{"slug": "in-supply-chain-cyberattacks-ai-is-being-used-to-fight-ai", "title": "In supply chain cyberattacks, AI is being used to fight AI", "summary": "Supply chain operators are turning to AI-enabled tools to both prevent and respond to cyberattacks as breaches at Uber Freight, Ceva Logistics, and Coca-Cola's Fairlife brand mount, according to Business Insider. IBM reported this year that identifying the source of a data breach takes an average of 247 days, and a March 2026 software supply chain attack on the open-source tool LiteLLM exposed cloud keys, credentials, and terabytes of data across more than 2,500 organizations, per disclosures from CloudSEK and Hudson Rock. ZEDEDA founder and CEO Said Ouissal said the risk grows \"as we do more and more intelligent things with these computers and as more and more they're becoming the brain of an autonomous system.", "body_md": "A series exploring the companies, leaders, and workers who are at the forefront of the AI supply-chain revolution.\n\nIn mid-August, [Uber Freight](https://www.businessinsider.com/ai-trucking-logistics-uber-freight-tech-optimize-routes-2025-4) revealed a cybersecurity incident involving unauthorized access to a portion of its systems and data.\n\nDays prior, [Ceva Logistics](https://www.businessinsider.com/reverse-logistics-experts-executives-wrangling-e-commerce-returns-power-players-2022-7), a subsidiary of CMA CGM, reported a data breach that affected numerous companies and leaked their customers' personal information. Weeks before that, Coca-Cola's dairy brand Fairlife was hit by a [ransomware attack](https://www.businessinsider.com/what-to-know-about-the-growing-threat-of-ransomware-attacks-2021-11), prompting the company to temporarily suspend its US operations.\n\nConcerns around supply chain hacks are only growing, \"as we do more and more intelligent things with these computers and as more and more they're becoming the brain of an autonomous system,\" Said Ouissal, the founder & CEO of the [edge-computing software](https://www.businessinsider.com/ai-edge-computing-5g-cloud-artificial-intelligence-2024-3) company ZEDEDA, told Business Insider.\n\nWarehouses and plants are adopting AI technologies like trackers on trucks and forklifts, cameras and temperature sensors inside facilities, laptops and tablets, and GPS systems. As they do, they're becoming more vulnerable to cybersecurity incidents, said Bart Bullard, the chief technology officer of Source Logistics, a warehousing, fulfillment, and transportation provider.\n\nIt's a catch-22: the very technologies that supply chain operators use to stay competitive are also \"vectors of entry\" for hackers to gain access to company systems, Bullard said.\n\nAs supply chain executives grapple with this increasingly common challenge, they're also finding that AI can be a part of the solution, Ouissal said.\n\n## **What's at stake in a supply chain cyberattack**\n\nWhen a data breach occurs, companies will shut down their systems until they can identify the source of the issue. That can take an average of 247 days, according to an IBM report this year.\n\nSupply chain attacks are particularly problematic because a data breach that suspends operations can disrupt the timing of the entire supply chain. Production is delayed and products could expire, Bullard said.\n\nThat's what happened when Jaguar Land Rover was hit by a cyber attack last fall. Production halted for six weeks. During the shutdown, suppliers lost work, and some small companies went out of business, said Liz James, a managing security consultant at cybersecurity firm NCC Group.\n\nAttacks also occur within the software supply chain, Ouissal said. A bad actor hacks a piece of software, which then gets distributed to multiple businesses operating robots. The result is [malware running the bots](https://www.businessinsider.com/microsoft-thwarts-massive-botnet-that-could-have-targeted-elections-2020-10).\n\nThis type of attack was disclosed last month by CloudSEK and Hudson Rock. The groups revealed that a software supply chain attack poisoned the [open-source tool LiteLLM](https://www.businessinsider.com/mercor-lawsuits-data-breach-2026-4) in March 2026. The data breach exposed cloud keys, credentials, and terabytes of data across more than 2,500 organizations.\n\n## **Preventing cyberattacks and responding with AI**\n\nFighting cyberattacks in the supply chain requires both preventing and responding to them — often with the assistance of AI-enabled tools, as well as human training and expectation-setting, Ouissal said.\n\nCompanies use AI to scan software and detect hidden vulnerabilities that humans haven't noticed. AI tools are programmed to detect oddities that deviate from standard patterns. If there's an unexpected issue, the company can immediately [deploy a patch](https://www.businessinsider.com/ai-security-gap-companies-researcher-sander-schulhoff-2025-12) to prevent hackers from exploiting the vulnerabilities.\n\nBob Krohn, a partner and manufacturing practice co-leader at consulting firm ISG, said it's important to train employees on [cybersecurity best practices](https://www.businessinsider.com/ways-to-protect-yourself-from-hacks-or-scams-2024-12), from the C-suite and white-collar supervisors to the shop floor. Workers should be trained to spot [phishing scams](https://www.businessinsider.com/ai-phishing-scams-automation-detection-2024-6), and employees with critical system access should use password managers, Bullard said.\n\n\"Everyone in an enterprise must become AI-security forward thinkers,\" Bullard said. He added that detecting attacks is increasingly challenging, as deepfake videos and voice calls become more sophisticated, and AI becomes more convincing at emulating behavior. The usual tells of a phishing scam — like odd grammar and misspelled words — disappear with the help of AI, Bullard said.\n\nCyber attacks in the supply chain are also changing how businesses approach supplier contracts and audits, James said.\n\nTwenty years ago, many businesses were accustomed to buying the same parts from the same suppliers for decades, according to Krohn. Now, companies tend to have diversified suppliers to manage risks like tariffs. Each time they work with another business, they have to [consider new cyber threats](https://www.businessinsider.com/openai-collective-action-cyber-defense-anthropic-hugging-face-hack-2026-8), since these entities can view business data and inventory levels, Krohn said. While firewalls exist, there are still gaps that a bad actor could exploit.\n\n\"You are opening yourselves up to cyber risk in an exponential way,\" Krohn said. He added: \"Choose your supply chain partners carefully. Make sure that they have the same sort of emphasis on cyber policies as you do.\"\n\nThat said, not all attacks can be proactively prevented. \"All our C-suite clients recognize that they are going to get hacked,\" Krohn said. That's why executives are focused on having plans in place to respond to a cyberattack.\n\nBattling cyberattacks with the help of AI is critical because hackers using AI can mine software code for vulnerabilities much faster than a human can, said Bullard.\n\n\"Fighting AI with AI is the only real avenue,\" Bullard said.", "url": "https://wpnews.pro/news/in-supply-chain-cyberattacks-ai-is-being-used-to-fight-ai", "canonical_source": "https://www.businessinsider.com/supply-chain-cyberattacks-ai-to-fight-ai-2026-9", "published_at": "2026-09-11 17:12:17+00:00", "updated_at": "2026-09-11 17:44:06.322446+00:00", "lang": "en", "topics": ["ai-safety", "ai-policy", "artificial-intelligence"], "entities": ["Uber Freight", "Ceva Logistics", "CMA CGM", "Fairlife", "Coca-Cola", "ZEDEDA", "Said Ouissal", "IBM"], "alternates": {"html": "https://wpnews.pro/news/in-supply-chain-cyberattacks-ai-is-being-used-to-fight-ai", "markdown": "https://wpnews.pro/news/in-supply-chain-cyberattacks-ai-is-being-used-to-fight-ai.md", "text": "https://wpnews.pro/news/in-supply-chain-cyberattacks-ai-is-being-used-to-fight-ai.txt", "jsonld": "https://wpnews.pro/news/in-supply-chain-cyberattacks-ai-is-being-used-to-fight-ai.jsonld"}}