Singapore's digital ministry has told Parliament that it has no complete picture of how the LiteLLM compromise affected commercial entities and that each company should check its own systems and make any required reports

Singapore Puts LiteLLM Checks on Deployers. The Leveraged Years regulation briefing card.

A written parliamentary answer is not an instrument and creates no obligation. The Government account of its own exposure is the part that will get quoted. The sentence that costs a deployer money is the one handing the assessment back.

The short version

Bottom line: This is a written answer to a parliamentary question, not an instrument. It creates no duty. It records what the Government says it found inside its own estate and states that each company should check its own systems, fix any problems, and make any required reports.

Who this affects: Engineering and security leads running open-source AI gateway or LLM proxy software, data protection officers who own breach notification decisions in Singapore, and CISOs assessing AI software supply chain exposure.

Issue date: 10 September 2026, the Parliament sitting of that date. Question for Written Answer No. 31, asked by Mr Gerald Giam Yean Song.

What changed: Nothing in law. The Government put on the record how it says the compromise worked, how far it reached inside Government, and that it does not have a complete picture of how the incident affected commercial entities.

Analysis: The answer refers to any required reports without naming the statute, the threshold or the deadline. Working out which report is required, on what trigger and to whom, is left with the deployer.

Primary sources: MDDI written answer on the LiteLLM supply chain attack

Instrument (EN)
Ministerial written answer on Government and commercial data compromised in the LiteLLM supply chain attack and measures to prevent recurrence
Authority
Ministry of Digital Development and Information, Singapore
Jurisdiction
Singapore
Status
Answered and published 10 September 2026
Bindingness
Non-binding. A written answer creates no obligation. Any reporting duty it alludes to arises under other law that the answer does not name
Issue date / next deadline
10 September 2026. No deadline, no reporting window and no review date is stated
Document
Parliament Sitting on 10 September 2026, Question for Written Answer, item 31
Primary source
https://www.mddi.gov.sg/newsroom/mddi-response-to-pq-on-government-and-commercial-data-compromised-in-litellm-supply-chain-attack-and-measures-to-prevent-recurrence/

What the Ministry says happened

The account is compact enough to set out in full, in the order the Ministry gives it. The Ministry states that LiteLLM is widely used open-source AI software, and that hackers compromised it by using login details stolen in an earlier breach to add malicious code to software updates.

On the Government side, it states that GovTech used scanning and detection tools to identify the affected Government agencies and informed them quickly, that the attack was confirmed to have compromised only one user account which supported a small number of agencies, and that the affected agencies changed any login details that might have been exposed and checked their system records for signs of unauthorised activity.

Then the finding that will be quoted most: the Ministry states there is no evidence that any Government data, including personal data held by the Government, was stolen or compromised. That is the Government reporting on itself, and the hedge is in the original. No evidence of theft is a different statement from no theft, and we keep the Ministry's wording rather than tidying it.

The question asked which data was compromised. The answer lists none

Limb (a) of the question asked what types of data owned by the Government or by commercial entities in Singapore were compromised. No type of data is named anywhere in the answer.

For the Government estate that follows from the finding: on the Ministry's account there is no evidence anything was taken, so there is nothing to categorise. For the commercial side the reason is different and is stated plainly, that the Government does not have a complete picture of how the incident affected commercial entities.

Stating that absence is not a criticism of the answer. It is the fact a reader needs, because any account circulating elsewhere that specifies categories of compromised Singapore commercial data is not sourced to this answer.

The Ministry also gives no count of affected agencies beyond a small number, no count of affected companies, no dates, no version numbers and no indicators of compromise. Where a government supplies a figure for one thing and not another, the absence is worth recording as a fact rather than filled in from elsewhere.

Where the work actually lands

One sentence carries the operational weight, and it is aimed at the private sector: each company should check its own systems, fix any problems, and make any required reports. That is a recommendation in a written answer that binds nobody and creates no obligation of its own. The Ministry adds that SingCERT has published an advisory on the incident and can provide cybersecurity guidance and help where needed.

Look at the construction of any required reports. It presupposes a duty arising somewhere else and does not say where. The answer names no statute, no trigger, no threshold and no reporting window. We are not going to supply one, because the answer does not, and a deployer working out whether a report is owed needs the actual instrument rather than a news desk's guess at which one.

What the sentence does settle is allocation. The Government is not going to tell a company whether it was exposed. The assessment, the remediation and the reporting decision all sit with the deployer, and the Government's contribution is an advisory and help on request. None of that is a duty this answer creates.

What an AI platform team can and cannot take from this

The described vector is worth reading carefully because it is not an AI-specific vulnerability. On the Ministry's account, credentials stolen in an earlier breach were used to push malicious code into software updates of a widely used open-source component. The AI part is which component it was, and therefore what it sits in front of.

That is the reason an LLM gateway is an uncomfortable place for this to happen. A proxy layer of that kind typically sees traffic from many internal systems at once, which is a scope question rather than a severity question. That observation is ours, not the Ministry's, and the answer says nothing about what LiteLLM was deployed in front of in any affected environment.

The answer closes on a note that reads as deliberate: attacks on software supply chains are an ongoing threat, the risks cannot be removed completely, and the Government will keep reviewing and improving how it prevents, detects and responds to such attacks so that similar incidents are less likely and cause less harm. No programme, review or instrument is named.

What we did not verify

What we opened: the published written answer on the Ministry's newsroom, read in full, including the dateline of 10 September 2026, the sitting header, the three-limb question as tabled with its number and the name of the member who asked it, and all four paragraphs of the Answer.

What we did not open: the SingCERT advisory the answer refers to, any LiteLLM project security advisory, release notes or affected version list, the Personal Data Protection Act notification provisions, the Cybersecurity Act, and any GovTech technical account of the incident. We did not independently verify any statement about the incident. Every factual claim about what happened in this piece is the Ministry's, attributed to the Ministry, and a self-reported account is primary for provenance and not independent confirmation.

What we refuse to claim: we do not say no Government data was stolen, because the Ministry said there is no evidence of theft. We do not name the statute behind any required reports, because the answer names none. We do not state how many commercial entities were affected, or what data of theirs was involved, because the Government says it does not have a complete picture. We do not identify affected LiteLLM versions or dates, because the answer gives none. We do not say a Singapore company has a reporting duty arising from this incident, because whether one arises depends on facts and on instruments this answer does not address.

Quotations are reproduced with ASCII punctuation in place of the typographic characters used in the published answer, which is a house typesetting convention and not a change to any word.

Informational analysis for working professionals, not legal advice. Confirm how any rule applies to your situation with qualified counsel.

Key compliance takeaway

The transferable question is not whether you run LiteLLM. It is whether anyone in your organisation can say, today and without a project, which AI gateway, proxy or orchestration components are in your build, how their updates are pinned and verified, and who decides within hours whether an exposure is reportable. Singapore's Government has just said in Parliament that it cannot answer that question on any company's behalf, and that each company should check its own systems and make any required reports. That answer is non-binding and imposes no duty of its own; any report actually owed arises under instruments it does not name.

Source File

https://www.mddi.gov.sg/newsroom/mddi-response-to-pq-on-government-and-commercial-data-compromised-in-litellm-supply-chain-attack-and-measures-to-prevent-recurrence/

Open the written answer and confirm three things: the description of the vector in the first paragraph of the Answer, the single-account finding and the no-evidence-of-theft sentence in the second, and the sentence in the third placing the checking, fixing and reporting on each company.

The Government does not have a complete picture of how the incident affected commercial entities. Each company should check its own systems, fix any problems, and make any required reports. ยท MDDI written answer, Parliament Sitting on 10 September 2026, Question for Written Answer No. 31, first two sentences of the third paragraph of the Answer

FAQ

Was Singapore Government data stolen in the LiteLLM compromise?

The Ministry states there is no evidence that any Government data, including personal data held by the Government, was stolen or compromised. It also states that the attack was confirmed to have compromised only one user account, which supported a small number of agencies. That is the Government's own account of its own estate, and no evidence of theft is not the same statement as no theft.

Does this answer create a reporting duty for Singapore companies?

No. A written answer creates no obligation. It states that each company should check its own systems, fix any problems, and make any required reports, and it does not name the statute, the trigger, the threshold or the deadline for those reports.

How did the attackers get in?

The Ministry states that hackers used login details stolen in an earlier breach to add malicious code to software updates of LiteLLM, which it describes as widely used open-source AI software. The answer gives no version numbers, no dates and no indicators of compromise.

What did the Ministry say about preventing a recurrence?

It states that attacks on software supply chains are an ongoing threat, that the risks cannot be removed completely, and that the Government will keep reviewing and improving how it prevents, detects and responds to such attacks so that similar incidents are less likely and cause less harm. No specific programme, review or instrument is named.

Sponsored Training

Practical AI training for regulated professionals, built around verification, documentation and a defensible process. See the courses.

."}}]}