London Stock Exchange Group PLCLondon Stock Exchange Group is listed among potentially affected organizations, risking exposure of credentials and source code.
CloudSEK ระบุองค์กรกว่า 2,500 แห่งที่อาจได้รับผลกระทบจากเหตุการณ์สำคัญในห่วงโซ่อุปทาน AI ที่เกี่ยวข้องกับ LiteLLM ในเดือนมีนาคม 2026 โดยมีไปป์ไลน์การพัฒนาซอฟต์แวร์อัตโนมัติประมาณ 434,000 รายการที่เชื่อมโยงกับการเปิดเผยข้อมูลดังกล่าว องค์กรที่อาจได้รับผลกระทบครอบคลุมอุตสาหกรรมสำคัญ ได้แก่ เทคโนโลยี ความมั่นคงปลอดภัยไซเบอร์ ธนาคารและบริการทางการเงิน โทรคมนาคม การผลิต การให้คำปรึกษา โลจิสติกส์ และซอฟต์แวร์องค์กร โดยมีการจับคู่ด้วยความเชื่อมั่นสูงกับองค์กรระดับโลกรายใหญ่ เช่น NVIDIA, Samsung Electronics, Cisco Systems, Siemens, S&P Global, ServiceNow, Deloitte, Vodafone, X Corp, Zscaler, FedEx, Volkswagen, Thales และ London Stock Exchange Group เหตุการณ์นี้เกิดขึ้นหลังจากกลุ่มอาชญากรไซเบอร์ Team PCP เจาะระบบ LiteLLM ได้ และมีรายงานว่าเวอร์ชันที่เป็นอันตรายถูกเผยแพร่ผ่านคลังซอฟต์แวร์ Python อย่าง PyPI เพียงประมาณ 40 นาทีเท่านั้น แต่การวิเคราะห์ของ CloudSEK ระบุไปป์ไลน์ CI/CD ประมาณ 434,000 รายการที่อาจเชื่อมโยงกับการเปิดเผยข้อมูลดังกล่าว ข้อมูลที่อาจเข้าถึงได้รวมถึงข้อมูลรับรองคลาวด์ การเข้าถึงซอร์สโค้ด คีย์เซิร์ฟเวอร์ ความลับในการพัฒนาซอฟต์แวร์ คีย์ API ของ AI และข้อมูลรับรองอื่น ๆ ที่อาจทำให้ผู้โจมตีเข้าถึงระบบธุรกิจที่สำคัญได้ และ CloudSEK เน้นย้ำว่าการปรากฏชื่อในชุดข้อมูลไม่ได้หมายความว่าองค์กรถูกเจาะระบบสำเร็จโดยอัตโนมัติ แต่ควรได้รับการตรวจสอบอย่างเร่งด่วน CloudSEK ได้เปิดตัวเครื่องมือตรวจสอบการเปิดเผยข้อมูลฟรีเพื่อช่วยให้องค์กรตรวจสอบว่าข้อมูลรับรองหรือโครงสร้างพื้นฐานที่เกี่ยวข้องกับตนปรากฏอยู่ในชุดข้อมูลที่ระบุหรือไม่
London Stock Exchange Group PLCLondon Stock Exchange Group is listed among potentially affected organizations, risking exposure of credentials and source code.
Samsung Electronics Co LtdSamsung is listed as potentially impacted by the LiteLLM supply chain compromise, with exposure of credentials and source code.
ServiceNow IncServiceNow is identified as potentially impacted, facing possible exposure of cloud credentials and development secrets.
NVIDIA CorporationNVIDIA is listed as a high-confidence match, potentially exposed to credential and source-code leaks via the compromised LiteLLM.
Space Exploration Technologies Corp. Class A Common Stock
Zscaler IncZscaler is named as potentially impacted by the LiteLLM supply chain compromise, with exposure of credentials and secrets.
Cisco Systems IncCisco is listed as potentially impacted by the LiteLLM supply chain compromise, with possible exposure of credentials and source code.
Thales S.A.Thales is listed as potentially impacted by the LiteLLM supply chain compromise, with exposure of credentials and source code.
ZSCALER INC. DL-,001
Vodafone Group PLCVodafone is identified as potentially impacted by the AI supply chain incident, with possible exposure of credentials and secrets.
S&P Global IncS&P Global is among potentially affected organizations, with possible exposure of sensitive credentials and system access.
Siemens AktiengesellschaftSiemens is named as potentially affected, with risk of credential and source-code exposure from the compromised LiteLLM.
Volkswagen AGVolkswagen is listed among potentially impacted organizations, facing potential exposure of credentials and development secrets.
FedEx CorporationFedEx is named among potentially affected organizations, with risk of credential and system access exposure.
Siemens Healthineers AG
Volkswagen AG VZO O.N.