AI data company Mercor confirms a major data breach involving clients such as OpenAI, Anthropic, and others.

robot
Abstract generation in progress

Golden Finance reports that on April 3, according to Fortune, the startup Mercor, which provides training data for AI companies such as OpenAI, Anthropic, and Meta, confirmed that it suffered a major security vulnerability. The incident stemmed from a supply-chain attack targeting the open-source library LiteLLM, which is widely used by developers to connect AI services, with daily downloads reaching millions of times.
The attack was launched by the hacker group TeamPCP by embedding malicious code in LiteLLM to steal credentials. Another hacker group, Lapsus$, later claimed it had obtained up to 4TB of Mercor’s data, including source code, database records, internal Slack communications, and video recordings of platform chats. According to unverified reports, some of Mercor’s customers’ datasets and confidential information related to its AI projects may have been exposed. Mercor said it has taken swift measures to contain the situation and has initiated a third-party forensics investigation.

View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • Comment
  • Repost
  • Share
Comment
Add a comment
Add a comment
No comments
  • Pin