The Operations
The Internet Is a Supply Chain
Every physical product reaches us through a supply chain, and people understand what that means. Food passes from farm to processor to truck to warehouse to shelf, and at each step somebody could tamper with it. In 1982, seven people in the Chicago area died after someone put cyanide into Tylenol capsules on store shelves. The manufacturer had done nothing wrong. The product was altered after it left the factory and before it reached the customer. Within months, medicine was being sold in tamper-evident packaging, and everyone learned to check the seal.
The internet is a supply chain too, and a far longer one than most people imagine. The screen in front of you was assembled from resources that passed through software developers, volunteer programmers, hosting companies, delivery networks, advertising exchanges, and the firms that register web addresses. Each of them is a place where a resource can be altered after the publisher approved it and before your device receives it. For most of what travels along that chain, there is no seal.
Attacks through the software supply chain are already among the most damaging on record. In 2017, attackers broke into the maker of one of only two tax programs approved for use in Ukraine, installed at most of the country's businesses, and hid destructive code in a routine update. The malware, known as NotPetya, spread around the world in hours, crippled the shipping company Maersk, the drug maker Merck, and many others. A former White House security adviser put the damage at more than ten billion dollars. In 2020, attackers hid a back door in an update to network management software made by a company called SolarWinds. As many as 18,000 customers installed it, among them several departments of the United States government, and it went undetected for most of a year before a security firm discovered it while investigating a break-in at its own offices.
Both of those attacks worked by getting customers to install poisoned software, and anything installed can eventually be found, taken apart, and traced. Attack the Glass uses the same route, a trusted supplier, and installs nothing. What it delivers exists for the length of one visit.
Getting Into Position
An operation of this kind begins long before anything appears on a screen. It begins with getting into position. Intelligence services have a phrase for it, placement and access: being placed somewhere inside the chain, with access to something that flows toward the target. A person with placement and access has no lock to defeat, because they are already inside, doing what looks like their job.
The better the position, the more it allows. A place on one small site reaches that site's visitors. A place inside a resource that thousands of sites use reaches all of them at once. What an attacker can do follows from where they sit, far more than from how large or sophisticated they are.
Once in position, an attacker can wait. Nothing about the resource changes until the day it is used, so a search in the meantime comes up empty.
The most patient example yet discovered came to light in March 2024. A small, unglamorous piece of free software called xz, which compresses data, is built into most of the Linux systems that run the internet's servers. For years it had been maintained by one unpaid volunteer. Around 2021 a helpful newcomer using the name Jia Tan began contributing improvements, while other accounts, since judged to be fake, pressured the tired maintainer to share the load. Over more than two years the newcomer earned full control of the project, and then slipped in a carefully hidden back door that would have opened a vast number of servers to whoever held the key. It was caught by luck. An engineer at Microsoft noticed that logging in to a test machine was taking half a second longer than it should, went looking for the reason, and found it days before the altered version would have spread worldwide. Nobody has publicly established who Jia Tan was. The operation took years, cost little, broke into nothing, and came within days of succeeding.
Many Ways In, and Most Are Not Hacking
People hear "cyberattack" and imagine someone breaking through defenses. That is one way into a supply chain, and often the hardest. The others are the ways anyone has ever gotten into any supply chain.
An insider can do it. An employee at one of the suppliers, with ordinary access and few resources, can hold more power over what millions of screens show than most outside attackers could ever obtain. Insiders can also be recruited. In 2019 the United States charged two former Twitter employees with using their staff access to look up the private account details of critics of the Saudi government on behalf of Saudi officials, and one of them was later convicted.
A supplier can be bought, openly and legally, and the new owner inherits its place on every screen it serves. This happens regularly with browser extensions, the small add-ons people install to block ads or manage tabs. A popular one called The Great Suspender, with around two million users, was sold by its developer in 2020. The new owner added hidden code, and in early 2021 Google removed the extension as malware. Nothing about it had changed from the users' side except who controlled it.
A piece of free software maintained by one tired volunteer can be handed over to a helpful stranger who offers to take on the work. In 2018 the unpaid author of a widely used piece of code called event-stream, downloaded about two million times a week, did exactly that. The new maintainer added code designed to steal from one particular brand of bitcoin wallet, and it went unnoticed for about two and a half months after the handover.
A web address can be allowed to lapse and be registered by someone else, who then receives every request still being sent to it. A distributor or reseller in the middle can alter what passes through. Passwords can be stolen, and systems can be hacked, which is how the Ticketmaster and British Airways thefts began.
Most of these involve no break-in, which means most of them are not things a cybersecurity team is placed to stop. They are matters of ownership, hiring, contracts, and money. No public registry records who owns the companies and addresses that deliver resources to our screens, and when control of one changes hands, nobody who depends on it is told. The address stays the same. The padlock stays the same. The party deciding what gets delivered is someone new.
Propaganda Is Old, the Delivery Is New
Deceiving a population is as old as politics. Four days before the British general election of 1924, a newspaper published a letter, supposedly from a Soviet leader named Zinoviev, urging British communists to prepare for revolution. It was a forgery, and it dominated the final days of the campaign. During the Second World War, Britain ran a radio station called Soldatensender Calais that posed as a German military broadcaster, mixing accurate news and popular music with invented stories meant to wear down German morale. In the 1980s the Soviet KGB spent years spreading the claim that the United States had created the AIDS virus as a weapon, a story that is still in circulation today.
The practice goes by many names. Propaganda is the oldest. Militaries speak of psychological operations and information operations. Governments and researchers speak of influence operations, and the European Union uses the term foreign information manipulation and interference, or FIMI. Disinformation is falsehood spread on purpose, and misinformation is the same falsehood passed along by people who believe it. NATO has begun to describe the contest over what populations believe as cognitive warfare. Every one of these names points at a single aim: changing what people hold to be true so that they decide differently. What the internet changed is the cost and the reach of delivery.
The record of the last ten years is public, and four episodes from it show the range.
Election interference. Before the 2016 United States election, a Russian organization called the Internet Research Agency ran thousands of fake social media accounts posing as American citizens and community groups. Its staff organized real rallies from St. Petersburg by pretending to be local activists. Facebook later estimated that the agency's posts reached 126 million Americans.
Conspiracy theory. In late 2016 a story spread from anonymous message boards to social media claiming that a Washington pizzeria was the center of a child-abuse ring run by politicians. It was entirely invented. On December 4 a man who believed it drove from North Carolina, walked into the restaurant with a rifle, and fired it, intending to free the children. There were none. Nobody was hurt, and the man went to prison. A lie assembled on screens had put an armed man in a room full of families.
Cloned news. Since 2022 a Russia-attributed campaign known as Doppelganger has built copies of real Western news sites, including major German, French, British, and American outlets, and used them to publish fabricated stories under trusted names. In 2024 the United States government seized 32 web addresses used in the campaign.
Deepfakes. In early 2024 an employee of the engineering firm Arup, in Hong Kong, sent about 25 million dollars to criminals after joining a video call in which every colleague on the screen, including the chief financial officer, was an AI-generated fake. The company's computer systems were never breached. The attack was on what one employee saw and heard.
Every one of those operations had to build its own stage. The fake accounts had to gather followers. The cloned news sites lived at slightly wrong addresses, which is how they were eventually caught. The fake executives had to get their victim onto a call. Each left something for a careful person or an investigator to notice.
Attack the Glass removes that burden. The false content is delivered inside the real site, at the real address, under the real name, to the people the attacker selects. A campaign like Doppelganger carried this way would need no cloned sites, because it would be speaking from inside the genuine ones. Nobody can say whether that has been done, because it would leave nothing to find.
Buying a Position of Trust
The clearest public case of Attack the Glass is polyfill.io. A polyfill is a small piece of helper code that lets older web browsers display newer websites properly. For years a free service at the address polyfill.io supplied that code to any site that asked, and more than a hundred thousand websites added the one line that fetched it. Most of them then forgot it was there.
In early 2024 the address and the service were sold to a company called Funnull. The service's original creator, who no longer controlled it, publicly warned every website to remove it at once, and two large internet companies set up safe replacement copies for anyone who wanted to switch. Few did. In June 2024 security researchers reported that the address had begun serving altered code, through the same channel those websites had always used, and that it sent some visitors on mobile phones to gambling and scam sites. Google began blocking advertisements that pointed to affected sites, and within days the company that registered the address suspended it.
Nobody broke in, and nothing a security alarm is built to catch would have fired. The US Treasury sanctioned Funnull in 2025, finding that the company had bought a repository of code used by web developers and altered it to send visitors of legitimate websites to scam websites. The address never changed. The owner did.
This operation was crude. It redirected people to other sites, which is about the most noticeable thing altered code can do, and it was still running on a hundred thousand sites before anyone raised the alarm. A quieter operator with the same position could have changed what those sites said.
Anyone in Position
It would be comforting to file all of this under espionage and leave it to governments. State services can certainly launch an attack of this kind. So can anyone else who holds placement and access. A single developer who controls a popular code library or a source of data can do it alone. So can a corporation moving against a rival, an industry protecting itself, an organized crime group, a terrorist or violent extremist organization, a political party, a lobbyist, or one super-empowered individual with money and a cause.
The record already holds examples at each scale. In January 2022 the author of two free code libraries used by thousands of companies, angry that large firms profited from his unpaid work, deliberately broke them, and applications around the world started printing gibberish. Two months later the maintainer of another popular library added code that erased files on computers located in Russia and Belarus, as a protest against the invasion of Ukraine. Each was one person acting alone with a keyboard. At the corporate scale, Volkswagen and Uber both built software to show inspectors a false version of events. Web skimming is the work of organized criminal groups. During the 2016 election, more than a hundred websites pushing invented political stories to American readers turned out to be run by teenagers in one small town in Macedonia, who had no interest in politics and were doing it for the advertising money.
A precision operation once needed a state intelligence service behind it, because a human analyst had to research every target by hand. Generative AI does that research now, so content shaped for one recipient, or for one segment, costs whatever the computing costs. Criminal groups, commercial rivals, insiders, and state services all reach the same capability at the same price.
Whoever it is works without detection, without evidence, and without attribution: a ghost in the machine.
Digital Supernodes
The internet's supply chain is not spread evenly. A small number of suppliers sit at hubs that millions of sites, apps, and organizations all depend on: a dominant content delivery network, a nearly universal piece of shared code, a sign-in service, an advertising exchange. A content delivery network, or CDN, is a company that keeps copies of websites' resources on computers all over the world, so that each visitor is served from somewhere nearby. A handful of CDNs carry a large share of everything on the web. They reached that position by being good, cheap or free, and popular, and each new customer made the next one feel safer in choosing them. We call these hubs Digital Supernodes.
The world has had two accidental demonstrations of how much rests on these hubs. On June 8, 2021, a software fault at a CDN called Fastly, set off by one customer changing a setting, took a long list of major sites offline at once for about an hour, among them Amazon, Reddit, the New York Times, and the British government's main website. On July 19, 2024, the security company CrowdStrike sent out a faulty update that crashed about 8.5 million Windows computers in a morning. Airlines grounded flights, hospitals cancelled operations, and banks and broadcasters went dark. Neither event was an attack. Each showed that a single supplier, trusted by everyone for good reasons, can reach a large part of the world's screens in minutes.
For an attacker a supernode is the most valuable position there is. Control of one gives a place on millions of screens at once, and the ability to choose among them. Polyfill.io was a small example, one shared piece of code on a hundred thousand sites. There are hubs far larger.