2,500+ Companies and 434,000 CI/CD Pipelines Exposed in the Largest AI Supply Chain Breach of 2026
According to CloudSEK Threat Intelligence, the Team PCP threat actor compromised LiteLLM in March 2026, exposing reconstructed data for 2,500+ organizations and about 434,000 CI/CD pipelines. CloudSEK says the FBI’s July 2026 FLASH advisory warns credentials may be weaponized later. Reported high-confidence victims include NVIDIA, AWS, Samsung, Salesforce, Cisco, and ServiceNow.
How this was made

The 30-second read
Why it matters
The newest actionable element is the named list of high-confidence exposed organizations and the specific credential classes described (cloud keys, repo tokens, SSH keys, Kubernetes secrets, CI/CD secrets, and AI provider keys). However, the article repeatedly states this is not proof of successful compromise, so direct financial impact is uncertain.
Market read
This is a defensive cybersecurity exposure disclosure that can drive short-term risk sentiment for listed victims, but it does not provide confirmed breach outcomes or quantified financial damage.
What to watch
Traders should wait for follow-on confirmation such as verified exfiltration, customer impact, regulatory inquiries, or material remediation costs, none of which are provided here.
Background
CloudSEK attributes a large AI infrastructure supply chain attack to Team PCP, claiming compromise of LiteLLM and publishing reconstructed exposure data for many organizations.
Ticker impact
The report lists NVIDIA Corporation (nvidia.com) as a high-confidence exposed organization with 153 secrets and 176 runs.
Near-term sentiment pressure is possible, but the article provides no confirmed breach or financial impact.
The piece is a defensive exposure disclosure with no verification of successful compromise or downstream misuse, limiting direct earnings impact visibility.
ServiceNow (servicenow.com) is listed as high-confidence exposed, with 44 secrets and 162 runs in the reconstructed dataset.
Moderate negative bias for risk sentiment, but likely limited unless follow-on reporting confirms impact.
The article repeatedly frames results as “potentially exposed” and “not proof of successful compromise,” reducing certainty of material financial effects.
Amazon Web Services (amazon.com) appears as high-confidence exposed with 19 secrets and 12 runs, implying cloud credential exposure risk.
Limited immediate price impact unless regulators or AWS-specific incident confirmation follows.
The disclosure is exposure-based and does not establish exfiltration, unauthorized access, or operational disruption.
Salesforce (salesforce.com) is listed as high-confidence exposed with 2 secrets and 4 runs in the dataset.
Low likelihood of a direct, material stock move from this article alone.
Small counts and lack of confirmed compromise make it difficult to infer financial magnitude.
Cisco Systems (cisco.com) is listed as high-confidence exposed with 327 secrets and 1,900 runs, indicating broad pipeline exposure.
Potential negative risk premium, but confirmation of impact is missing.
The article provides reconstructed exposure metrics, not verified compromise or business interruption.
F. Hoffmann-La Roche (roche.com) is listed as high-confidence exposed with 4 secrets and 16 runs.
Unlikely to drive a large move without follow-on confirmation of breach impact.
The report does not confirm malicious execution or exfiltration, and the counts are modest.
S&P Global (spglobal.com) is listed as high-confidence exposed with 1,218 secrets and 1,108 runs.
Possible short-term risk-off sentiment, but materiality is unproven here.
The article explicitly cautions that exposure metrics are reconstructed and not proof of successful compromise.
John Deere (deere.com) is listed as high-confidence exposed with 185 secrets and 203 runs.
Low to moderate negative sentiment risk, contingent on follow-up verification.
No evidence of successful compromise or financial impact is provided.
Market effects
Highlights systemic AI supply chain risk, likely increasing demand for CI/CD security, secret rotation, and build integrity monitoring.
Global multinational exposure list suggests cross-region incident response and vendor notification activity.
If confirmed by follow-on reporting, could raise broader confidence concerns around AI infrastructure dependencies and package ecosystems.
Counterpoint
Because the article is explicitly “potentially exposed” and not proof of compromise, the market may overreact to reconstructed exposure counts without evidence of real breaches.
Key entities
- threat_actorTeam PCP
Threat actor group attributed to the AI infrastructure supply chain campaign.
- software_projectLiteLLM
AI infrastructure component reportedly compromised in the supply chain attack.
- security_vendorCloudSEK
Threat intelligence firm disclosing reconstructed exposure details and offering an exposure-check platform.
- regulatory_advisoryFBI FLASH-20260702-01
July 2026 FBI advisory warning affiliated actors may weaponize harvested credentials later.




