CloudSEK Identifies AI Supply Chain Exposure Affecting More Than 2,500 Organisations

Cloud keys, repository tokens, SSH keys, Kubernetes secrets, package publishing credentials, and more were stolen from the affected organisations.

Advertisement
Written by Nithya P Nair, Edited by Rohan Pal | Updated: 13 August 2026 14:36 IST
Highlights
  • Over 2,500 firms could have been impacted by an AI supply-chain attack
  • LiteLLM is an open-source tool
  • CloudSEK said the incident was more than a software supply-chain breach

In March 2026, the threat actor group TeamPCP orchestrated the attack

Photo Credit: Reuters

Cybersecurity firm CloudSek has identified an AI supply-chain attack on LiteLLM that affected more than 2,500 organisations. The incident, which reportedly occurred in March this year, seems to have potentially exposed around 4,34,000 automated software development pipelines. The attack reportedly exposed data of many leading tech brands, including Microsoft, X, Amazon, Cisco, Samsung and Salesforce.

Over 2,500 Organisations Potentially Exposed in AI Supply Chain Incident

In a blog post, CloudSEK confirmed that more than 2,500 companies and 4,34,000 CI/CD pipelines worldwide were exposed in the largest AI supply chain breach of 2026. In March 2026, the threat actor group TeamPCP orchestrated a supply chain attack targeting AI infrastructure by compromising LiteLLM.

Advertisement

The company claimed that CloudSEK Threat Intelligence gained access to the victims' information and has disclosed the details of all the impacted victims. The list shared by CloudSEK includes names such as Nvidia, AWS, Samsung, Salesforce, Cisco, ServiceNow, Siemens, Accenture Federal Services, X, MediaTek, Munich, Thomson Reuters, London Stock Exchange Group, FedEx, Volkswagen, Orange, and HP.

CloudSEK said that cloud keys, repository tokens, SSH keys, Kubernetes secrets, package publishing credentials, environment variables, and AI provider keys were stolen from the listed companies. The attackers also reportedly targeted LLM API keys and gateway configuration. The research firm said that stolen objects allow attackers to move into other systems.

Advertisement

The cybersecurity firm also notes that removing the affected package does not resolve the problem because stolen credentials remain usable for weeks or months unless they are rotated and downstream activity is investigated. The company states that the latest AI infrastructure is becoming an attractive target for attackers, as Gateways, agents, vector stores, model endpoints, and MCP servers can give access to confidential data and systems.

CloudSEK said the incident was more than a software supply chain breach involving an AI product. "It demonstrated that compromising an AI control point can expose the identities and systems around it. Future attacks are likely to target the AI layer precisely because it is connected to everything else," it added.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Further reading: CloudSEK, CloudSEK Report, AI
Advertisement

Related Stories

Popular Mobile Brands
  1. Here's When the Google Fitbit Air Will Launch in India
  2. Google Pixel 11 vs Pixel 10: What's The Difference?
  3. Vivo's New S50t Vitality Edition Packs a Snapdragon 8s Gen 3 Chipset
  4. Google Pixel 11 vs iPhone 17: Price in India and Specifications Compared
  5. OTT Releases This Week: Cocktail 2, Bharat Bhhagya Viddhaata, and More
  6. Realme 16x 5G Goes on Sale in India With These Offers
  7. Amazon Great Freedom Sale 2026: Best Deals on Storage Devices
  8. Pova 8 Pro 5G Will Launch in India on This Date: See Expected Specifications
  9. Google Pixel 11 Pro Fold vs Pixel 10 Pro Fold: What's The Difference
  1. Arizona Crypto ATM Law Helps 35 Scam Victims Recover $171,000 in Lost Funds
  2. CloudSEK Identifies AI Supply Chain Exposure Affecting More Than 2,500 Organisations
  3. Google Gemini Expands Connected Apps With OpenTable, Ticketmaster and More
  4. Realme 16x 5G Goes on Sale in India With 144Hz Display, 7,000mAh Battery: Price, Offers
  5. Pova 8 Pro 5G India Launch Date Revealed Along With Design; Will Feature a Secondary Display on the Rear
  6. Bitcoin Holds Near $64,000 as In-Line US CPI Offers Little Direction
  7. Vivo S50t Vitality Edition Launched With Snapdragon 8s Gen 3 SoC, 50-Megapixel Periscope Camera
  8. Boat Aavante Bar Prime Soundbar Series Launched in India With Up to 600W Sound: Price, Specifications
  9. Ghost of Yotei Will Get Its First Story Expansion and a New Roguelike Single-Player Mode in October
  10. Google Fitbit Air Confirmed to Launch in India in October: Specifications, Features
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.