Meta suspends work with Mercor after data breach at vendor - Inspirepreneur Magazine

Meta suspends work with Mercor after data breach at vendor

Apr 4, 2026 9:02 PM IST
Category Business

Synopsis

Meta paused its collaboration with training data provider Mercor after a supply chain security breach tied to compromised code in an open‑source tool. The incident has raised industry concerns about third‑party vendor security and halted contractor work as investigations into exposed systems continue.

Meta has suspended work with Mercor after a supply chain data breach at the training data vendor, prompting industry vendors to reassess data handling and security practices.

01
Chapter one

Key Highlights

  • Meta suspended work with Mercor after a data breach at the AI training data vendor.
  • The breach stemmed from a supply chain attack linked to compromised open‑source code.
  • Mercor, valued at about $10 billion, supplies datasets to multiple major technology firms.
  • Contractors working on Meta projects through Mercor have been halted pending review.

Meta has suspended collaboration with Mercor following a data breach at the training data vendor that raised concerns about potential exposure of sensitive information used in developing advanced machine learning systems.

Multiple credible outlets, including Wired and Business Insider, report that the breach originated from a supply chain attack linked to compromised updates in the open‑source tool LiteLLM, which affected Mercor’s internal systems and other organisations globally.

Mercor, a company valued at roughly $10 billion in its most recent funding round and a supplier of training datasets to several major tech firms, confirmed the incident and said it engaged external forensic experts to contain and investigate the issue.

Meta has not publicly detailed what, if any, of its own data was accessed, but has paused all work with Mercor while the investigation continues.

02
Chapter two

Supply chain breach raises vendor security concerns

According to reporting, the breach involved malicious code inserted into an update for LiteLLM, which Mercor and others installed.

The compromised tool provided an entry point into systems that handle training data and internal documentation.

Mercor said in a statement that it is working to understand the full scope of the breach and strengthen its security practices.

Meta has suspended contractor access and paused logging hours for workers assigned through Mercor on Meta‑related tasks.

03
Chapter three

Broader impact and sector considerations

Other major AI organisations, including OpenAI, are also reviewing their relationships with Mercor to determine if any internal datasets or workflows were affected.

OpenAI clarified that customer data is not believed to be impacted, but has launched its own assessment.

The incident has attracted industry attention because third‑party vendors like Mercor play a key role in supplying annotated training data and managing human review processes that support model development.

04
Chapter four

Operational and contractor effects

According to reporting, contractors working on projects for Meta via Mercor have been unable to log hours since the pause and have been told that project assignments are under review.

Some internal leads advised teams to halt ongoing tasks while the investigation continues.

Mercor’s leadership described the company’s response as focused on containment and mitigation, and reaffirmed its commitment to improving its internal controls. Meta has not provided a public timeline for resuming work with Mercor.

05
Chapter five

FAQs

Q1. Why did Meta suspend work with Mercor?
Meta halted collaboration after a data breach at Mercor involving a supply chain attack on training data systems.

Q2. What caused the Mercor security breach?
The breach is linked to malicious updates in the open‑source tool LiteLLM that provided an entry point into vendor systems.

Q3. Are other companies affected by the breach?
Other major technology firms are reviewing their use of Mercor services to determine any impact on their data and operations.


Follow Inspirepreneur Magazine for daily global business news.

Pooja Malik
Written by Pooja Malik

Pooja Malik is a business journalist with over six years of experience covering startups, entrepreneurship, and emerging trends. She has previously worked with leading media platforms such as YourStory Media and BW BusinessWorld, where she reported on business, policy, and market developments. Currently, she serves as Editor at The Inspirepreneur Magazine, where she writes and edits stories across business, lifestyle, and travel, with a focus on clarity, accuracy, and reader relevance.