Mercor.io (LiteLLM) Reports Data Breach to Washington AG
Mercor.io, operating the LiteLLM platform, filed a data breach notification with the Washington Attorney General on June 26, 2026. This incident exposed various sensitive data types, including names, email addresses, and API keys. Individuals affected should review the notification and take recommended security measures.
- State
- Washington
- Reported
- June 26, 2026
What may have been exposed
- Full Name
- Email Address
- Password or Credential Hash
- API Keys and Access Tokens
- Administrative Credentials
- Mailing Address
- Internal System Logs
- Payment Card Information
Mercor.io, which operates the LiteLLM platform, filed a data breach notification with the Washington Attorney General on June 26, 2026. The filing indicates a security incident occurred, though the specific nature of the breach remains unspecified in the public record.
The incident involved the exposure of several categories of sensitive information. Data reported as compromised includes Full Names, Email Addresses, Password or Credential Hashes, API Keys and Access Tokens, Administrative Credentials, Mailing Addresses, Internal System Logs, and Payment Card Information.
Mercor.io and its LiteLLM platform are involved in AI development, software deployment, and enterprise data processing. Given its role in facilitating large language model integration and API routing, the platform handles significant volumes of digital assets. The exposure of data like API Keys and Administrative Credentials can pose significant risks due to the interconnected nature of modern software systems.
The compromise of API Keys and Access Tokens can enable unauthorized access to integrated systems, while exposed Password or Credential Hashes could potentially be used in credential stuffing attacks. Administrative Credentials provide access to core systems. This type of exposure necessitates vigilance from affected individuals and entities.
Individuals who receive a breach notification from Mercor.io should immediately change passwords for any affected accounts, especially if those passwords are reused on other platforms. Enable multi-factor authentication (MFA) wherever possible to add an extra layer of security to online accounts.
It is also advisable to remain alert for any unsolicited communications or phishing attempts that may leverage exposed email addresses. Regularly monitor all account statements for unusual activity and consider placing fraud alerts with credit bureaus.
Source: Attorney General filing