In supply chain cyberattacks, AI is being used to fight AI
Getty Images; BI Logistics companies have reported data breaches, highlighting supply chain vulnerabilities. AI in supply chains increases efficiency but also exposes systems to cyber threats, experts say. Supply chain cyberattacks disrupt operations, prompting calls for AI-enhanced cybersecurity measures. In mid-August, Uber Freight revealed a cybersecurity incident involving unauthorized access to a portion of its systems and data. Days prior, Ceva Logistics, a subsidiary of CMA CGM, reported a data breach that affected numerous companies and leaked their customers' personal information. Weeks before that, Coca-Cola's dairy brand Fairlife was hit by a ransomware attack, prompting the company to temporarily suspend its US operations. Concerns around supply chain hacks are only growing, "as we do more and more intelligent things with these computers and as more and more they're becoming the brain of an autonomous system," Said Ouissal, the founder & CEO of the edge-computing software company ZEDEDA, told Business Insider. Warehouses and plants are adopting AI technologies like trackers on trucks and forklifts, cameras and temperature sensors inside facilities, laptops and tablets, and GPS systems. As they do, they're becoming more vulnerable to cybersecurity incidents, said Bart Bullard, the chief technology officer of Source Logistics, a warehousing, fulfillment, and transportation provider. It's a catch-22: the very technologies that supply chain operators use to stay competitive are also "vectors of entry" for hackers to gain access to company systems, Bullard said. As supply chain executives grapple with this increasingly common challenge, they're also finding that AI can be a part of the solution, Ouissal said. What's at stake in a supply chain cyberattack When a data breach occurs, companies will shut down their systems until they can identify the source of the issue. That can take an average of 247 days, according to an IBM report this year. Supply chain attacks are particularly problematic because a data breach that suspends operations can disrupt the timing of the entire supply chain. Production is delayed and products could expire, Bullard said. That's what happened when Jaguar Land Rover was hit by a cyber attack last fall. Production halted for six weeks. During the shutdown, suppliers lost work, and some small companies went out of business, said Liz James, a managing security consultant at cybersecurity firm NCC Group. Attacks also occur within the software supply chain, Ouissal said. A bad actor hacks a piece of software, which then gets distributed to multiple businesses operating robots. The result is malware running the bots. This type of attack was disclosed last month by CloudSEK and Hudson Rock. The groups revealed that a software supply chain attack poisoned the open-source tool LiteLLM in March 2026. The data breach exposed cloud keys, credentials, and terabytes of data across more than 2,500 organizations. Preventing cyberattacks and responding with AI Fighting cyberattacks in the supply chain requires both preventing and responding to them — often with the assistance of AI-enabled tools, as well as human training and expectation-setting, Ouissal said. Companies use AI to scan software and detect hidden vulnerabilities that humans haven't noticed. AI tools are programmed to detect oddities that deviate from standard patterns. If there's an unexpected issue, the company can immediately deploy a patch to prevent hackers from exploiting the vulnerabilities. Bob Krohn, a partner and manufacturing practice co-leader at consulting firm ISG, said it's important to train employees on cybersecurity best practices, from the C-suite and white-collar supervisors to the shop floor. Workers should be trained to spot phishing scams, and employees with critical system access should use password managers, Bullard said. "Everyone in an enterprise must become AI-security forward thinkers," Bullard said. He added that detecting attacks is increasingly challenging, as deepfake videos and voice calls become more sophisticated, and AI becomes more convincing at emulating behavior. The usual tells of a phishing scam — like odd grammar and misspelled words — disappear with the help of AI, Bullard said. Cyber attacks in the supply chain are also changing how businesses approach supplier contracts and audits, James said. Twenty years ago, many businesses were accustomed to buying the same parts from the same suppliers for decades, according to Krohn. Now, companies tend to have diversified suppliers to manage risks like tariffs. Each time they work with another business, they have to consider new cyber threats, since these entities can view business data and inventory levels, Krohn said. While firewalls exist, there are still gaps that a bad actor could exploit. "You are opening yourselves up to cyber risk in an exponential way," Krohn said. He added: "Choose your supply chain partners carefully. Make sure t
READ ORIGINAL REPORT ↗



