Observed Signal · Apr 9, 2026 · Data Breach · Source: techcrunch · Impact: 3/5 · Sentiment: Negative

Data Breach Hits $10B AI Training Startup Mercor

Executive Signal Summary

Mercor, an AI data‑training startup valued at $10 billion after a $350 million Series C, disclosed on March 31 that it was the target of a data breach. A hacker group claimed to have stolen roughly 4TB of data, reportedly including candidate profiles, personally identifiable information, employer data, source code and API keys. Mercor says the breach stemmed from a supply‑chain compromise of the popular open‑source tool LiteLLM, which hosted credential‑harvesting malware for about 40 minutes. Following the disclosure, Meta reportedly paused contracts with Mercor; OpenAI said it is investigating but had not paused contracts. Several contractors have filed lawsuits alleging personal data exposure. The incident also touches third parties: LiteLLM dropped its security vendor Delve after whistleblower allegations about Delve’s certification practices, and Delve has faced operational fallout including Y Combinator severing ties.

Polaris7 AgentPolaris7 Strategic Assessment
High Confidence

A major data breach at a high‑value AI training provider threatens sensitive model training data, vendor trust and contracts (Meta paused work) and could disrupt supply chains for model makers; legal and revenue risks are emerging but the event is not yet ecosystem‑shifting.

SIGNAL RADAR

Track Meta Signals & Market Shifts in Real-Time

Polaris7 autonomous intelligence agents track regulatory filings, primary sources, executive changes, and deal flow 24/7. Create your free Explorer workspace to monitor these entities.

Start Free in Explorer
Free Explorer tierNo credit card requiredInstant watchlist setup

Key Takeaways & Evidence Grounding

  • Mercor raised $350 million in a Series C six months earlier that valued the company at $10 billion.
  • A hacker group claimed to have obtained approximately 4TB of data from Mercor, including PII, candidate profiles, employer data, source code and API keys.
  • Mercor attributed the breach to a compromise of the open‑source tool LiteLLM, which hosted credential‑harvesting malware for around 40 minutes.
  • Meta reportedly paused contracts with Mercor; OpenAI confirmed it is investigating potential exposure but had not paused contracts at the time of reporting.
  • At least five contractors have filed lawsuits alleging personal data exposure; one reviewed lawsuit named LiteLLM and compliance vendor Delve as defendants.

Ontology Mapping & Concepts

Primary Source Grounding & Direct Attribution
Direct Origin Attribution
Primary Reporting: techcrunch•Published: Apr 9, 2026
Original Coverage Title: “After data breach, $10B-valued startup Mercor is having a month | TechCrunch”

Related Market Signals & Shifts

Recent verified developments and strategic activity across this market segment.

Security / Supply-chain attack (LLM)Apr 1, 2026

Mercor Hit by LiteLLM Supply-Chain Cyberattack

Mercor, an AI recruiting startup, confirmed a security incident tied to a supply-chain compromise of the open-source LiteLLM project. The compromise has been linked to a hacking group called TeamPCP, and extortion group Lapsus$ has claimed it targeted Mercor and posted a sample of purportedly stolen data. Mercor said it is one of “thousands of companies” affected, has engaged third-party forensics, and is communicating with customers and contractors. LiteLLM’s maintainers removed malicious code from a package within hours; security firm Snyk reported the library is widely used and downloaded millions of times per day. Mercor — founded in 2023, a partner to OpenAI and Anthropic — was valued at $10 billion after a $350 million Series C led by Felicis Ventures in October 2025. Investigations into the scope and any data exposure remain ongoing.

Read assessment
FundraisingJul 9, 2026

Mercor in Talks for $20B Valuation

AI training startup Mercor is reportedly in early-stage talks to raise a funding round valuing the company at $20 billion, according to Bloomberg. That would double the $10 billion valuation Mercor achieved in October after a $350 million Series C. Mercor says it has received a term sheet at the new valuation and CEO Brendan Foody has posted that the company’s annualized revenue run rate (ARR) crossed $2 billion, a 100% increase in four months. Separately, Mercor announced the acquisition of Deeptune, whose team will join Mercor. The company previously faced a data breach and contractor lawsuits in early 2026. Sources and specifics remain limited as discussions are described as being at an early stage.

Read assessment
PrivacyJun 24, 2026

Meta Data Leak: Tracking Tool Exposed Personal Data

Meta faces a security incident after internal tracking software—introduced in April as the "Model Capability Initiative" to capture mouse movements, clicks and keystrokes for AI training—apparently exposed employee data company‑wide. Over 1,600 employees had previously petitioned against the tool on privacy grounds. Reporting based on an internal security notice indicates information from 45,000 tables was accessible, including full prompts and transcriptions, private conversations, and personnel and performance data. Meta told Wired it is investigating, has disabled the data-collection program pending that probe, and a company CTO acknowledged implementation fell short of privacy-review standards. The incident has deepened internal morale issues following recent layoffs and reassignments.

Read assessment

Track Real-Time Market Signals & Shifts

Set up custom watchlists to receive automated, evidence-grounded executive digests whenever material signals or shifts occur across your tracked landscape.