Technology

Terabytes of credentials leaked in massive supply-chain attack

Attackers stole sensitive data from thousands of companies over 40 minutes.

◆2 independent outlets◆3 source items◆heat 0.06◆updated 10m

Outlets are counted by registrable domain, so a broadcaster’s station subdomains count once. 1 of the 3 items repeat an outlet already counted.

The engine’s read

Attackers stole sensitive data from thousands of companies over 40 minutes.

What was stolen

Security firms CloudSEK and Hudson Rock reported terabytes of access credentials were exposed in a supply-chain attack on LiteLLM, a popular open-source tool used in AI software development.

The data, scraped from the memory of infected machines in March, included cloud keys, repository tokens, SSH keys, Kubernetes secrets, and credentials for AI providers and package publishing.

The firms said the leaked credentials could allow attackers to access over 2,500 organizations, naming major companies like Microsoft, Amazon, Cisco, Samsung, and Salesforce among the victims.

How the breach happened

The attackers compromised LiteLLM through a prior supply-chain attack on the Trivy vulnerability scanner, a security researcher corroborated. Other software, including KICS and the Telnyx Python SDK, were also infected.

During a 40-minute window, victims who downloaded compromised versions of LiteLLM from its official Python Package Index repository had their machine memory accessed and data sent to an attacker-controlled channel.

Researchers largely credit a group called TeamPCP, described as a highly capable gang largely composed of teenagers, for the attack.

The scale of exposure

Analysts at CloudSEK and Hudson Rock said approximately 434,000 CI/CD software pipelines had credentials exposed after running the compromised software.

The credential archive was so large and complex that researchers reported having trouble identifying all the organizations affected by the leaked data.

Hudson Rock said it made its discovery after analyzing a 195-terabyte file it obtained, while CloudSEK reported finding 'a significant volume of sensitive content at orgs'.

Coverage

2 independent outlets filed 3 reports over 18 days.

2outlets
3filings
430hspan
singletrend
Why this is happeningwritten from what the engine measured

This supply-chain breach is a complex system shock, not just a leak. The dominant force is exploration, which is critically high. This means the full scope and capability of the attack remain unknown, and defenders are scrambling to understand exactly what data was taken and how it could be used next.

Interaction is also at a critical level. The breach has instantly tied together 2,500 victim organizations, law enforcement, and security researchers. Every move one of them makes now directly affects the others, creating a tightly linked response network that is difficult to coordinate but impossible to ignore.

A high level of cost and friction is working against a fast, unified fix. The financial and operational burden on victims to change credentials and shore up systems is immense. Getting thousands of companies and independent developers to cooperate creates significant practical drag, slowing down the overall response.

What could happen nextsealed to the ledger before this was written
NOW60%Gradual Containment withLong-Term Damageby 30 Sept 202625%Immediate Cascading BreachChainby 15 Sept 202615%Rapid Containment with MinimalDamageby 25 Sept 2026
Each channel’s width is that outcome’s probability as it was sealed into the ledger, before this page existed. Widths are not rescaled to fill the frame, so branches that do not sum to 100% visibly do not. Where a cost is shown it is the dominant measured drag on that branch, not a price.
  • 60%Resolves YES if, by 2026-09-30 (UTC), at least two independent sources of the kind already tracked on this narrative report that gradual containment with long-term damage — specifically: Authorities and companies systematically contain the breach, but significant credential exposure leads to secondary attacks and regulatory consequences over months.. Resolves NO if the horizon passes without such reporting. Resolves VOID if the underlying question stops being answerable (for example the event is cancelled or superseded).#98fd725ea307
  • 25%Resolves YES if, by 2026-09-15 (UTC), at least two independent sources of the kind already tracked on this narrative report that immediate cascading breach chain — specifically: Leaked credentials trigger immediate secondary breaches across interconnected systems, creating a domino effect of security incidents.. Resolves NO if the horizon passes without such reporting. Resolves VOID if the underlying question stops being answerable (for example the event is cancelled or superseded).#b75fab9d3c9b
  • 15%Resolves YES if, by 2026-09-25 (UTC), at least two independent sources of the kind already tracked on this narrative report that rapid containment with minimal damage — specifically: Quick coordinated response by security teams and law enforcement contains the damage before widespread credential abuse occurs.. Resolves NO if the horizon passes without such reporting. Resolves VOID if the underlying question stops being answerable (for example the event is cancelled or superseded).#c161f0ed7b42
The bottom lineprovisional while the story is live

The story is still very much in motion, with the exact path of consequence depending on how the main forces—exploration of the attack's unknowns and the friction of a coordinated response—play out in the coming weeks. The system is in a low-certainty state, meaning future events will determine which forecast branch becomes reality.

What to watch are the specific resolution conditions for each branch. Credential reuse causing new breaches points toward the long-term damage scenario, while a fast cascade of incidents would confirm the imminent chain. A report of successful global credential rotations before major abuse would signal rapid containment.

The evidence3 items
The Verge30 Aug
Enormous 12TB Steam leak includes abandoned Half-Life 2: Episode 3 assets

Over 12 terabytes of data, containing builds of every game uploaded to Steam between 2003 and 2013, has been leaked. We don't know everything in the archives yet because of its massive size. But people have already dug up assets related to the canceled Half-Life 2: Episode 3, content cut from Portal 2, and a […]

Authorities arrest 2 alleged members of prolific hacking group TeamPCP

The group infected more than 1,000 organizations in a relentless supply-chain attack campaign.

Terabytes of credentials leaked in massive supply-chain attack

The data was scraped and exfiltrated from 2,500 users of a compromised AI package.

Sources are evidence, not content. Each keeps its own name, its own link and an extract capped at 400 characters; none of it is rewritten into the copy above.

More from Technology
1/8All →
FULL DISK ACCESS
Technology

Apple says it’s tightening macOS ‘Full Disk Access’ controls due to new risks from AI agents

Apple is changing the permissions system for Full Disk Access on its macOS operating system. It cites new and substantial risks created by AI agents able to manipulate other software.

3 outlets10m

News that moves. Intelligence that decides. Powered by GodEngine AI — forecasting the future from today’s headlines.

Stay Updated

Get every edition as it publishes. No list and no account — copy this into a feed reader, or point a WebSub client at it and be pushed.

© 2026 GodEngine AI. All rights reserved.Written and published by machine, with no human in the publish path. Every edition passes seven automated gates, carries the engine latency it was produced at, and links the evidence it read. Corrections are published as new entries on the story’s thread; the original text is never rewritten.