2,500+ Organisations Identified in Major AI Supply-Chain Exposure

Global companies across technology, finance, telecom, cybersecurity, manufacturing and logistics among organisations linked to the exposure

New Jersey, U.S.: More than 2,500 organisations worldwide have been identified as potentially affected by a major AI supply-chain incident involving LiteLLM, a widely used open-source tool that enables applications to connect with artificial intelligence models.

The organisations potentially linked to the exposure span critical sectors including technology, cybersecurity, banking and financial services, telecommunications, manufacturing, consulting, logistics and enterprise software.

According to CloudSEK’s exposure dataset, high-confidence matches include major organisations such as NVIDIA, Samsung Electronics, Cisco Systems, Siemens, S&P Global, ServiceNow, Deloitte, Vodafone, X Corp, Zscaler, FedEx, Volkswagen, Thales and London Stock Exchange Group, among others.

CloudSEK Exposure Checker

Potential Exposure Goes Beyond a Single AI Tool

The significance of the incident lies not only in the number of organisations potentially involved, but also in the type of information that may have been exposed.

Potentially accessible information included cloud credentials, source-code access, server keys, software-development secrets, AI API keys and other authentication credentials that could provide access to critical business systems.

If valid credentials were obtained, attackers could potentially:

  • Access corporate cloud environments
  • Enter internal servers and systems
  • Steal proprietary source code
  • Access software-development infrastructure
  • Abuse AI platforms using stolen API credentials
  • Move deeper into corporate networks
  • Use legitimate credentials to disguise malicious activity
  • Target customers, partners or suppliers through trusted access

In effect, the incident may have exposed digital keys to sensitive parts of enterprise technology environments.

CloudSEK has stressed that appearing in its dataset does not automatically mean an organisation was breached or that data was stolen. Rather, it indicates that information associated with the organisation was identified in the exposure and should be investigated.

Thousands of Organisations Potentially Exposed in Around 40 Minutes

The incident reportedly occurred in March 2026, when the cybercriminal group Team PCP compromised LiteLLM.

Malicious versions of LiteLLM were reportedly available through the Python software repository PyPI for approximately 40 minutes.

Despite the short duration, CloudSEK’s analysis identified approximately 434,000 CI/CD pipelines potentially connected to the exposure.

CI/CD pipelines automate the process of building, testing and deploying software. They can automatically download software packages, meaning a malicious package can potentially reach large numbers of development environments without requiring manual installation by individual developers.

For organisations using affected versions, the malicious package could potentially operate within development environments containing highly sensitive credentials.

What Information May Have Been Exposed?

CloudSEK identified several categories of potentially sensitive information, including:

  • AWS credentials
  • Google Cloud credentials
  • Microsoft Azure credentials
  • Source-code repository credentials
  • SSH keys
  • Kubernetes access tokens
  • CI/CD and deployment secrets
  • Environment variables containing passwords and tokens
  • LLM and AI API keys

Such credentials are particularly sensitive because they are used by employees, applications and automated systems to authenticate themselves.

If attackers successfully obtained them, they might not need to compromise the organisation again—they could potentially use legitimate credentials to gain access.

This can make malicious activity considerably harder to identify.

Risk May Continue Long After the Original Incident

Removing the malicious package does not necessarily eliminate the security risk.

If credentials were copied while the compromised package was active, those credentials could remain valid until the affected organisation revokes or rotates them.

As a result, organisations potentially exposed during the March incident could continue to face risks even after the original compromise ended.

Potential consequences include:

  • Unauthorised access to corporate systems
  • Theft of sensitive information
  • Intellectual-property theft
  • Operational disruption
  • Financial losses
  • Regulatory scrutiny
  • Reputational damage
  • Potential compromise of software supplied to customers

High- and Medium-Confidence Matches Explained

CloudSEK has categorised organisations according to the strength of evidence linking them to the exposure.

A high-confidence match indicates strong technical indicators—such as identifiable corporate domains, repositories, credentials or infrastructure—connecting the exposed information to an organisation.

A medium-confidence match indicates credible evidence of a connection, but with less certainty.

Importantly, neither classification should be interpreted as proof that an organisation suffered a successful cyberattack. The classification reflects the strength of the association between the exposed information and the organisation.

Why Software Supply-Chain Attacks Are So Dangerous

The incident highlights the growing threat posed by software supply-chain attacks.

Attackers do not necessarily need to compromise thousands of companies individually. Instead, they can target software that thousands of organisations already trust and incorporate into their technology environments.

Once compromised software enters automated development systems, it can potentially gain access to credentials and infrastructure belonging to numerous organisations simultaneously.

In this case, a compromise reportedly lasting approximately 40 minutes was associated with potential exposure involving more than 2,500 organisations and around 434,000 development pipelines.

AI Infrastructure Is Becoming a High-Value Target

The incident also demonstrates why AI infrastructure is becoming an increasingly attractive target for cybercriminals.

Enterprises are connecting AI tools with cloud infrastructure, internal applications, source-code repositories, databases and other business systems.

Consequently, compromising an AI gateway or related component could potentially provide access beyond the AI application itself.

AI gateways, agents, MCP servers and other AI infrastructure are increasingly becoming central components of enterprise technology environments, making them an important part of the modern corporate attack surface.

FBI Warning Highlights Continuing Concern

The FBI reportedly issued FLASH-20260702-01 on July 2, 2026, concerning cybercriminal group TeamPCP and highlighting continuing security concerns associated with the group and its activities.

CloudSEK has made its exposure research available to help potentially affected organisations determine whether their infrastructure appears in the dataset.

Organisations that identify potential exposure should investigate affected systems, review access logs and immediately rotate or revoke potentially compromised credentials.

CloudSEK Releases Free Exposure Checker

CloudSEK has released a free tool allowing organisations to check whether credentials or infrastructure associated with them appear in the identified dataset.

Check Potential Exposure — CloudSEK

Read the Full CloudSEK Research Report

CloudSEK AIVigil

CloudSEK’s AIVigil monitors enterprise AI exposure, including exposed AI infrastructure, leaked AI credentials, MCP servers, vector databases, AI-agent workflows and unauthorised AI deployments.

The platform combines cyber-threat intelligence with AI attack-surface monitoring to help organisations identify exposed systems, credentials and potential attack paths before they can be exploited.

About CloudSEK

CloudSEK is an AI-native predictive cyber-intelligence company focused on helping organisations identify potential attack paths and exposed access before attackers exploit them.

Its capabilities include digital-risk protection, cyber-threat intelligence, external attack-surface monitoring, AI attack-surface monitoring and third-party risk intelligence.

CloudSEK — Official Website

ADVERTISING

Latest News

INDIA NEWS

Chhattisgarh NEWS

World NEWS