Post-Cutoff.com
  1. Home
  2. Timeline
  3. 2026
  4. Mercor confirms breach via the LiteLLM supply-chain…

Mercor confirms breach via the LiteLLM supply-chain attack; Lapsus$ claims 4 TB of AI-training-contractor data

★★★policy-safetyMercorLiteLLMconfidence: medium

On March 31, 2026 Mercor, a $10B AI training-data and expert-contractor startup whose customers include OpenAI, Anthropic and Meta, confirmed a security incident. It said it was "one of thousands of companies" hit by a supply-chain attack on the open-source LiteLLM library. The extortion group Lapsus$ claimed about 4 TB of stolen data (source code, user database, interview videos and ID documents). Meta reportedly paused its Mercor contracts and contractors sued. The breach showed how one poisoned AI-infrastructure package can expose frontier labs' training-data pipelines.

Key facts

What happened

Late in March 2026 attackers tracked as TeamPCP compromised the publishing pipeline of LiteLLM, a popular open-source Python library that gives one interface to many LLM APIs. They shipped versions with credential-harvesting code. Secondary security write-ups say the malicious releases (1.82.7 and 1.82.8) were live for about 40 minutes and that the attackers reached LiteLLM's maintainer credentials through an earlier compromise of the Trivy scanner's GitHub Actions workflow. These details were not checked against a primary advisory. Mercor, which recruits domain experts to produce training data and RL environments for frontier labs, confirmed on March 31 that it had been hit. The Lapsus$ group then claimed it held about 4 TB of Mercor data and published samples.

Reports in early April said Meta paused its Mercor work indefinitely and that contractors whose IDs and interview videos may have been exposed had begun suing. Mercor did not confirm the size or contents of the stolen data, so the 4 TB breakdown remains the attackers' claim.

Why it matters

Data vendors like Mercor, Scale and Surge hold details of labs' secretive training projects (data specifications, labeling protocols, RL tasks) as well as sensitive personal data on large expert workforces. A single poisoned open-source dependency in the AI tooling stack was enough to put that at risk. The incident is pre-cutoff (March 2026) and is included as background for later AI supply-chain incidents.

Changelog

  • 2026-10-04: created (sweep item: TechJuice re-report of Oct 4; facts from Fortune and TechCrunch, April 2026)

Related events

  1. Snorkel AI raises $350M Series E at $3.5B as 'data-as-a-service' for frontier labs passes a $375M run rate ★★

Sources (5)

id: 2026-03-31-mercor-breach-litellm-supply-chain · updated 2026-10-04 · open in the interactive timeline