DataBreachSearch.com

Did Mercor.io (LiteLLM) have a data breach?

Answer

Yes. Mercor.io (LiteLLM) reported a data breach to the Washington Attorney General on June 26, 2026.

View the official filing

What the filing says

Reported to
Washington Attorney General
Filing date
June 26, 2026
Breach date
Not stated in the filing
People affected
Not stated in the filing

Information involved

  • Full Name
  • Email Address
  • Password or Credential Hash
  • API Keys and Access Tokens
  • Administrative Credentials
  • Mailing Address
  • Internal System Logs
  • Payment Card Information

In plain terms

Mercor.io, which operates LiteLLM infrastructure, officially reported a data breach to the Washington Attorney General on June 26, 2026. This incident involved the exposure of various sensitive data types, including full names, email addresses, and payment information. Individuals affected should review their notification and take recommended security steps.

Mercor.io, known for its LiteLLM platform, formally notified the Washington Attorney General's office of a data breach on June 26, 2026. The company's public filing acknowledges a security incident without specifying the exact breach date.

According to the official report, the exposed information includes individuals' Full Name, Email Address, Password or Credential Hash, API Keys and Access Tokens, Administrative Credentials, Mailing Address, Internal System Logs, and Payment Card Information. These details are derived directly from the filing made with state regulators.

The compromise of data types such as API keys and administrative credentials can pose significant risks. Malicious actors could potentially exploit these to gain unauthorized access to other systems, compromise linked accounts, or infiltrate integrated client environments.

Individuals who receive a notification regarding this breach should immediately review the contents of their notice from Mercor.io. It is recommended to change any passwords or API keys that may have been exposed, especially if they are reused across multiple services.

Enabling multi-factor authentication (MFA) on all online accounts wherever possible is a strong protective measure. Additionally, monitoring account statements and being alert for any suspicious activity is advisable to help mitigate potential risks associated with data exposures.

Commonly recommended next steps

  • Watch your financial accounts

    Review bank and card statements for unfamiliar activity and turn on transaction alerts. Report anything you don't recognize to your bank right away.

  • Secure your online accounts

    Change the password on any account that reused an exposed password and turn on two-factor authentication wherever it's offered.

  • Stay alert to targeted scams

    Be cautious of calls, texts, or emails that reference this breach. Legitimate organizations won't ask you to confirm sensitive details through an unsolicited message.

  • Keep your notification letter

    Save the notice you received. It documents that your information was involved and is often needed to enroll in any credit monitoring offered or to join a related legal claim.

Look up another company

Other breaches reported in Washington

DataBreachSearch.com reports what was filed with state regulators. It is not legal advice, is not a law firm, and is not affiliated with any government agency or with Mercor.io (LiteLLM).