I have a blog probably coming on this one btw, but Xploitrs have been using the credentials gathered from the Trivvy and LiteLLM breaches to hold companies worldwide to ransom, gaining access via their cloud environments. The victim orgs have been paying them to cover it up.

