Written Answer · 2026-09-10 · Parliament 15
Government and Commercial Data Compromised in LiteLLM Supply Chain Attack and Measures to Prevent Recurrence
Workers' Party MP Gerald Giam Yean Song asked the Minister for Digital Development and Information what Government or commercial data in Singapore was compromised in the AI supply chain attack on LiteLLM, what remedial actions were taken, and how a recurrence will be prevented. Minister Josephine Teo replied that LiteLLM is widely used open-source AI software, compromised by hackers who used login details stolen in an earlier breach to add malicious code to software updates. GovTech used scanning and detection tools to identify affected agencies and informed them quickly; only one user account, supporting a small number of agencies, was compromised. The agencies changed exposed login details and checked system records, and there is no evidence that any Government data, including personal data, was stolen or compromised. The Government does not have a complete picture of the impact on commercial entities; companies should check their own systems and make required reports, and SingCERT has published an advisory. Supply chain risks cannot be removed completely, but the Government will keep improving prevention, detection and response.
Why it matters
The LiteLLM attack compromised only one Government user account with no evidence of Government data theft, but the Government lacks a full picture of the impact on companies.
Key Points
- • Hackers used login details stolen in an earlier breach to add malicious code to software updates of the open-source AI software LiteLLM.
- • GovTech used scanning and detection tools to identify the affected Government agencies and informed them quickly.
- • The attack was confirmed to have compromised only one user account, which supported a small number of agencies; they changed potentially exposed login details and checked system records for unauthorised activity.
- • There is no evidence that any Government data, including personal data held by the Government, was stolen or compromised.
- • The Government does not have a complete picture of the impact on commercial entities; the Singapore Cyber Emergency Response Team has published an advisory and can provide guidance and help.
- • Supply chain attack risks cannot be removed completely, and the Government will keep reviewing and improving how it prevents, detects and responds to them.
The Government said the impact on its systems was limited to one user account, with no evidence of Government data being stolen. It did not describe what commercial data was affected, saying it lacks a complete picture and that companies must check their own systems and make required reports, and acknowledged supply chain risks cannot be removed completely.
Questioner Mr Gerald Giam (Workers' Party) asked what Government and commercial data in Singapore was compromised in the LiteLLM supply chain attack, what remedial action was taken and how a recurrence will be prevented.
Open-source AI components have become a real attack surface for Government systems; leaving companies to self-check and self-report with SingCERT guidance suggests AI supply chain security will, for now, rest mainly on each organisation's own defences rather than central monitoring.
"Attacks on software supply chains are an ongoing threat."
Participants (2)
Original Text (English)
SPRS Hansard · Fetched: 2026-09-26
31 Mr Gerald Giam Yean Song asked the Minister for Digital Development and Information (a) what types of data owned by the Government or commercial entities in Singapore were compromised in the artificial intelligence (AI) supply chain attack on LiteLLM; (b) what remedial actions were taken to safeguard any personal and Government data lost; and (c) what is being done to prevent a recurrence.
Mrs Josephine Teo : LiteLLM is widely used open-source artificial intelligence (AI) software. Hackers compromised it by using login details stolen in an earlier breach to add malicious code to software updates.
GovTech used scanning and detection tools to identify the affected Government agencies and informed them quickly. The attack was confirmed to have compromised only one user account, which supported a small number of agencies. The affected agencies changed any login details that might have been exposed and checked their system records for signs of unauthorised activity. There is no evidence that any Government data, including personal data held by the Government, was stolen or compromised.
The Government does not have a complete picture of how the incident affected commercial entities. Each company should check its own systems, fix any problems and make any required reports. The Singapore Cyber Emergency Response Team has published an advisory on the incident and can provide cybersecurity guidance and help where needed.
Attacks on software supply chains are an ongoing threat. The risks cannot be removed completely. However, the Government will keep reviewing and improving how it prevents, detects and responds to such attacks, so that similar incidents are less likely and cause less harm.