Back to news
AI Policy & Regulation
15h ago

Large-scale credential leak affects major organizations due to supply-chain attack

Aug 12, 2026
AI Summary

A significant supply-chain attack on the open-source tool LiteLLM has resulted in the exposure of terabytes of sensitive credentials belonging to major companies, including Microsoft and Amazon. The breach occurred during a brief 40-minute window when compromised versions of the software were downloaded, potentially impacting over 2,500 organizations.

Large-scale credential leak affects major organizations due to supply-chain attack
  • A supply-chain attack on LiteLLM has led to the leak of terabytes of credentials from numerous organizations.
  • Companies affected include Microsoft, Amazon, Cisco, Samsung, and Salesforce.
  • Security firms CloudSEK and Hudson Rock reported the incident, revealing that various types of sensitive information were compromised, including cloud keys and SSH keys.
  • The credentials were extracted during a 40-minute period in March when users downloaded compromised versions of LiteLLM from the official Python Package Index repository.
  • Hudson Rock analyzed a 195TB file to uncover the extent of the breach, but the source of the leaked information has not been identified.
data breachsupply chain attackai securitycredentials leakcybersecurity