2,500 Companies and 434,000 Pipelines Exposed – Largest AI Supply Chain Breach CloudSEK's research on the LiteLLM AI supply-chain attack found that 2,500+ organizations and 434,000 CI/CD pipelines were potentially exposed, with the threat actor group Team PCP compromising the AI infrastructure in March 2026. The FBI's July 2026 FLASH advisory warns that affiliated actors may weaponize harvested credentials, and affected organizations include Robert Bosch GmbH, London Stock Exchange Group, Thomson Reuters, FedEx, and X Corp. 2,500+ Companies and 434,000 CI/CD Pipelines Exposed in the Largest AI Supply Chain Breach of 2026 CloudSEK’s latest research examines the LiteLLM AI supply-chain attack, which potentially exposed 2,500+ organisations and 434,000 CI/CD pipelines worldwide. The report details the risks to cloud credentials, source-code repositories, Kubernetes environments and AI infrastructure, while highlighting how compromised AI dependencies can create enterprise-wide security exposure. Get the latest industry news, threats and resources. No items found. Executive Summary In March 2026, the threat actor group Team PCP orchestrated what is believed to be the largest supply chain attack targeting AI infrastructure by compromising LiteLLM. CloudSEK Threat Intelligence was able to get access to the victim information and is disclosing the details of all the impacted victims . We are sharing this openly so that every affected organization can act proactively The threat is still live: the FBI's July 2026 FLASH advisory FLASH-20260702-01 warns that affiliated actors are likely to weaponize the harvested credentials long after the original intrusion, which means further supply chain attacks remain a real possibility. Early awareness is the strongest defense; knowing you were impacted lets you rotate credentials, close the exposure, and harden before the next campaign hits. Attacks on AI infrastructure are on the rise and that is exactly what CloudSEK AIvigil, our AI Attack Surface Monitoring platform, is built to prevent. AIvigil continuously discovers, monitors, and secures exposed AI infrastructure, MCP servers, leaked AI credentials, vector databases, agentic workflows, and shadow AI. We combine the power of cyber threat intelligence and AI exposure to detect and prevent cyberattacks on AI infrastructure. Those exposed range from large AI companies and model providers to cybersecurity vendors, SaaS platforms, and enterprises worldwide. companies in CloudSEK's reconstructed exposure dataset 434,000 CI/CD pipelines potentially exposed 40 min approximate period the affected PyPI packages were live VICTIM EXPOSURE DATA Selected High-Confidence Organizations in the Exposure Dataset The records below are the leading organization-level matches supplied for this report. High confidence refers to the strength of the exposure match,not proof of successful compromise or attacker use. “Secrets” and “Runs” are reproduced as aggregate counts from the supplied dataset. Domains are shown only where provided. No secret values, credentials, internal paths, or personal information are included. Selected High-Confidence Organizations — continued Organization / domain Secrets Runs Confidence Robert Bosch GmbH — 1 1 High London Stock Exchange Group LSEG lseg.com 48 241 High Thomson Reuters thomsonreuters.com 0 36 High FedEx fedex.com 164 147 High Munich Re munichre.com 110 62 High MediaTek Inc. mediatek.com 126 119 High Volkswagen AG volkswagenag.com 0 2,242 High Deloitte deloitte.com 462 503 High The Kroger Co. kroger.com 95 35 High Siemens Energy siemens-energy.com 0 36 High Thales Group thalesgroup.com 146 266 High X Corp Twitter twitter.com 3,459 1,153 High Zscaler, Inc. zscaler.com 65 304 High Epic Games epicgames.com 62 31 High Selected High-Confidence Organizations , continued Organization / domain Secrets Runs Confidence Orange S.A. orange.com 180 5,642 High HP Inc. hp.com 1 18 High Philips philips.com 5 6 High Fortum Oyj fortum.com 823 455 High Vodafone Group Plc vodafone.com 83 51 High Carl Zeiss AG zeiss.com 119 178 High Deutsche Bahn AG , 25 35 High NGINX, Inc. nginx.com 267 269 High BT Group bt.com 216 325 High Liebherr liebherr.com 98 20 High Krungthai Bank Public Company Limited krungthai.com 614 604 High Roku, Inc. roku.com 61 51 High Interpretation requirement A high-confidence organization match should trigger private validation, notification, credential review, and log investigation. Public wording should remain “potentially exposed” unless malicious execution, exfiltration, unauthorized access, or downstream use has been independently verified. DATA AT RISK What matters for victims The stolen object was Cloud keys, repository tokens, SSH keys, Kubernetes secrets, package publishing credentials, environment variables, and AI provider keys could allow attackers to move far beyond the affected package. Removal does not end the incident. A package can disappear in minutes while copied credentials remain usable for weeks or months unless they are rotated and downstream activity is investigated. Automated pipelines amplify a brief compromise. CI/CD systems install dependencies at machine speed and often run with broad privileges, making a short publication window operationally significant. AI infrastructure is becoming a strategic target. Gateways, agents, vector stores, model endpoints, and MCP servers sit between sensitive data and systems capable of taking action. Actor context is secondary. Public reporting attributes the campaign to Team PCP; this report limits actor discussion to what defenders need for attribution and response. Important interpretation The 2,500+ company and 434,000 pipeline figures describe reconstructed exposure. They should not be read as proof that every listed organization was successfully compromised or that every credential was stolen. The Scale of Exposure What was taken On every compromised CI runner, TeamPCP's stealer tracked by Google as SANDCLOCK escalated to root and swept: SSH keys AWS, GCP, and Azure credentials Kubernetes tokens .env files and CI/CD secrets — including the values GitHub Actions tries to mask, scraped directly from /proc/