AI data-training company Mercor confirmed in June 2026 that it was affected by a supply chain attack in late March targeting LiteLLM, a widely used open-source tool for connecting applications to large language models. Mercor, a San Francisco-based startup that supplies human-generated training data and evaluation work to major AI labs, said a malicious actor published compromised versions of LiteLLM designed to steal credentials from any system that installed them, and that its own systems were affected during that window.

According to Mercor's public statement, the company worked with outside forensics firms including Google's Mandiant and security firm Latacora, along with law enforcement, to investigate the incident. The company said its completed investigation found that only a limited subset of the nearly 5 million contract workers registered on its platform had sensitive information affected, and that it found no evidence the exposed data had been used fraudulently. Mercor began notifying affected individuals in late June and said it would offer identity protection services through TransUnion to those impacted.

Independent security researchers who tracked the broader LiteLLM incident reported a larger scope, describing a cascading attack in which a threat group first compromised an open-source vulnerability scanning tool, then used stolen credentials to publish malicious LiteLLM package versions to the Python Package Index. Multiple outlets covering the incident reported that data connected to Mercor, including contractor identity documents and platform source code, was later found circulating outside the company's systems, though Mercor's own disclosure characterized the confirmed impact on individuals as limited.

Mercor said it has since audited its third-party software dependencies, rotated credentials and access keys across its cloud and development systems, and implemented continuous security monitoring. The company said all of the frontier AI labs it works with have continued or increased their engagements with Mercor in the months following the incident.

Source: Mercor – https://www.mercor.com/blog/update-on-mercor-security-incident/