Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.
Meta paused all work with AI-data company Mercor indefinitely in early April 2026 after Mercor disclosed a security incident linked to a compromise of the open-source LiteLLM project. The pause was reported at the time; it does not establish that Meta permanently ended the relationship or that Meta’s own systems were breached. In a June update, Mercor said its investigation was complete, the effect on customer information was very limited, and affected people were being notified.
For workers, the incident also meant interrupted Meta-related assignments and uncertainty about access to work and personal information. Here is what the public record says—and what it does not.
What happened, in brief
Mercor connects companies developing AI with human experts who help create and assess training and evaluation data. On March 31, 2026, the company confirmed a security incident affecting its systems and said thousands of organizations were affected by the broader software compromise. Mercor said its incident was tied to LiteLLM, an open-source tool used to connect applications to AI services. On April 3, WIRED reported, citing two sources, that Meta had paused all work with Mercor indefinitely.
That pause is a reported response to a vendor and software-supply-chain incident—not proof of an intrusion into Meta’s core production network. The public reporting cited here does not confirm that Meta user data, model weights, source code, credentials, or production systems were accessed.
#1 Best Overall
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
How a LiteLLM compromise could reach a vendor’s data
A software supply-chain attack targets software, its maintainers, or the process that distributes it, rather than necessarily breaking into each customer directly. In this case, reporting described malicious LiteLLM versions that could harvest credentials. An organization that installed a compromised version in a privileged environment could expose secrets; an attacker might then try to use those credentials to reach connected systems and data.
- A malicious version of LiteLLM was distributed.
- Organizations that installed it in an exposed environment could have had credentials collected.
- Those credentials could potentially provide access to other connected systems, depending on their privileges and safeguards.
- Mercor determined that it was affected during the relevant period.
TechCrunch reported that the compromised software was available for about 40 minutes. Other reporting named versions 1.82.7 and 1.82.8 and placed the compromise around March 27; treat those package specifics and timing as secondary reporting, not as a complete forensic account. Mercor’s later update described the incident as part of the LiteLLM supply-chain attack. TechCrunch’s report on Mercor and LiteLLM and Mercor’s investigation update provide the company and reporting context.
Why an AI-data vendor can hold sensitive information
Mercor is more than a conventional recruiter. It helps AI companies engage specialists to perform coding and writing tasks, review domain-specific material, judge model answers, test safety, and evaluate quality. Work can involve prompts, model outputs, task instructions, scoring rubrics, and evaluation results. Those materials may reveal how a company trains or tests a model even if no model weights are involved.
Free tools Windows power users keep installed
One-click scans. No signup required.
A vendor may also hold worker records, such as profiles and identity or employment information. That creates two distinct categories of potential harm: exposure of people’s personal information and exposure of a customer’s confidential project information. They should not be conflated, and the public record does not establish that every category was accessed.
Rank #2
- POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
What was exposed—and what remains unproven
Mercor’s account
In its June 25, 2026 update, Mercor said only a very limited subset of its nearly five million experts had sensitive information affected. It said there was no evidence that the information had been used fraudulently and that affected individuals were being notified directly on June 25 and 26. These are Mercor’s findings and statements; they are not an independently published forensic report establishing the full scope of every customer’s exposure.
Attacker claims and media reports
A group using the Lapsus$ name claimed to have stolen Mercor data. Reports described claims involving candidate profiles, personally identifiable information, employer data, source code, API keys, and very large volumes of files. Some accounts repeated figures such as a database exceeding 200 GB, nearly 1 TB of source code, roughly 3 TB of video and other information, or about 4 TB in total.
Those figures and categories should be read as claims attributed to attackers or reporting about those claims—not verified amounts of data stolen. The identity of the actor was also uncertain: reporting linked the LiteLLM compromise to TeamPCP or an affiliated actor, while researchers cautioned that the Lapsus$ attribution was unverified.
Do these 3 things before closing this tab:
1Repair Windows errors before they cause bigger problems2Scan for outdated or missing drivers - takes under a minute3Clear out junk files and repair common Windows errorsQuestions the public record does not settle
- Whether any Meta-owned datasets were accessed.
- Whether Meta credentials, model weights, source code, or production systems were involved.
- Whether proprietary training methods were actually exfiltrated.
- Whether alleged leaked samples were complete and authentic, or how much of any data was usable.
- Whether a reported data volume included duplicates, encrypted files, or information unrelated to customer projects.
Do not infer that Meta’s user data was compromised from the fact that it paused a vendor relationship. Equally, the absence of public confirmation about model weights would not rule out strategic exposure: task instructions, prompts, rubrics, and evaluation outcomes can also be sensitive.
Rank #3
- POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
Why Meta paused the work—and what is known about other labs
WIRED reported that Meta paused all its work with Mercor indefinitely in April. Contractors assigned to Meta projects reportedly could not log hours while the projects were paused, and a Meta-related initiative called Chordus was reassessing its scope. The reporting does not establish a permanent contract termination. A halt can be a containment step while a customer checks access, data flows, credentials, project integrity, subcontractors, and contractual notification obligations; those are reasonable areas for review, not a publicly itemized list of actions Meta confirmed taking.
OpenAI said it was investigating its exposure but had not halted its current Mercor projects, and said the incident did not affect OpenAI user data. That statement should not be stretched into a claim that every kind of OpenAI proprietary information was definitively outside the incident. Anthropic’s position was not publicly confirmed in the cited coverage. WIRED reported that other major AI labs were reevaluating their relationships.
By June, Mercor said all frontier labs had increased their work with it in the preceding months. That is Mercor’s own characterization, not a detailed, separate public confirmation from each client. It also means the April headline describes a historical pause; it should not be read as confirmation that the work remained halted in August 2026. WIRED’s April report and Mercor’s June update document the two stages.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Timeline
| Date | What was reported |
|---|---|
| March 27, 2026 | Secondary reporting placed the LiteLLM compromise around this date. Package and timing details should be attributed to that reporting. |
| March 31, 2026 | Mercor confirmed a security incident affecting its systems in the context of a wider compromise. WIRED |
| April 1, 2026 | TechCrunch reported Mercor’s confirmation that it was affected by the LiteLLM supply-chain attack; claims using the Lapsus$ name also circulated. TechCrunch |
| April 3, 2026 | WIRED reported that Meta had paused all work with Mercor indefinitely. WIRED |
| April 9, 2026 | TechCrunch reported further fallout, including attacker data-theft claims and contractor lawsuits. TechCrunch |
| June 25–26, 2026 | Mercor said its investigation was complete, described customer impact as very limited, and said it was notifying affected experts. Mercor |
What the incident meant for contractors
The reported pause had a practical effect beyond corporate risk: contractors assigned to Meta work reportedly could not log hours while projects were on hold. Mercor was trying to identify other projects for affected workers, according to WIRED. That does not mean every contractor lost work or that every worker’s information was exposed.
Rank #4
- POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Workers concerned about their own records should rely on direct notices rather than broad online claims. Check the notice’s description of the information involved, the relevant dates, any identity-protection offer, and the steps for contacting the company. Mercor said affected experts would be notified and offered TransUnion identity-protection services. The offer is relevant to personal-information concerns; it does not address exposure of a customer’s project data.
Mercor’s stated response
Mercor said it worked with Mandiant, Latacora, industry peers, and law enforcement. It also said it audited third-party dependencies; rotated credentials and access keys across cloud platforms, GitHub, and SaaS systems; tightened cloud and network controls; began open-box penetration testing by independent researchers; and implemented 24/7 managed detection and response. The company said it was notifying affected experts and offering identity-protection services.
These are measures Mercor said it took or began. They are not a guarantee against recurrence, nor does the public update establish that every measure was independently audited. Read Mercor’s full investigation update.
What AI companies can learn from the breach
The central lesson is not simply to choose a different workforce vendor. An open-source dependency can become a route to credentials, while a data-services provider can concentrate customer workflows and worker records in one environment. Replacing one provider without changing access controls may only move the same risk.
- Control dependencies: Maintain software inventories and lockfiles, verify package provenance and signatures where available, and test updates in isolated build environments before using them with privileged access.
- Limit credential exposure: Use short-lived tokens, phishing-resistant multifactor authentication, least privilege, centralized secrets management, and a tested process for quickly revoking and rotating credentials.
- Separate customers and data types: Isolate projects, avoid unnecessary mixing of customer work and worker records, and minimize identity information retained by vendors.
- Monitor access: Keep useful audit logs, detect unusual downloads, and define retention periods and access-review schedules.
- Know the subcontractors: Require disclosure and approval of relevant cloud, identity-verification, payment, analytics, and recruiting providers.
- Make incident duties concrete: Contracts should cover notification timing, forensic cooperation, evidence preservation, audit rights, and customer-specific impact reporting.
- Plan for a pause: Identify fallback workflows and a process for validating work produced during a suspected exposure window before it is used or retained.
There are real trade-offs. External experts can give AI teams specialized capacity quickly, but add vendors, software dependencies, and access paths. Richer task context can improve annotation and evaluation quality while revealing more about model-development strategy. Customer-controlled environments may reduce vendor-side exposure but can add integration and administration work. The useful procurement question is not only whether a vendor has a security certification, but how projects are isolated, credentials are controlled, and the customer can verify what happened during an incident.
What affected workers can do
- Look for a direct notification from Mercor and confirm it through an independently obtained company contact channel if a message seems suspicious.
- Read the notice carefully to learn which information was involved and whether the TransUnion offer applies to you.
- Use unique passwords and multifactor authentication for accounts that may share credentials with work systems; never provide passwords or verification codes in response to an unsolicited message.
- Watch financial and identity accounts for unusual activity if the notice says sensitive identity or financial information was affected. Follow the notice’s specific guidance and applicable local reporting options.
- Ask the company or relevant project contact how the pause affects assignment status, time reporting, and payment. The available reporting does not specify a universal payment outcome for contractors.
Mercor’s notification and identity-protection statements concern its identified affected experts; they do not establish that every contractor needs the same response. The right steps depend on what information a person’s notice says was involved and where they live.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.
The Tool Desk
Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →

