Meta pauses Mercor AI work after security breach

Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- Meta paused all work with data‑contractor Mercor indefinitely while investigating a major security breach that impacted Mercor.
- Mercor confirmed the security incident in an email to staff on March 31, saying it affected its systems and thousands of other organizations worldwide.
- OpenAI said it continues current projects with Mercor but is probing whether proprietary training data was exposed, and clarified the breach does not affect OpenAI user data.
- Mercor contractors assigned to Meta projects cannot log hours until the project resumes, leaving them potentially out of work; Mercor is seeking additional projects for them.
- TeamPCP is identified as the attacker who compromised two versions of the AI API tool LiteLLM, linking the breach to Mercor and potentially exposing data of thousands of victims.
- Lapsus$ claimed responsibility for the Mercor breach and offered to sell large amounts of alleged data, but researchers note the attacker is likely TeamPCP or an associated actor.
- Chordus initiative, a Meta‑specific AI project, was described in a Slack channel as “currently reassessing the project scope” after the breach.
Why it matters: Meta loses immediate access to Mercor‑generated training data, slowing its AI development and forcing the company to seek alternative data sources. Contractors assigned to Meta projects are left unable to log hours, risking periods of unpaid work. Meanwhile, OpenAI, Anthropic and other labs must audit their own data pipelines for similar breaches, heightening industry‑wide security scrutiny.




