Monday, August 3, 2026

Policy & Regulation

Mercor faces fallout after data breach exposes 4TB of data

Mercor, a $10 billion AI data training startup, is facing lawsuits and paused contracts after a hacker group claimed to have stolen 4TB of data.

Mercor faces fallout after data breach exposes 4TB of data

On March 31, the AI data training startup Mercor admitted that it was the target of a data breach. Since making this admission, the company has been facing a world of trouble. A hacker group claims to have obtained 4TB of stolen data from Mercor’s systems. In the immediate aftermath of the incident, Meta, a client of the startup, paused its contracts with Mercor indefinitely, according to sources who spoke to Wired. At the same time, OpenAI, another client, is investigating its exposure in the breach, though the company has not paused or terminated its contracts.

The security incident originated from a hack of LiteLLM, an open source tool used for LLM API management whose compromise led directly to the Mercor data breach. For 40 minutes, the open source tool harbored credential harvesting malware, which is rogue software designed to steal login credentials. These harvested credentials were subsequently used to gain unauthorized access to additional software and accounts, which were then used to harvest even more credentials.

The fallout from the breach has quickly escalated into legal action. Five contractors have filed lawsuits against Mercor over their alleged personal data exposure, Business Insider reported. One of these lawsuits also names LiteLLM and Delve, an AI compliance startup, as defendants. Delve has been accused by an anonymous whistleblower of allegedly faking data for security certifications and using rubber-stamping auditors. Following these allegations, the investor Y Combinator severed ties with Delve.

Despite the current operational turmoil, Mercor remains a significant player in the AI training space. The startup previously raised $350 million in a Series C funding round, which valued the company at $10 billion. Earlier this year, Mercor was reportedly on pace to hit over $1 billion in annualized revenue, according to an anonymous source. The startup’s market position was notable enough that Meta continued to contract with it even after spending $14.3 billion on its competitor, Scale AI. Addressing the ongoing situation, Mercor stated that it “will continue to communicate with our customers and contractors directly as appropriate and devote the resources necessary to resolving the matter as soon as possible.”

Why it matters

The security incident at Mercor highlights the vulnerability of the AI supply chain, where a brief compromise of an open source tool can disrupt a startup valued at $10 billion. As clients pause contracts over data exposure, the fallout underscores the high stakes of securing the training pipelines that power artificial intelligence.