CloudSEK Identifies AI Supply Chain Exposure Affecting More Than 2,500 Organisations

Cloud keys, repository tokens, SSH keys, Kubernetes secrets, package publishing credentials, and more were stolen from the affected organisations.

Advertisement
Written by Nithya P Nair, Edited by Rohan Pal | Updated: 13 August 2026 14:36 IST
Highlights
  • Over 2,500 firms could have been impacted by an AI supply-chain attack
  • LiteLLM is an open-source tool
  • CloudSEK said the incident was more than a software supply-chain breach

In March 2026, the threat actor group TeamPCP orchestrated the attack

Photo Credit: Reuters

Cybersecurity firm CloudSek has identified an AI supply-chain attack on LiteLLM that affected more than 2,500 organisations. The incident, which reportedly occurred in March this year, seems to have potentially exposed around 4,34,000 automated software development pipelines. The attack reportedly exposed data of many leading tech brands, including Microsoft, X, Amazon, Cisco, Samsung and Salesforce.

Over 2,500 Organisations Potentially Exposed in AI Supply Chain Incident

In a blog post, CloudSEK confirmed that more than 2,500 companies and 4,34,000 CI/CD pipelines worldwide were exposed in the largest AI supply chain breach of 2026. In March 2026, the threat actor group TeamPCP orchestrated a supply chain attack targeting AI infrastructure by compromising LiteLLM.

Advertisement

The company claimed that CloudSEK Threat Intelligence gained access to the victims' information and has disclosed the details of all the impacted victims. The list shared by CloudSEK includes names such as Nvidia, AWS, Samsung, Salesforce, Cisco, ServiceNow, Siemens, Accenture Federal Services, X, MediaTek, Munich, Thomson Reuters, London Stock Exchange Group, FedEx, Volkswagen, Orange, and HP.

CloudSEK said that cloud keys, repository tokens, SSH keys, Kubernetes secrets, package publishing credentials, environment variables, and AI provider keys were stolen from the listed companies. The attackers also reportedly targeted LLM API keys and gateway configuration. The research firm said that stolen objects allow attackers to move into other systems.

Advertisement

The cybersecurity firm also notes that removing the affected package does not resolve the problem because stolen credentials remain usable for weeks or months unless they are rotated and downstream activity is investigated. The company states that the latest AI infrastructure is becoming an attractive target for attackers, as Gateways, agents, vector stores, model endpoints, and MCP servers can give access to confidential data and systems.

CloudSEK said the incident was more than a software supply chain breach involving an AI product. "It demonstrated that compromising an AI control point can expose the identities and systems around it. Future attacks are likely to target the AI layer precisely because it is connected to everything else," it added.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Further reading: CloudSEK, CloudSEK Report, AI
Advertisement

Related Stories

Popular Mobile Brands
  1. Samsung Galaxy S26 FE vs Oppo Find X9s vs Vivo V70 Elite Compared
  2. Best Gaming Phones Under Rs. 80,000 in India
  3. Best Phones Under Rs. 70,000 With Telephoto Cameras in India
  4. OnePlus N6 Lite 4G vs iQOO Z11 Lite vs Samsung Galaxy M17
  1. Magic Eden Investigates Possible Exploit After NFTs Move for 0 ETH
  2. Amazon Great Indian Festival 2026: Early Deals Are Now Live on OnePlus N6x, iQOO Z10 Lite 5G, and More
  3. Marking 12 Years of Make in India, Gov't Targets the Brains Inside Our Smartphones
  4. Google Photos Update Brings Redact Tool, Moods and AI Wardrobe
  5. Halo Studios Reportedly Has Around 30 Employees Left After Layoffs as Activision Takes Charge of Franchise
  6. KelpDAO Sues LayerZero Over $292 Million rsETH Exploit, Claims Bridge Risks Were Not Disclosed
  7. OpenAI Plans to Launch a New Cybersecurity-Focused GPT-6 Series AI Model: Report
  8. Vivo V80 Price in India Leaked Ahead of October 6 Launch: What You Need to Know
  9. Infinix GT NX Controller With Pixel-Level FPS Touchpad, GT NX Station Cooling Dock Unveiled
  10. Bitget Suffers $351.6 Million Security Breach, Exchange Says No Private Keys Were Leaked
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.