As first reported by Wired on Friday, Meta has paused all work with AI data startup Mercor following a confirmed security breach linked to a supply chain attack involving the LiteLLM open-source project, which impacted thousands of organizations globally.
Mercor, which provides proprietary training data to major AI companies including Meta, OpenAI, and Anthropic, said it was among those affected and has launched an investigation with third-party forensic experts.
The breach raised concerns about potential exposure of sensitive AI training data and internal datasets, which are used to develop and fine-tune large language models. Reports indicate that Mercor’s systems were impacted as part of a broader compromise involving malicious updates to widely used AI tooling, though it remains unclear what specific data was accessed.
Michael Bell, Founder & CEO, Suzu Labs had this comment:
“The Mercor breach is what happens when the companies building the most valuable AI models in the world outsource the creation of their training data to vendors running on Airtable and shared passwords. A single poisoned open-source package gave attackers VPN credentials, and from there they walked through Mercor’s systems and took 4TB of proprietary datasets, source code, and contractor PII.
“We’ve been investigating these AI data vendors for months and found the same structural failures at Sama, Teleperformance, Scale AI, and Cognizant we see unrotated credentials, info-stealer infections on contractor endpoints, and access controls that don’t exist. The training data behind every major frontier model is sitting inside vendors that wouldn’t pass a basic security audit, and now that data is on an extortion site. This is a national security problem dressed up as a vendor management failure.”
Lydia Zhang, President & Co-Founder,Ridge Security Technology Inc. adds this comment:
“This incident alerts us that AI training data should be treated as critical infrastructure, subject to stricter security scrutiny and regulation.
“The breach also underscores the risks of relying directly on open-source projects in enterprise environments. Supply chain attacks, like the compromised LiteLLM library in this case, can introduce vulnerabilities at scale and expose highly sensitive data.
“At a minimum, enterprises should adopt thoroughly tested and commercially supported versions of such components, with stronger security guarantees and accountability.”
Noelle Murata, Sr. Security Engineer, Xcape, Inc. provided this comment:
“Meta’s indefinite suspension of its partnership with Mercor underscores how the AI industry’s rush to outsource training data has effectively liquidated billions in proprietary methodology. By allowing a poisoned version of the LiteLLM gateway (versions 1.82.7 and 1.82.8) to persist in their environment, Mercor gifted attackers 4 TB of data, including the precise “secret sauce” protocols Meta and OpenAI use to tune their models.
“This was not a sophisticated zero-day; it was a basic supply chain failure where a compromised security scanner (Trivy) was used to poison a niche dependency that nobody bothered to pin. For anyone surprised that an autonomous, interconnected AI stack would eventually expose sensitive data to the internet, the lesson is clear.
“If you are not auditing your data vendors for basic dependency hygiene, your IP is already public property. Defenders must immediately scan for litellm_init.pth files, which provide stealthy persistence on every Python startup, and rotate all LLM provider API keys and cloud tokens. Protecting training integrity now requires treating every AI data broker as a high-risk production endpoint and enforcing strict, pinned Software Bill of Materials (SBOM) standards.
“If your AI supply chain is this leaky, you are not training a model; you are just broadcasting a technical manual to Lapsus$.”
Supply chain vulnerabilities are real. If your organization doesn’t take them seriously, your organization will get pwned. It’s as simple as that. And you can double that if AI is involved.
ShinyHunters hackers claim to have hit data center provider used by Microsoft and Meta
Posted in Commentary with tags Facebook, Microsoft on August 27, 2026 by itnerdThe infamous ShinyHunters ransomware crew has added CyrusOne, a major US data center operator, to its list of victims, claiming to have stolen a treasure trove of highly sensitive data which, if proven true, could turn this into a bonafide catastrophe for the company and its customers. CyrusOne is used by Miscrosoft and Meta both.
Rebecca Moody, Head of Data Research at Comparitech:
“It’s important to distinguish between ransomware attacks and data theft with a ransom demand. ShinyHunters isn’t a traditional ransomware group, rather, it’s an extortion group that seeks to steal vast quantities of data before demanding a ransom to delete it. It doesn’t tend to use ransomware to encrypt systems.
Regardless of the type of attack on CyrusOne, it serves as a reminder that cybercriminals are continuing to seek out companies with huge datasets. Technology companies like CyrusOne are a prime example as they’ll often deal with multiple companies. Therefore, by targeting one company, hackers can access the data of multiple organizations. As well as giving them access to more data, it also gives hackers more negotiating power. Not only will the organizations be pressured into resolving the attack as quickly as possible by their clients but hackers may even start contacting the organization’s clients individually, issuing them with a ransom demand, too.”
Brian Higgins, Security Specialist at Comparitech:
“This attack is one to watch. The nature and volume of data stolen simply cannot be mitigated with backups and patches. What happens in the next couple of days could seriously set the agenda for high stakes ransomware challenges as we move into the data centre era. ShinyHunter’s frustration at the lack of engagement is clearly exposed but what that means for any next steps is anyone’s guess at this stage. If CyrusOne have a trick or two up their sleeve it will be fascinating to see them played. Otherwise the potential fallout could be catastrophic. It’s a high profile game of Cyber-chicken and if it weren’t so devastating for the tech sector it would probably make a good movie.”
This is a #fail as it gives ShinyHunters keys to the kingdom so to speak. Everyone needs to take note now and take the appropriate steps to mitigate what appears to be a substantial threat.
Leave a comment »