{
  "id": 2284594,
  "title": "Massive supply-chain attack sees terabytes of data belonging to some of the world’s biggest and most sensitive organizations leaked online",
  "url": "https://urgent.news/2026/08/21/massive-supply-chain-attack-sees-terabytes-of-data-belonging-to-some",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-08-21T03:00:00.000Z",
  "source": {
    "name": "TechRadar",
    "slug": "techradar",
    "url": "https://www.techradar.com/pro/security/massive-supply-chain-attack-sees-terabytes-of-data-belonging-to-some-of-the-worlds-biggest-and-most-sensitive-organizations-leaked-online"
  },
  "original_language": "en",
  "account": "A massive supply-chain attack has exposed terabytes of sensitive data from some of the world's most prominent and critical organizations, according to security firms CloudSEK and Hudson Rock. The breach, which occurred on March 24, 2026, targeted LiteLLM, an open-source security scanner, which in turn allowed hackers to compromise credentials and secrets of numerous large companies.\n\nTeamPCP, a financially motivated hacking group, exploited a known vulnerability in Aqua Security's Trivy, an open-source security tool used for vulnerability scanning. The compromised package, downloaded and installed without proper verification, granted server administrator privileges and installed a stealer that harvested a plethora of sensitive information.\n\nThe stolen data includes crucial elements like Cloud keys, SSH keys, Kubernetes tokens, environment variables, repository and package-publishing tokens, and AI provider keys. These stolen assets pose a more significant security risk due to their widespread impact and the fact that they serve as keys to numerous security systems.\n\nThe compromised credentials, which were still functional five months after the attack, indicate a persistent security risk despite organizations' claims of rotating those keys. CloudSEK and Hudson Rock independently reported that more than 2,500 organizations and 434,000 CI/CD pipelines were affected by the breach, with Hudson Rock releasing a 153 GB archive of the exfiltrated data from a 195 TB file obtained during the attack.\n\nSecurity experts urge organizations to reevaluate their use of AI tools in mission-critical instances, as the breach could have far-reaching consequences for both customer data and trade secrets.",
  "summary": "Hackers compromised a security tool, used it to steal the publishing keys of a popular AI tool, and released a poisoned version under that tool's real name in a far-reaching attack",
  "key_points": [
    "Massive supply-chain attack exposes terabytes of sensitive data from major organizations.",
    "Hackers exploited vulnerabilities in LiteLLM and Aqua Security's Trivy tools.",
    "Compromised credentials and keys pose persistent security risk for 2,500+ organizations."
  ],
  "editors_take": "This breach heightens security concerns for organizations using AI tools and open-source security scanners, revealing a significant risk of compromised credentials and sensitive data being exploited.",
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}