After data breach, $10B valued startup Mercor is having a month
A $10B-valued AI data training startup Mercor suffered a critical data breach through a compromised open-source tool (LiteLLM), exposing 4TB of sensitive data including customer trade secrets, source code, and API credentials—resulting in Meta pausing contracts indefinitely and threatening the company's reported $1B+ annualized revenue. This incident underscores how supply chain vulnerabilities in third-party open-source dependencies can cascade through enterprise systems and highlights the inadequacy of security certifications alone in preventing sophisticated attacks. IT organizations must recognize that even heavily-vetted vendors managing high-stakes AI/ML infrastructure remain vulnerable, requiring enhanced vendor risk assessment and zero-trust architecture across critical data pipelines.
