☰Series Navigation (13 parts)
There is a certain kind of security advice that sounds wise and is dangerous. Simplify. Go back to basics. The old technology was safer because it was dumber. I’ve heard versions of it my whole career, usually after a breach, usually from someone who wants a clean answer to a messy problem.
Hezbollah followed that advice to the letter. It gave up the powerful, connected, trackable smartphone for the simple, dumb, untrackable pager, and the simplification is exactly what killed its people. The previous article covered what happened. This one is about why the low-tech move failed, because the reason it failed is a warning for everyone who buys anything. That is all of us.
Why didn’t going low-tech protect Hezbollah?
Because low-tech solved the wrong problem.
The threat Hezbollah was defending against was surveillance. Smartphones leak location and can be turned into listening devices, so the group reasoned that a device with no GPS, no microphone, and no internet connection would close that hole. On that specific threat, the reasoning was sound. A pager genuinely cannot be tracked the way a phone can.
But the attack that came was not surveillance. It was sabotage, built into the device before Hezbollah ever touched it. And against that threat, simple versus sophisticated made no difference at all. A dumb device can hide a bomb just as well as a smart one, maybe better, because nobody is scanning a pager’s traffic or worrying about its firmware. Hezbollah moved from a threat it could see to a threat it could not, and felt safer the whole way.
This is the trap in the “go back to basics” advice. Simplifying a system reduces some risks and does nothing for others, and it can hide the ones it leaves behind a feeling of having done something. The centrifuge operators at Natanz felt safe behind their air gap. Hezbollah felt safe behind its pagers. Both had addressed the threat on their minds and left the flank open, and in both cases the attacker walked in through the flank.
What is a supply chain attack?
A supply chain attack is one where the attacker doesn’t come at you directly. They compromise something you buy or depend on, and let your own trust carry the attack the last mile.
You don’t build your own computers, write your own operating system, or manufacture your own network hardware. Nobody does. You buy them, from companies you mostly don’t know, who buy parts from other companies you’ve never heard of, assembled in places you’ll never see. Every product that arrives at your door is the end of a chain of hands, and you trust the whole chain because you have no practical choice. Checking it yourself, all the way down, is impossible.
The attacker’s insight is simple. Why fight through your defenses when you’ll happily install their code or plug in their device yourself, as long as it arrives wearing the label of someone you trust? The pager attack is that insight taken to its most extreme conclusion. Israel didn’t break into Hezbollah’s supply chain. It became Hezbollah’s supply chain, building a real company that sold a real product, so the weapon arrived through the front door as a normal purchase.
The genius and the horror of becoming the supplier
I want to be precise about what made this work, because this is what translates to every other field.
Israel reportedly didn’t intercept a shipment and tamper with it. Interception is the older, cruder method, and it leaves seams: a delayed package, a resealed box, a serial number that doesn’t match. Israel built a legitimate business instead. A company in Budapest with real staff, real clients, and a genuinely good product, established over time until it was simply a known vendor in the market. Then it steered the compromised devices to the target through ordinary sales.
Sit with the defensive nightmare in that. There was no seam to find. The company was real. The product worked. The paperwork was clean. Hezbollah could have run every check available to a careful buyer, inspected the devices, tested them, verified the vendor, and found nothing, because there was nothing to find until the moment the devices were told to detonate. A supplier who is patient enough to be genuine for years is a supplier no inspection can catch.
Strip the explosives away and this is the exact thing that keeps security professionals awake. A trusted vendor, built up over years, delivering a compromised product through legitimate channels. Swap the bomb for a hidden hardware implant, a backdoor in the firmware, or a poisoned piece of software, and the pager attack is just the bloodiest version of a risk that runs under every organization on earth.
Does this reach ordinary organizations, or just militant groups?
It reaches everyone, and the rest of this series is the proof.
Nobody is going to build a bomb into your laptop. But the structure of the pager attack, the compromised thing delivered through a trusted channel, is the single most common way large organizations get breached, and the articles ahead walk through case after case.
A software company’s routine update, signed and shipped to thousands of customers, carries an attacker’s code because the company itself was compromised first. A retailer loses millions of credit cards because attackers got in through the account of a heating and cooling contractor nobody thought of as a security risk. A core piece of software that runs on much of the internet is quietly backdoored by a volunteer who spent two years earning the right to touch it.
None of those needed a bomb. Each one used the same move Israel used against Hezbollah: get inside the chain of trust, and let the target install the attack themselves. The pager attack is the extreme, physical version that makes the pattern impossible to look away from. The software versions kill no one and happen constantly, and most of them never make the news.
What can an organization do about supply chain risk?
Less than we’d like, and more than nothing, and both halves matter.
The hard limit first. You cannot fully verify a supply chain. You cannot take apart every device, audit every line of code in every update, or trace every component to its origin. A determined, well-resourced attacker who becomes your supplier can beat any check a normal organization can run. That was the whole point of the pager attack, and pretending otherwise sells a false comfort I won’t sell.
What you can do is stop treating trusted as a permanent state. A vendor being familiar is not evidence they’re safe today.
The practices that help all come from that shift. Buy from as few hands as possible, so the chain is short enough to reason about. Prefer suppliers who can show you how they secure their own process. Design your systems so one compromised component can’t reach everything.
That last one matters most. Hezbollah’s failure wasn’t only that the pagers were rigged. It was that thousands of people carried the same compromised device, so one betrayal reached them all at once. A system where any single trusted thing can take down the whole is a system waiting for its supplier to turn.
And treat the contractors, vendors, and dependencies at the edge of your operation as part of it, because the attacker already does. The heating contractor, the small software library, the reseller two steps removed, none of them feels like your security perimeter, and every one of them is. The diagram on the wall shows the systems you own. The attack comes through the ones you merely trust.
The next articles leave the physical world and follow this exact pattern through the biggest software supply chain attacks on record, starting with a company that sold spying dressed as security for half a century. For the wider view, the cybersecurity hub collects the rest of my work on this.
Frequently Asked Questions
Because no organization builds its own hardware and software from scratch, everyone trusts a long chain of suppliers they cannot fully verify, and the attacker exploits exactly that trust.
Continue the Series
1. The Morris Worm |
2. Stuxnet: The History |
3. Stuxnet: Crossing the Air Gap |
4. Stuxnet: The Aftermath |
5. The Pager Attack |
6. The Pager Supply Chain |
7. Crypto AG |
8. Agent.btz |
9. NotPetya |
10. SolarWinds |
11. The Target Breach |
12. The XZ Backdoor |
13. The Line to AI
