After data breach, $10B-valued startup Mercor is having a month
Just half a year after securing a major $350 million funding round that elevated its valuation to $10 billion, AI data training company Mercor is grappling with the fallout from a serious data breach. The company recently disclosed that it was compromised through a popular open-source tool, LiteLLM, which briefly contained malware capable of harvesting credentials. This breach has reportedly led to hackers claiming possession of 4TB of stolen data, including sensitive information such as candidate profiles, employer data, and source code.
Major Repercussions for Mercor
While Mercor is still investigating the scope of the breach and has not verified the data leak claims, consequences have been swift. Sources indicate that Meta has indefinitely paused its contracts with Mercor, reflecting growing concerns across the industry regarding the leaked proprietary datasets and AI training methods handled by the company. Although OpenAI continues its partnership as of now, other large AI model developers are said to be reassessing their ties following the incident.
Lawsuits and Industry Backlash
Alongside customer fallout, several of Mercor's contractors have filed lawsuits, alleging exposure of their personal information. Notably, legal action has extended to third-party vendors involved in the chain of events, including the LiteLLM tool and the compliance startup Delve. Delve faced controversy over its security certifications, and recent allegations have led to both Y Combinator distancing itself and LiteLLM switching compliance providers.
Uncertain Financial Future
Prior to the data leak, Mercor was reportedly on track for over $1 billion in annualized revenue. Now, the financial impact of lost contracts and ongoing litigation could be significant if customer confidence continues to erode.
For further details, read the original article by Julie Bort on TechCrunch.