Cloud keys, repository tokens, SSH keys, Kubernetes secrets, package publishing credentials, and more were stolen from the affected organisations.
Photo Credit: Reuters
In March 2026, the threat actor group TeamPCP orchestrated the attack
Cybersecurity firm CloudSek has identified an AI supply-chain attack on LiteLLM that affected more than 2,500 organisations. The incident, which reportedly occurred in March this year, seems to have potentially exposed around 4,34,000 automated software development pipelines. The attack reportedly exposed data of many leading tech brands, including Microsoft, X, Amazon, Cisco, Samsung and Salesforce.
In a blog post, CloudSEK confirmed that more than 2,500 companies and 4,34,000 CI/CD pipelines worldwide were exposed in the largest AI supply chain breach of 2026. In March 2026, the threat actor group TeamPCP orchestrated a supply chain attack targeting AI infrastructure by compromising LiteLLM.
The company claimed that CloudSEK Threat Intelligence gained access to the victims' information and has disclosed the details of all the impacted victims. The list shared by CloudSEK includes names such as Nvidia, AWS, Samsung, Salesforce, Cisco, ServiceNow, Siemens, Accenture Federal Services, X, MediaTek, Munich, Thomson Reuters, London Stock Exchange Group, FedEx, Volkswagen, Orange, and HP.
CloudSEK said that cloud keys, repository tokens, SSH keys, Kubernetes secrets, package publishing credentials, environment variables, and AI provider keys were stolen from the listed companies. The attackers also reportedly targeted LLM API keys and gateway configuration. The research firm said that stolen objects allow attackers to move into other systems.
The cybersecurity firm also notes that removing the affected package does not resolve the problem because stolen credentials remain usable for weeks or months unless they are rotated and downstream activity is investigated. The company states that the latest AI infrastructure is becoming an attractive target for attackers, as Gateways, agents, vector stores, model endpoints, and MCP servers can give access to confidential data and systems.
CloudSEK said the incident was more than a software supply chain breach involving an AI product. "It demonstrated that compromising an AI control point can expose the identities and systems around it. Future attacks are likely to target the AI layer precisely because it is connected to everything else," it added.
Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.