Terabytes of Credentials Leaked in Massive Supply-Chain Attack
16 Articles
16 Articles
Terabytes of credentials leaked in massive supply-chain attack
Terabytes worth of credentials, many belonging to the world’s biggest and most sensitive organizations, have been exposed in a supply-chain attack on LiteLLM, an open source tool that streamlines AI-driven software development. Microsoft, Amazon, Cisco, Samsung, and Salesforce are only a handful of the entities whose access secrets were exposed. The revelation was posted on Tuesday and Wednesday by security firms CloudSEK and Hudson Rock. CloudS…
(Jakarta=Yonhap News) Reporter Park Hyun-soo = "Korea and ASEAN must cooperate more closely in various fields, including supply chains. 'Products made in Korea' (M...
IT researchers have gained access to the lost data from thousands of companies during the LiteLLM supply chain attack in March.
153GB of stolen credentials surface after LiteLLM supply chain attack
A massive 153GB archive stolen during the LiteLLM supply chain attack exposes credentials and other sensitive data linked to thousands of corporate domains, including AWS, Samsung, Cisco, and Salesforce. Hudson Rock says it obtained and analyzed the archive, which contains 433,909 files, and attributed 118,829 CI runner dumps to 2,488 corporate domains. “We are leveraging this data for a global ethical disclosure effort,” Alon Gal, Hudson Rock’s…
CloudSEK Identifies AI Supply Chain Exposure Affecting More Than 2,500 Organisations
CloudSEK said that over 2,500 companies and 4,34,000 CI/CD pipelines across the world were exposed in the supply chain breach. The attack occurred in March 2026, and the threat actor group TeamPCP orchestrated a supply chain attack targeting AI infrastructure by compromising LiteLLM. The attack reportedly exposed data of companies including MediaTek, Microsoft, X, Amazon, Cisco, Samsung and Salesforce.
LiteLLM Attack Affected 2,500 Companies, 434,000 CI/CD Pipelines: CloudSEK
The massive supply-chain attack that compromised LiteLLM in the spring affected more than 2,500 companies and exposed about 434,000 CI/CD pipelines, with victims ranging from top-tier IT and AI companies to cybersecurity firms, SaaS, and enterprises. It rolled up a lot of victims, but also was a high-profile example of the growing trend of threat actors targeting companies’ AI infrastructure layer that is increasingly becoming connected to every…
Coverage Details
Bias Distribution
- 50% of the sources are Center, 50% of the sources lean Right
Factuality
To view factuality data please Upgrade to Premium













