Finnish companies hit by major cyberattack targeting AI software
Translated from Finnish, summarized and contextualized by DistantNews.
At a glance
- Several Finnish companies were targeted in a large-scale cyberattack in March, exploiting vulnerabilities in software used for AI model management.
- The attack, identified as a supply chain attack, leveraged the LiteLLM and Trivy software, potentially affecting up to 2,500 companies globally.
- Finnish companies Smartly and Fortum reported limited impact, stating customer data remained secure, while other Finnish entities like Veikkaus, Cinia, and UPM-Kymmene may also have been affected.
A significant supply chain cyberattack in March impacted numerous Finnish companies, exploiting vulnerabilities in software used for managing artificial intelligence models. Security firms Cloudsek and Hudson Rock reported that the attack leveraged the LiteLLM software, which integrates and manages AI models, and potentially the Trivy vulnerability scanner.
Cloudsek described the incident as potentially the largest supply chain attack targeting AI infrastructure to date, estimating that up to 2,500 companies worldwide, including major players like Amazon Web Services, Samsung Electronics, and X Corp, were affected. Based on Cloudsek's data, the Finnish software company Smartly appears to have been heavily targeted among Finnish entities.
The attacker did not gain access to customer data or other confidential information.
Smartly's communications department stated that the attacker did not gain access to customer data or other confidential information. They confirmed that the compromise of the Trivy software on March 19 had a limited impact on Smartly, affecting internal credentials. The company asserted that it quickly regained control, replaced the compromised credentials, and ensured no customer impact.
Energy company Fortum was also identified by Cloudsek as a significant target. Fortum's communications team reported that while they investigated the claim as a precaution, they found no indications of system breaches or unauthorized access. One observation related to a brief exposure was detected, investigated, and rectified by Fortum in April. Other Finnish entities, including Veikkaus, Cinia, and UPM-Kymmene, may also have been affected, though the extent of compromised data appears small in many cases.
The company has observed a brief exposure, which it investigated and rectified in April.
Originally published by Helsingin Sanomat in Finnish. Translated, summarized, and contextualized by our editorial team with added local perspective. Read our editorial standards.