Most people assume a device is safe the moment it comes out of the box. Why wouldn’t it be? It’s brand new, sealed, untouched.
Except… that’s not always true anymore.
Preinstall credential theft is one of those problems that doesn’t make headlines, but it should. It’s basically the idea that a laptop, phone, or workstation can be compromised before it ever reaches you. Not through user error. Not through a bad link. But somewhere in the long chain of manufacturing, packaging, shipping, someone slips something in.
And here’s the uncomfortable part: you won’t notice. Your IT team probably won’t notice either. The malware usually sits quiet until the first boot. Then it watches. It waits for the first login, the first VPN connection, the first authentication token. And once it gets that, it’s game over.
Lots of companies assume their vendors have everything under control. Big brands, large distributors, “secure” channels. But supply chains aren’t neat anymore. One weak link, one careless intermediary, one tampered shipment, and a device arrives already working for someone else.
The solution isn’t paranoia, but awareness.
Know where your hardware comes from.
Check what’s being shipped to you.
Don’t trust a sealed box just because it’s sealed.
And whatever tools you use for onboarding devices, make them actually look for unusual behavior during setup, not after.
The threat isn’t dramatic. It’s quiet, easy to miss, and that’s why it works.
Sometimes the biggest risk isn’t what employees click, it’s what the company buys.