Skip to content
Live newsroom 63 readers online
Friday, August 21, 2026 Live Sync: Just now
Demystifying Finance, Technology, and Global Markets for the Next Generation.
Breaking‘Incredible’ Dragons’ Den star gives one of the most powerful pitches ever
Share Suggestions AVOID MSFT Stage 4 (Conv: 3/5 | Size: 10%)

Your data can get stolen through a company you’ve never heard of

Cybersecurity for businesses involves a lot of jargon unfamiliar to us consumers, and for good reason. Such language generally doesn’t apply to our lives. But one concept has begun affecting us everyday users more—supply chain attacks. A supply chain attack is when hackers go after a vendor or partner that a company works with, rather […]

By deepak · August 21, 2026 · 3 min read

Cybersecurity for businesses involves a lot of jargon unfamiliar to us consumers, and for good reason. Such language generally doesn’t apply to our lives. But one concept has begun affecting us everyday users more—supply chain attacks.

A supply chain attack is when hackers go after a vendor or partner that a company works with, rather than attacking the business directly. The bad actors focus on a weaker link in the chain, then use that opening to steal information from the main target. (Or at least, see what kind of dirt they can get on other organizations.)

Before AI, this kind of hack mostly stayed confined in the corporate realm. Now consumers often end up at risk after business-to-business attacks, too. It’s a new way of thinking about supply chain attacks—where they’re not just a problem for IT departments.

The hack of a Valve partner ended up affecting Steam Machine buyers in Europe.

Just a few years ago, supply chain attacks were more rare—and quieter. But now with AI in the mix, they’re happening more often, and with bigger consequences. 

This summer alone, multiple supply chain attacks made the news, including a major one involving terabytes of data and the world’s largest corporations. (Think Nvidia, Samsung, Amazon, Microsoft, Airbus, FedEx, MediaTek, X/Twitter, Epic Games—and that’s just part of the list.) The attack focused on an open-source AI tool called LiteLLM, which pulls together large-language model use into a single interface. Through that breach, hackers stole credentials, secrets, tokens, and keys belonging to those major businesses.

Meanwhile, closer to home for us consumers, Valve sent out a warning to Steam Machine buyers in Europe about the hack of a distributor. Meanwhile, modular PC maker Framework lost personal information on all customers after an exploit of Metabase, the partner who hosted the data.

The danger: Use of the stolen data could end up in scam texts, email, or phone calls.

Unfortunately, you can’t do much about cyberattacks on businesses, much less the fallout. (For example, we don’t know what will happen with the LiteLLM breach—if ripple effects will include further compromise of those major corporations.)

But you can change how you interact with text, email, and phone call notifications. Be suspicious of messages about package delays, problems with your accounts, or dangers lurking on your PC. 

If you think you may actually have an account issue, contact the website or service directly. Either call on a number you looked up on the website, go to the website in a tab you opened yourself, or open your app.

Why? In the old days, people assumed having their basic details out on the web wasn’t a problem. But AI now allows bad actors to easily create personalized scams, with ever-increasing convincing detail, faster speed, and bigger target groups. Seeing them for what they are is becoming harder. So cut them off at the source. Bypass questionable messages and you shouldn’t get snared in their net.

Source: Read the original article on www.pcworld.com