AI Pulse by Inblix

LiteLLM breach leaks terabytes of secrets from Microsoft, Amazon, Cisco

Ars Technica AI · Aug 12, 2026 · 2 min read · Read original article →

Curated by the Inblix editorial team


Featured image for article: LiteLLM breach leaks terabytes of secrets from Microsoft, Amazon, Cisco

A supply-chain attack on LiteLLM, the open source tool developers use to streamline AI projects, has spilled terabytes of credentials belonging to more than 2,500 organizations. Microsoft, Amazon, Cisco, Samsung, and Salesforce are among the victims. Security firms CloudSEK and Hudson Rock disclosed the breach this week, cataloging exposed cloud keys, repository tokens, SSH keys, Kubernetes secrets, package publishing credentials, environment variables, and AI provider keys.

The damage happened fast. CloudSEK says victims downloaded compromised versions of LiteLLM from PyPI, Python’s official package repository, during a 40-minute window in March. Hudson Rock analyzed a 195TB file to confirm the scope. Neither firm named the source of that data, but the trail leads somewhere unsettling: the LiteLLM compromise was itself the fallout from an earlier supply-chain attack on Trivy, a vulnerability scanner used across the industry. KICS and the Telnyx Python SDK were also infected in the same campaign.

TeamPCP, a loosely organized crew largely made up of teenagers, has claimed responsibility, and researchers have mostly backed that up. Kevin Beaumont, an independent security researcher, didn’t mince words: “I’ve confirmed the data is legit by the way, multiple victim orgs. It contains a significant volume of sensitive content at orgs.” His assessment cuts to the core problem — this isn’t an AI security failure in the sci-fi sense. It’s the same DevOps hygiene problem that’s plagued software for years, now turbocharged by teams rushing AI features into production without locking down their dependency chains.

What makes this sting is the asymmetry. A group of teenagers exploited a chain of trusted tools — Trivy to LiteLLM to whatever sat downstream — and walked away with credentials that could take years to fully rotate. The breach echoes the 2020 SolarWinds attack in structure, but with a fraction of the sophistication and none of the nation-state backing. That’s the alarming part: the barrier to entry for devastating supply-chain attacks has dropped, and the AI gold rush is giving attackers more targets than ever.

💡 Key Takeaways

  1. Compromised LiteLLM versions on PyPI exposed credentials from over 2,500 organizations during a 40-minute window in March.
  2. The attack originated from a prior breach of Trivy, showing how a single compromised developer tool can cascade across the software supply chain.
  3. TeamPCP, a group largely composed of teenagers, claimed responsibility, demonstrating that sophisticated-feeling breaches no longer require nation-state resources.
  4. The exposed data included cloud keys, SSH keys, Kubernetes secrets, and AI provider credentials, putting both infrastructure and AI services at risk.

Keep reading: See related articles below for more coverage on this topic.

Get smarter about AI

The sharpest AI news, curated daily. Delivered free to your inbox.

Learn more

Glossary terms

← Back to all articles