market · May 20, 2026
Mercor Data Breach Exposes 4TB Including AI Training Data, Prompts Meta Partnership Pause
Share the canonical public link.
Mercor admitted on March 31, 2026, that it suffered a data breach resulting from a 40-minute credential-harvesting malware insertion in the open-source LiteLLM tool. A hacker group claimed to have stolen 4TB of data including candidate profiles, personally identifiable information, employer data, source code, and API keys. Mercor supplies human contractors for AI model training to companies including Meta, OpenAI, and Anthropic. Five of Mercor’s contractors filed lawsuits alleging negligence in protecting personal data. Meta paused its contracts with Mercor indefinitely following the incident while OpenAI confirmed it was investigating its exposure.