Meta has put its work with AI data contractor Mercor on hold after a major security breach raised alarms across the AI industry. The breach, linked to a supply-chain attack, potentially exposed sensitive data critical to several top AI labs.
Major AI Firms Rethink Ties with Mercor
Meta’s decision to pause work with Mercor is indefinite, sources told WIRED. The move comes as other big names in AI, including OpenAI and Anthropic, reassess their relationships with the startup amid concerns about the scope of the breach.
Mercor stands out from typical contractors. It provides tailored training data to some of the biggest AI labs, including OpenAI and Anthropic. These datasets are core secrets—key ingredients in building AI models like ChatGPT and Claude. Labs guard this data fiercely because it reveals how their models are trained and could hand rivals a competitive edge.
OpenAI hasn't halted current projects with Mercor but confirmed it's investigating how the breach might have exposed proprietary training data. The company stressed that no user data from OpenAI’s platforms was affected. Anthropic has remained silent on the issue so far.
What Happened with Mercor?
Mercor acknowledged the breach in a March 31 email to employees, describing it as part of a global security incident impacting thousands of organizations.
The attack traces back to a supply-chain compromise involving LiteLLM, a widely used open-source AI API tool.
The hacking group behind the incident, TeamPCP, inserted malicious code into LiteLLM’s updates. This allowed them to harvest credentials and infiltrate multiple companies using the tool, potentially including Mercor. The malicious updates were quickly removed once detected, but the damage had been done.
Mercor’s workforce, especially contractors working on Meta projects, have been left in limbo. They can’t log hours or advance work until the project restarts—if that ever happens.
Internal talks show the company is scrambling to find alternative projects to keep contractors employed.
Why the Breach Matters
Mercor is valued at around $10 billion and has made a name for itself by recruiting experts across medicine, law, and literature to generate specialized data that sharpens AI capabilities. Its clients include some of the most secretive AI labs in Silicon Valley.
Attacks targeting supply chains pose serious risks. Instead of hacking a single company directly, attackers compromise trusted software components that many firms rely on. That means thousands of companies can be hit all at once without warning.
TeamPCP’s role draws particular attention. The group has a reputation for sophisticated supply-chain intrusions.
They recently began collaborating with Lapsus$, a notorious extortion gang known for phishing and credential theft. Lapsus$ later claimed to have accessed Mercor’s data, though details remain murky.
Security experts warn that exposure of training datasets could give competitors insight into how AI models are built. That could weaken a company’s edge in the fast-paced AI race, especially with rival labs in the US and China watching closely.
Industry Response and Fallout
Mercor’s response has been swift. The company said it moved promptly to contain the breach and hired a third-party forensics team to investigate. Mercor's spokesperson emphasized customer and contractor privacy as a top priority and promised ongoing communication.
Despite these efforts, the breach has rattled confidence. The AI industry relies heavily on a handful of data contractors like Mercor, Surge, Handshake, Turing, Labelbox, and Scale AI. These firms operate behind a veil of secrecy, rarely speaking publicly about their work due to the sensitive nature of their data.
Meta pausing its partnership with Mercor shows just how fragile the AI supply chain is. It also makes people wonder about how the industry will safeguard its most valuable asset—training data—against future attacks.
Related Articles
- Anthropic Mythos access for US agencies
- OpenAI upgrades Codex with desktop agent powers
- Anthropic to Open 158,000 sq ft London Hub
The Mercor breach highlights the risks AI companies take while pushing to develop stronger models. With so much riding on secret training data, the industry’s next moves could shape the future of AI development.
This article was created with AI assistance.