Mercor suffers a LiteLLM supply-chain breach, Meta pauses its work and contractors sue

Mercor, the expert-data vendor described in B05-42, acknowledged a cyberattack on 2026-03-31 tied to a compromised release of the open-source LiteLLM gateway, whose poisoned versions were live for…

Date
31 March 2026
Who
Mercor, Meta, OpenAI
Confidence
Medium (press reports; the 4TB and contents figures are hacker and court-filing
Deep dive
RLHF and instruction tuning (how base models became assistants)

Tier: Supporting · Significance: 3/5 · Org(s): Mercor, Meta, OpenAI · Confidence: Medium (press reports; the 4TB and contents figures are hacker and court-filing claims, not independently confirmed) Mercor, the expert-data vendor described in B05-42, acknowledged a cyberattack on 2026-03-31 tied to a compromised release of the open-source LiteLLM gateway, whose poisoned versions were live for about 40 minutes. Attackers claimed to have taken about 4TB, including candidate profiles and personal information, employer data, source code and API keys; a Next Web report, citing court filings and hacker claims, describes interview video recordings, identity documents and personal data of more than 40,000 people. Wired reported that Meta paused its Mercor work indefinitely; OpenAI said it was investigating its exposure without ending its projects; and Business Insider reported five contractor lawsuits (TechCrunch, 2026-04-09; The Next Web; I did not open the Wired or Business Insider pieces). By July TechCrunch described the company as having moved past the incident, with a reported $20 billion valuation talk (TechCrunch, 2026-07-09). It belongs here because the expert-data model that replaced crowd labeling (B05-42) concentrates sensitive human data, including identity documents and labs' training methods, in a few vendors, which adds a security and confidentiality risk to the labor risks of B05-26. Sources: TechCrunch, 2026-04-09 · The Next Web · TechCrunch, 2026-07-09

Read it in the deep dive