Mercor, a $10 billion AI training-data and recruiting startup whose customers include OpenAI, Anthropic, and Meta, was breached after attackers compromised the open-source LiteLLM library in a supply-chain attack that hit multiple companies across the AI industry. An extortion group claimed to have obtained up to 4 terabytes of Mercor data, including source code, database records, internal Slack and ticketing information, API keys, and recordings of AI system conversations. Samples of the stolen data were published on a leak site as part of the extortion attempt.