Before AI, this kind of hack mostly stayed confined in the corporate realm. Now consumers often end up at risk after business-to-business attacks, too. It’s a new way of thinking about supply chain attacks—where they’re not just a problem for IT departments.
Table of Contents
Supply chain attacks now suck for everyone
The hack of a Valve partner ended up affecting Steam Machine buyers in Europe.
Valve
Just a few years ago, supply chain attacks were more rare—and quieter. But now with AI in the mix, they’re happening more often, and with bigger consequences.
This summer alone, multiple supply chain attacks made the news, including a major one involving terabytes of data and the world’s largest corporations. (Think Nvidia, Samsung, Amazon, Microsoft, Airbus, FedEx, MediaTek, X/Twitter, Epic Games—and that’s just part of the list.) The attack focused on an open-source AI tool called LiteLLM, which pulls together large-language model use into a single interface. Through that breach, hackers stole credentials, secrets, tokens, and keys belonging to those major businesses.
Meanwhile, closer to home for us consumers, Valve sent out a warning to Steam Machine buyers in Europe about the hack of a distributor. Meanwhile, modular PC maker Framework lost personal information on all customers after an exploit of Metabase, the partner who hosted the data.
The danger: Use of the stolen data could end up in scam texts, email, or phone calls.
What to watch out for now
PCWorld
Unfortunately, you can’t do much about cyberattacks on businesses, much less the fallout. (For example, we don’t know what will happen with the LiteLLM breach—if ripple effects will include further compromise of those major corporations.)