Software supply chain vulnerabilities require vigilant oversight and swift response to safeguard critical systems. In Parliament, I asked the government about data compromised in the LiteLLM open-source AI software supply chain attack, the remedial actions taken to secure exposed accounts, and measures to prevent future occurrences. Malicious code inserted through compromised login credentials could have far-reaching security risks across public and commercial sectors if left unchecked.
The Minister for Digital Development and Information explained that GovTech used scanning and detection tools to identify affected agencies promptly. The breach affected only one user account supporting a small number of agencies, and those involved changed exposed login details and checked system records. The Minister confirmed there is no evidence that any government data, including personal data, was stolen or compromised, while SingCERT issued an advisory for commercial entities.
This is the full question and answer in Parliament on 10 Sep 2026:
Government and Commercial Data Compromised in LiteLLM Supply Chain Attack and Measures to Prevent Recurrence
Mr Gerald Giam Yean Song asked the Minister for Digital Development and Information (a) what types of data owned by the Government or commercial entities in Singapore were compromised in the AI supply chain attack on LiteLLM; (b) what remedial actions were taken to safeguard any personal and Government data lost; and (c) what is being done to prevent a recurrence.
Mrs Josephine Teo: LiteLLM is widely used open-source AI software. Hackers compromised it by using login details stolen in an earlier breach to add malicious code to software updates.
GovTech used scanning and detection tools to identify the affected Government agencies and informed them quickly. The attack was confirmed to have compromised only one user account, which supported a small number of agencies. The affected agencies changed any login details that might have been exposed and checked their system records for signs of unauthorised activity. There is no evidence that any Government data, including personal data held by the Government, was stolen or compromised.
The Government does not have a complete picture of how the incident affected commercial entities. Each company should check its own systems, fix any problems, and make any required reports. SingCERT has published an advisory on the incident and can provide cybersecurity guidance and help where needed.
Attacks on software supply chains are an ongoing threat. The risks cannot be removed completely. However, the Government will keep reviewing and improving how it prevents, detects, and responds to such attacks, so that similar incidents are less likely and cause less harm.
Discover more from geraldgiam.sg
Subscribe to get the latest posts sent to your email.