MDDI's Response to PQ on Government and Commercial Data Compromised in LiteLLM Supply Chain Attack and Measures to Prevent Recurrence
10 September 2026
Parliament Sitting on 10 September 2026
Question for Written Answer
31. Mr Gerald Giam Yean Song asked the Minister for Digital Development and Information (a) what types of data owned by the Government or commercial entities in Singapore were compromised in the AI supply chain attack on LiteLLM; (b) what remedial actions were taken to safeguard any personal and Government data lost; and (c) what is being done to prevent a recurrence.
Answer
LiteLLM is widely used open-source AI software. Hackers compromised it by using login details stolen in an earlier breach to add malicious code to software updates.
GovTech used scanning and detection tools to identify the affected Government agencies and informed them quickly. The attack was confirmed to have compromised only one user account, which supported a small number of agencies. The affected agencies changed any login details that might have been exposed and checked their system records for signs of unauthorised activity. There is no evidence that any Government data, including personal data held by the Government, was stolen or compromised.
The Government does not have a complete picture of how the incident affected commercial entities. Each company should check its own systems, fix any problems, and make any required reports. SingCERT has published an advisory on the incident and can provide cybersecurity guidance and help where needed.
Attacks on software supply chains are an ongoing threat. The risks cannot be removed completely. However, the Government will keep reviewing and improving how it prevents, detects, and responds to such attacks, so that similar incidents are less likely and cause less harm.
