market · May 20, 2026
Mercor Data Breach via LiteLLM Supply Chain Attack Exposes Contractor Tax Records and AI Systems
Share the canonical public link.
Malicious actors inserted harmful code into LiteLLM updates, allowing attackers to extract API keys, tokens, and permissions from Mercor systems. The breach exposed contractor personal ID records, tax documents, recorded interviews, internal communications, source code, and potentially proprietary AI training datasets. Mercor supplies training data and human input to major AI developers including Meta Platforms, OpenAI, and Anthropic. Meta Platforms paused its work with Mercor following the incident while other AI firms began internal reviews of their exposure. Plaintiffs filed lawsuits alleging Mercor failed to implement reasonable cybersecurity safeguards and inadequate oversight of third-party tools.