoD relies more on third-party suppliers for many IT needs and supply chain attacks are likely to continue to increase, the need for fixes increases. The New York Times <a href=\"https:\/\/www.nytimes.com\/2021\/01\/02\/us\/politics\/russian-hacking-government.html\" target=_blank>reported <\/a>in early January that Russia \u201cexploited multiple layers of the supply chain\u201d to access more networks than previously thought.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u201cEven if you\u2019re buying things as a service, it doesn\u2019t excuse your responsibility in security and assurance,\u201d said Jennifer Bisceglie, CEO of Interos, a supply chain risk management company. \u201cYou will still remain responsible for the risk posture in your operation. And so what are you doing about that, especially if you are sharing or outsourcing the responsibility for a service? What are you doing to make sure that that service doesn\u2019t introduce harm or risk in a way that you weren\u2019t watching for?\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For several years, government commissions have warned about the risk of supply chain attacks. In 2017, the Defense Science Board <a href=\"https:\/\/www.hsdl.org\/?view&#038;did=799509\" target=_blank>warned <\/a>that attacks through software could disrupt weapons systems. In 2019, the National Counterintelligence and Security Center <a href=\"https:\/\/www.dni.gov\/files\/NCSC\/documents\/supplychain\/20190327-Software-Supply-Chain-Attacks02.pdf\" target=_blank>advised <\/a>that malicious actors were increasingly using the avenue to breach networks.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u201cSoftware supply chain attacks are particularly bothersome and insidious because they violate the basic and assumed trust between software provider and consumer,\u201d the NCSC report stated.<\/p>\n\n\n\t<aside class=\"smg-interstitial-link wp-block-smg-interstitial-link\">\n\t\t<a href=\"https:\/\/one.sightlinemg.com\/c4isrnet\/smr\/2019\/11\/11\/two-years-in-how-has-a-new-strategy-changed-cyber-operations\/\" class=\"smg-interstitial-link__inner\">\n\t\t\t\t\t\t\t<div class=\"smg-interstitial-link__media\">\n\t\t\t\t\t<img loading=\"lazy\" decoding=\"async\" width=\"300\" height=\"198\" src=\"https:\/\/one.sightlinemg.com\/wp-content\/uploads\/2026\/08\/NSA.jpg.jpg?w=300\" class=\"smg-interstitial-link__image wp-post-image\" alt=\"\" \/>\t\t\t\t<\/div>\n\t\t\t\t\t\t<div class=\"smg-interstitial-link__content\">\n\t\t\t\t<span class=\"smg-interstitial-link__kicker\">Related<\/span>\n\t\t\t\t<h3 class=\"smg-interstitial-link__title\">Two years in, how has a new strategy changed cyber operations?<\/h3>\n\t\t\t\t\t\t\t\t\t<p class=\"smg-interstitial-link__excerpt\">This is the story of how, in two short years, a new cybersecurity strategy has forced the national security community to rethink cyber operations and how &quot;persistent engagment&quot; will work.<\/p>\n\t\t\t\t\t\t\t<\/div>\n\t\t<\/a>\n\t<\/aside>\n\t\n\n\n<p class=\"wp-block-paragraph\">One challenge for the department is that risks differ for each vendor, meaning there\u2019s no one-size-fits-all solution. To improve visibility, the department should require vendors to assess and document any risks before it awards contracts, experts suggest. That would give the department more information to make purchasing decisions and to review if a compromise happens.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u201cIt is possible for every vendor to know something about the risks that are present in its supply chain,\u201d said Robert Metzger, a member of the Defense Science Board\u2019s 2017 study on supply chain vulnerabilities. He added, \u201cThis idea that we expect each supplier to assess and describe their own supply chain risks and to present their plans for mitigating that risk, that\u2019s a sound idea, I believe, even if it is a new and potentially difficult burden.\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For a variety of reasons, including a shortage of IT and cybersecurity talent and cost savings, the government relies on vendors for IT needs. But the way in which the companies are interconnected poses further unknowns for managing risks.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u201cWe stop at understanding who our supplier is, and we don\u2019t really give a thought to who their customers are, who are their suppliers, where they\u2019re reliant around the world, what countries that they\u2019re relying on, what other companies are relying on,\u201d Bisceglie said.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The Cybersecurity Maturity Model Certification, an audit system to evaluate the strength of contractors\u2019 cybersecurity, will improve the DoD\u2019s knowledge of its suppliers but focuses more on cybersecurity on an organization\u2019s perimeter. CMMC is a solid foundation to build on, Metzger said.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u201cWe will need to examine carefully what attributes of the CMMC control set should be emphasized or even changed, in order to address this kind of supply chain delivered threat,\u201d he said.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><b>What will it take to be secure?<\/b><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Advanced persistent threats, like Russian hackers, will always have an interest in the DoD. The difficulty for the department is that many suppliers don\u2019t have the skillsets or resources to defend against nation-state hackers.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u201cIt\u2019s a really tough problem to figure out how you\u2019re going to design resiliency against those kinds of attacks,\u201d said retired Rear Adm. Danelle Barrett, former deputy Navy CIO and cybersecurity division director.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">However, Barrett said that the suppliers and the department can still improve safeguards against advanced actors through consistent penetration testing, threat modeling and monitoring, as well as establishing a cybersecurity baseline, the posture when the network is fully secured.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Other steps could include increased behavioral analysis on networks to look for people acting unusually and a more collective approach to network defense by the government.<\/p>\n\n\n\t<aside class=\"smg-interstitial-link wp-block-smg-interstitial-link\">\n\t\t<a href=\"https:\/\/one.sightlinemg.com\/c4isrnet\/industry\/2020\/06\/25\/lightning-in-her-veins-how-katie-arrington-is-convincing-defense-contractors-to-love-cybersecurity\/\" class=\"smg-interstitial-link__inner\">\n\t\t\t\t\t\t\t<div class=\"smg-interstitial-link__media\">\n\t\t\t\t\t<img loading=\"lazy\" decoding=\"async\" width=\"300\" height=\"200\" src=\"https:\/\/one.sightlinemg.com\/wp-content\/uploads\/2026\/08\/6061025.jpg.jpg?w=300\" class=\"smg-interstitial-link__image wp-post-image\" alt=\"\" \/>\t\t\t\t<\/div>\n\t\t\t\t\t\t<div class=\"smg-interstitial-link__content\">\n\t\t\t\t<span class=\"smg-interstitial-link__kicker\">Related<\/span>\n\t\t\t\t<h3 class=\"smg-interstitial-link__title\">\u2018Lightning in her veins\u2019: How Katie Arrington is convincing defense contractors to love cybersecurity<\/h3>\n\t\t\t\t\t\t\t\t\t<p class=\"smg-interstitial-link__excerpt\">Katie Arrington is leading the Pentagon&#039;s overhaul of cybersecurity requirements for defense contractors. Now she has to convince 300,000 companies to follow them.<\/p>\n\t\t\t\t\t\t\t<\/div>\n\t\t<\/a>\n\t<\/aside>\n\t\n\n\n<p class=\"wp-block-paragraph\">\u201cIf you look across multiple networks and correlate anomalous network behavior across the whole government, you might have seen this if you could see across everybody and can sort between what is just anomalous and what is actually malicious,\u201d Tighe said. \u201cIf you see anomalous that all looks the same across the whole of government \u2026 and potentially even with the private sector, I think that you increase your ability, you use the power of a collective defense to our advantage.\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Today the government doesn\u2019t have the real-time ability to search across networks for early warning signs, Tighe added. However, the 2021 National Defense Authorization Act contains several measures that could eventually improve supply chain security.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Besides a feasibility study on a defense industrial base threat-hunting program, the law directs the department to assess possible programs to share information with the defense industrial base and place commercial off-the-shelf sensors on contractors\u2019 public-facing attack surfaces. The law designates the department\u2019s principal cyber adviser as the top official responsible for DIB cybersecurity issues.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Even with the best visibility into supply chain risks, advanced hackers will still search for new openings, making teamwork key.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u201cThe positive lesson that should be taken from SolarWinds is that supply chain risk is everybody\u2019s problem,\u201d Metzger said. \u201cIt is a very large and complex problem, and it will not accommodate anything like a business-as-usual approach.\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><i>Mark Pomerleau contributed to this report.<\/i><\/p>\n","protected":false},"excerpt":{"rendered":"<p>The path to protecting the DoD from breaches through contractors isn\u2019t easy.<\/p>\n","protected":false},"author":7,"featured_media":32257,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"_yoast_wpseo_meta-robots-noindex":"","_yoast_wpseo_meta-robots-nofollow":"","_yoast_wpseo_canonical":"","_acf":"","_yoast_wpseo_primary_category":106,"_jetpack_feature_clip_id":0,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","_smg_distribution_targets":{"4":{"categories":["daily-news-roundup","newsletters"],"primary_category":"daily-news-roundup"},"5":{"categories":["daily-news-roundup","newsletters"],"primary_category":"daily-news-roundup"},"6":{"categories":["daily-news-roundup","newsletters"],"primary_category":"daily-news-roundup"},"7":{"categories":["daily-news-roundup","newsletters"],"primary_category":"daily-news-roundup"},"10":{"categories":["daily-news-roundup","newsletters","pentagon"],"primary_category":"pentagon"}}},"categories":[106,32],"tags":[],"coauthors":[3252],"class_list":["post-17494","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-daily-brief","category-newsletters"],"acf":{"subheadline":"","legacy_arc_id":"GZKY3WOFEVF6HHLFPV3VBTZHWM","arc_canonical_url":"\/it-networks\/2021\/01\/12\/reports-had-warned-about-supply-chain-hacks\/","remove_feature_photo":false,"is_sponsored":false,"subtype":"","redirect_url":"","disable_inline_ads":false,"native_logo_pretext":"Presented By:"},"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v26.0 (Yoast SEO v28.1) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>Reports had warned about supply chain hacks - C4ISRNet<\/title>\n<meta name=\"description\" content=\"The path to protecting the DoD from breaches through contractors isn\u2019t easy.\" \/>\n<meta name=\"robots\" content=\"noindex, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Reports had warned about supply chain hacks\" \/>\n<meta property=\"og:description\" content=\"The path to protecting the DoD from breaches through contractors isn\u2019t easy.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/one.sightlinemg.com\/c4isrnet\/newsletters\/daily-brief\/2021\/01\/12\/reports-had-warned-about-supply-chain-hacks\/\" \/>\n<meta property=\"og:site_name\" content=\"C4ISRNet\" \/>\n<meta property=\"article:published_time\" content=\"2021-01-12T17:34:08+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-08-08T18:00:14+00:00\" \/>\n<meta name=\"author\" content=\"Andrew Eversden\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Andrew Eversden\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"6 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\n\t    \"@context\": \"https:\\\/\\\/schema.org\",\n\t    \"@graph\": [\n\t        {\n\t            \"@type\": \"Article\",\n\t            \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/c4isrnet\\\/newsletters\\\/daily-brief\\\/2021\\\/01\\\/12\\\/reports-had-warned-about-supply-chain-hacks\\\/#article\",\n\t            \"isPartOf\": {\n\t                \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/c4isrnet\\\/newsletters\\\/daily-brief\\\/2021\\\/01\\\/12\\\/reports-had-warned-about-supply-chain-hacks\\\/\"\n\t            },\n\t            \"author\": {\n\t                \"name\": \"migration\",\n\t                \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/c4isrnet\\\/#\\\/schema\\\/person\\\/cc76c831bb37a926738c8391fca7a3b1\"\n\t            },\n\t            \"headline\": \"Reports had warned about supply chain hacks\",\n\t            \"datePublished\": \"2021-01-12T17:34:08+00:00\",\n\t            \"dateModified\": \"2026-08-08T18:00:14+00:00\",\n\t            \"mainEntityOfPage\": {\n\t                \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/c4isrnet\\\/newsletters\\\/daily-brief\\\/2021\\\/01\\\/12\\\/reports-had-warned-about-supply-chain-hacks\\\/\"\n\t            },\n\t            \"wordCount\": 1293,\n\t            \"commentCount\": 0,\n\t            \"publisher\": {\n\t                \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/c4isrnet\\\/#organization\"\n\t            },\n\t            \"image\": {\n\t                \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/c4isrnet\\\/newsletters\\\/daily-brief\\\/2021\\\/01\\\/12\\\/reports-had-warned-about-supply-chain-hacks\\\/#primaryimage\"\n\t            },\n\t            \"thumbnailUrl\": \"https:\\\/\\\/one.sightlinemg.com\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/ISR-cyber-theme.jpg.jpg\",\n\t            \"articleSection\": [\n\t                \"Daily Brief\",\n\t                \"Newsletters\"\n\t            ],\n\t            \"inLanguage\": \"en-US\",\n\t            \"potentialAction\": [\n\t                {\n\t                    \"@type\": \"CommentAction\",\n\t                    \"name\": \"Comment\",\n\t                    \"target\": [\n\t                        \"https:\\\/\\\/one.sightlinemg.com\\\/c4isrnet\\\/newsletters\\\/daily-brief\\\/2021\\\/01\\\/12\\\/reports-had-warned-about-supply-chain-hacks\\\/#respond\"\n\t                    ]\n\t                }\n\t            ]\n\t        },\n\t        {\n\t            \"@type\": \"WebPage\",\n\t            \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/c4isrnet\\\/newsletters\\\/daily-brief\\\/2021\\\/01\\\/12\\\/reports-had-warned-about-supply-chain-hacks\\\/\",\n\t            \"url\": \"https:\\\/\\\/one.sightlinemg.com\\\/c4isrnet\\\/newsletters\\\/daily-brief\\\/2021\\\/01\\\/12\\\/reports-had-warned-about-supply-chain-hacks\\\/\",\n\t            \"name\": \"Reports had warned about supply chain hacks - C4ISRNet\",\n\t            \"isPartOf\": {\n\t                \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/c4isrnet\\\/#website\"\n\t            },\n\t            \"primaryImageOfPage\": {\n\t                \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/c4isrnet\\\/newsletters\\\/daily-brief\\\/2021\\\/01\\\/12\\\/reports-had-warned-about-supply-chain-hacks\\\/#primaryimage\"\n\t            },\n\t            \"image\": {\n\t                \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/c4isrnet\\\/newsletters\\\/daily-brief\\\/2021\\\/01\\\/12\\\/reports-had-warned-about-supply-chain-hacks\\\/#primaryimage\"\n\t            },\n\t            \"thumbnailUrl\": \"https:\\\/\\\/one.sightlinemg.com\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/ISR-cyber-theme.jpg.jpg\",\n\t            \"datePublished\": \"2021-01-12T17:34:08+00:00\",\n\t            \"dateModified\": \"2026-08-08T18:00:14+00:00\",\n\t            \"description\": \"The path to protecting the DoD from breaches through contractors isn\u2019t easy.\",\n\t            \"breadcrumb\": {\n\t                \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/c4isrnet\\\/newsletters\\\/daily-brief\\\/2021\\\/01\\\/12\\\/reports-had-warned-about-supply-chain-hacks\\\/#breadcrumb\"\n\t            },\n\t            \"inLanguage\": \"en-US\",\n\t            \"potentialAction\": [\n\t                {\n\t                    \"@type\": \"ReadAction\",\n\t                    \"target\": [\n\t                        \"https:\\\/\\\/one.sightlinemg.com\\\/c4isrnet\\\/newsletters\\\/daily-brief\\\/2021\\\/01\\\/12\\\/reports-had-warned-about-supply-chain-hacks\\\/\"\n\t                    ]\n\t                }\n\t            ]\n\t        },\n\t        {\n\t            \"@type\": \"ImageObject\",\n\t            \"inLanguage\": \"en-US\",\n\t            \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/c4isrnet\\\/newsletters\\\/daily-brief\\\/2021\\\/01\\\/12\\\/reports-had-warned-about-supply-chain-hacks\\\/#primaryimage\",\n\t            \"url\": \"https:\\\/\\\/one.sightlinemg.com\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/ISR-cyber-theme.jpg.jpg\",\n\t            \"contentUrl\": \"https:\\\/\\\/one.sightlinemg.com\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/ISR-cyber-theme.jpg.jpg\"\n\t        },\n\t        {\n\t            \"@type\": \"BreadcrumbList\",\n\t            \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/c4isrnet\\\/newsletters\\\/daily-brief\\\/2021\\\/01\\\/12\\\/reports-had-warned-about-supply-chain-hacks\\\/#breadcrumb\",\n\t            \"itemListElement\": [\n\t                {\n\t                    \"@type\": \"ListItem\",\n\t                    \"position\": 1,\n\t                    \"name\": \"Home\",\n\t                    \"item\": \"https:\\\/\\\/one.sightlinemg.com\\\/c4isrnet\\\/\",\n\t                    \"ad_zone\": \"home\"\n\t                },\n\t                {\n\t                    \"@type\": \"ListItem\",\n\t                    \"position\": 2,\n\t                    \"name\": \"Daily Brief\",\n\t                    \"item\": \"https:\\\/\\\/one.sightlinemg.com\\\/c4isrnet\\\/newsletters\\\/daily-brief\\\/\",\n\t                    \"ad_zone\": \"daily-brief\"\n\t                },\n\t                {\n\t                    \"@type\": \"ListItem\",\n\t                    \"position\": 3,\n\t                    \"name\": \"Reports had warned about supply chain hacks\"\n\t                }\n\t            ]\n\t        },\n\t        {\n\t            \"@type\": \"WebSite\",\n\t            \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/c4isrnet\\\/#website\",\n\t            \"url\": \"https:\\\/\\\/one.sightlinemg.com\\\/c4isrnet\\\/\",\n\t            \"name\": \"C4ISRNet\",\n\t            \"description\": \"Media for the Intelligence-Age Military | C4ISRNET\",\n\t            \"publisher\": {\n\t                \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/c4isrnet\\\/#organization\"\n\t            },\n\t            \"potentialAction\": [\n\t                {\n\t                    \"@type\": \"SearchAction\",\n\t                    \"target\": {\n\t                        \"@type\": \"EntryPoint\",\n\t                        \"urlTemplate\": \"https:\\\/\\\/one.sightlinemg.com\\\/c4isrnet\\\/?s={search_term_string}\"\n\t                    },\n\t                    \"query-input\": {\n\t                        \"@type\": \"PropertyValueSpecification\",\n\t                        \"valueRequired\": true,\n\t                        \"valueName\": \"search_term_string\"\n\t                    }\n\t                }\n\t            ],\n\t            \"inLanguage\": \"en-US\"\n\t        },\n\t        {\n\t            \"@type\": \"Organization\",\n\t            \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/c4isrnet\\\/#organization\",\n\t            \"name\": \"C4ISRNet\",\n\t            \"url\": \"https:\\\/\\\/one.sightlinemg.com\\\/c4isrnet\\\/\",\n\t            \"logo\": {\n\t                \"@type\": \"ImageObject\",\n\t                \"inLanguage\": \"en-US\",\n\t                \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/c4isrnet\\\/#\\\/schema\\\/logo\\\/image\\\/\",\n\t                \"url\": \"https:\\\/\\\/one.sightlinemg.com\\\/wp-content\\\/uploads\\\/2026\\\/06\\\/c4isrnet-logo-white.png\",\n\t                \"contentUrl\": \"https:\\\/\\\/one.sightlinemg.com\\\/wp-content\\\/uploads\\\/2026\\\/06\\\/c4isrnet-logo-white.png\",\n\t                \"caption\": \"C4ISRNet\"\n\t            },\n\t            \"image\": {\n\t                \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/c4isrnet\\\/#\\\/schema\\\/logo\\\/image\\\/\"\n\t            }\n\t        },\n\t        {\n\t            \"@type\": \"Person\",\n\t            \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/c4isrnet\\\/#\\\/schema\\\/person\\\/cc76c831bb37a926738c8391fca7a3b1\",\n\t            \"name\": \"migration\",\n\t            \"image\": {\n\t                \"@type\": \"ImageObject\",\n\t                \"inLanguage\": \"en-US\",\n\t                \"@id\": \"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/9e8d47be443ce94ce7fc357677b5f9c70235bb1f59e7267a102a74af58c04f59?s=96&d=mm&r=gcf4cb6ee0ec29e49e7a963234e4340ec\",\n\t                \"url\": \"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/9e8d47be443ce94ce7fc357677b5f9c70235bb1f59e7267a102a74af58c04f59?s=96&d=mm&r=g\",\n\t                \"contentUrl\": \"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/9e8d47be443ce94ce7fc357677b5f9c70235bb1f59e7267a102a74af58c04f59?s=96&d=mm&r=g\",\n\t                \"caption\": \"migration\"\n\t            },\n\t            \"url\": \"https:\\\/\\\/one.sightlinemg.com\\\/c4isrnet\\\/author\\\/migration\\\/\"\n\t        }\n\t    ]\n\t}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"Reports had warned about supply chain hacks - C4ISRNet","description":"The path to protecting the DoD from breaches through contractors isn\u2019t easy.","robots":{"index":"noindex","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"og_locale":"en_US","og_type":"article","og_title":"Reports had warned about supply chain hacks","og_description":"The path to protecting the DoD from breaches through contractors isn\u2019t easy.","og_url":"https:\/\/one.sightlinemg.com\/c4isrnet\/newsletters\/daily-brief\/2021\/01\/12\/reports-had-warned-about-supply-chain-hacks\/","og_site_name":"C4ISRNet","article_published_time":"2021-01-12T17:34:08+00:00","article_modified_time":"2026-08-08T18:00:14+00:00","author":"Andrew Eversden","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Andrew Eversden","Est. reading time":"6 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/one.sightlinemg.com\/c4isrnet\/newsletters\/daily-brief\/2021\/01\/12\/reports-had-warned-about-supply-chain-hacks\/#article","isPartOf":{"@id":"https:\/\/one.sightlinemg.com\/c4isrnet\/newsletters\/daily-brief\/2021\/01\/12\/reports-had-warned-about-supply-chain-hacks\/"},"author":{"name":"migration","@id":"https:\/\/one.sightlinemg.com\/c4isrnet\/#\/schema\/person\/cc76c831bb37a926738c8391fca7a3b1"},"headline":"Reports had warned about supply chain hacks","datePublished":"2021-01-12T17:34:08+00:00","dateModified":"2026-08-08T18:00:14+00:00","mainEntityOfPage":{"@id":"https:\/\/one.sightlinemg.com\/c4isrnet\/newsletters\/daily-brief\/2021\/01\/12\/reports-had-warned-about-supply-chain-hacks\/"},"wordCount":1293,"commentCount":0,"publisher":{"@id":"https:\/\/one.sightlinemg.com\/c4isrnet\/#organization"},"image":{"@id":"https:\/\/one.sightlinemg.com\/c4isrnet\/newsletters\/daily-brief\/2021\/01\/12\/reports-had-warned-about-supply-chain-hacks\/#primaryimage"},"thumbnailUrl":"https:\/\/one.sightlinemg.com\/wp-content\/uploads\/2026\/08\/ISR-cyber-theme.jpg.jpg","articleSection":["Daily Brief","Newsletters"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/one.sightlinemg.com\/c4isrnet\/newsletters\/daily-brief\/2021\/01\/12\/reports-had-warned-about-supply-chain-hacks\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/one.sightlinemg.com\/c4isrnet\/newsletters\/daily-brief\/2021\/01\/12\/reports-had-warned-about-supply-chain-hacks\/","url":"https:\/\/one.sightlinemg.com\/c4isrnet\/newsletters\/daily-brief\/2021\/01\/12\/reports-had-warned-about-supply-chain-hacks\/","name":"Reports had warned about supply chain hacks - C4ISRNet","isPartOf":{"@id":"https:\/\/one.sightlinemg.com\/c4isrnet\/#website"},"primaryImageOfPage":{"@id":"https:\/\/one.sightlinemg.com\/c4isrnet\/newsletters\/daily-brief\/2021\/01\/12\/reports-had-warned-about-supply-chain-hacks\/#primaryimage"},"image":{"@id":"https:\/\/one.sightlinemg.com\/c4isrnet\/newsletters\/daily-brief\/2021\/01\/12\/reports-had-warned-about-supply-chain-hacks\/#primaryimage"},"thumbnailUrl":"https:\/\/one.sightlinemg.com\/wp-content\/uploads\/2026\/08\/ISR-cyber-theme.jpg.jpg","datePublished":"2021-01-12T17:34:08+00:00","dateModified":"2026-08-08T18:00:14+00:00","description":"The path to protecting the DoD from breaches through contractors isn\u2019t easy.","breadcrumb":{"@id":"https:\/\/one.sightlinemg.com\/c4isrnet\/newsletters\/daily-brief\/2021\/01\/12\/reports-had-warned-about-supply-chain-hacks\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/one.sightlinemg.com\/c4isrnet\/newsletters\/daily-brief\/2021\/01\/12\/reports-had-warned-about-supply-chain-hacks\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/one.sightlinemg.com\/c4isrnet\/newsletters\/daily-brief\/2021\/01\/12\/reports-had-warned-about-supply-chain-hacks\/#primaryimage","url":"https:\/\/one.sightlinemg.com\/wp-content\/uploads\/2026\/08\/ISR-cyber-theme.jpg.jpg","contentUrl":"https:\/\/one.sightlinemg.com\/wp-content\/uploads\/2026\/08\/ISR-cyber-theme.jpg.jpg"},{"@type":"BreadcrumbList","@id":"https:\/\/one.sightlinemg.com\/c4isrnet\/newsletters\/daily-brief\/2021\/01\/12\/reports-had-warned-about-supply-chain-hacks\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/one.sightlinemg.com\/c4isrnet\/","ad_zone":"home"},{"@type":"ListItem","position":2,"name":"Daily Brief","item":"https:\/\/one.sightlinemg.com\/c4isrnet\/newsletters\/daily-brief\/","ad_zone":"daily-brief"},{"@type":"ListItem","position":3,"name":"Reports had warned about supply chain hacks"}]},{"@type":"WebSite","@id":"https:\/\/one.sightlinemg.com\/c4isrnet\/#website","url":"https:\/\/one.sightlinemg.com\/c4isrnet\/","name":"C4ISRNet","description":"Media for the Intelligence-Age Military | C4ISRNET","publisher":{"@id":"https:\/\/one.sightlinemg.com\/c4isrnet\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/one.sightlinemg.com\/c4isrnet\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/one.sightlinemg.com\/c4isrnet\/#organization","name":"C4ISRNet","url":"https:\/\/one.sightlinemg.com\/c4isrnet\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/one.sightlinemg.com\/c4isrnet\/#\/schema\/logo\/image\/","url":"https:\/\/one.sightlinemg.com\/wp-content\/uploads\/2026\/06\/c4isrnet-logo-white.png","contentUrl":"https:\/\/one.sightlinemg.com\/wp-content\/uploads\/2026\/06\/c4isrnet-logo-white.png","caption":"C4ISRNet"},"image":{"@id":"https:\/\/one.sightlinemg.com\/c4isrnet\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/one.sightlinemg.com\/c4isrnet\/#\/schema\/person\/cc76c831bb37a926738c8391fca7a3b1","name":"migration","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/9e8d47be443ce94ce7fc357677b5f9c70235bb1f59e7267a102a74af58c04f59?s=96&d=mm&r=gcf4cb6ee0ec29e49e7a963234e4340ec","url":"https:\/\/secure.gravatar.com\/avatar\/9e8d47be443ce94ce7fc357677b5f9c70235bb1f59e7267a102a74af58c04f59?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/9e8d47be443ce94ce7fc357677b5f9c70235bb1f59e7267a102a74af58c04f59?s=96&d=mm&r=g","caption":"migration"},"url":"https:\/\/one.sightlinemg.com\/c4isrnet\/author\/migration\/"}]}},"jetpack_sharing_enabled":true,"distributor_meta":false,"distributor_terms":false,"distributor_media":false,"distributor_original_site_name":"C4ISRNet","distributor_original_site_url":"https:\/\/one.sightlinemg.com\/c4isrnet","push-errors":false,"jetpack_featured_media_url":"https:\/\/one.sightlinemg.com\/wp-content\/uploads\/2026\/08\/ISR-cyber-theme.jpg.jpg","_links":{"self":[{"href":"https:\/\/one.sightlinemg.com\/c4isrnet\/wp-json\/wp\/v2\/posts\/17494","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/one.sightlinemg.com\/c4isrnet\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/one.sightlinemg.com\/c4isrnet\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/one.sightlinemg.com\/c4isrnet\/wp-json\/wp\/v2\/users\/7"}],"replies":[{"embeddable":true,"href":"https:\/\/one.sightlinemg.com\/c4isrnet\/wp-json\/wp\/v2\/comments?post=17494"}],"version-history":[{"count":2,"href":"https:\/\/one.sightlinemg.com\/c4isrnet\/wp-json\/wp\/v2\/posts\/17494\/revisions"}],"predecessor-version":[{"id":43441,"href":"https:\/\/one.sightlinemg.com\/c4isrnet\/wp-json\/wp\/v2\/posts\/17494\/revisions\/43441"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/one.sightlinemg.com\/c4isrnet\/wp-json\/wp\/v2\/posts\/32257"}],"wp:attachment":[{"href":"https:\/\/one.sightlinemg.com\/c4isrnet\/wp-json\/wp\/v2\/media?parent=17494"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/one.sightlinemg.com\/c4isrnet\/wp-json\/wp\/v2\/categories?post=17494"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/one.sightlinemg.com\/c4isrnet\/wp-json\/wp\/v2\/tags?post=17494"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/one.sightlinemg.com\/c4isrnet\/wp-json\/wp\/v2\/coauthors?post=17494"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}