DataBreachSearch.com
MonitoringWashington AG filing · June 26, 2026

Mercor.io (LiteLLM) Reports Data Breach to Washington Officials

Mercor.io, which operates LiteLLM infrastructure, officially reported a data breach to the Washington Attorney General on June 26, 2026. This incident involved the exposure of various sensitive data types, including full names, email addresses, and payment information. Individuals affected should review their notification and take recommended security steps.

State
Washington
Reported
June 26, 2026

What may have been exposed

  • Full Name
  • Email Address
  • Password or Credential Hash
  • API Keys and Access Tokens
  • Administrative Credentials
  • Mailing Address
  • Internal System Logs
  • Payment Card Information

Mercor.io, known for its LiteLLM platform, formally notified the Washington Attorney General's office of a data breach on June 26, 2026. The company's public filing acknowledges a security incident without specifying the exact breach date.

According to the official report, the exposed information includes individuals' Full Name, Email Address, Password or Credential Hash, API Keys and Access Tokens, Administrative Credentials, Mailing Address, Internal System Logs, and Payment Card Information. These details are derived directly from the filing made with state regulators.

The compromise of data types such as API keys and administrative credentials can pose significant risks. Malicious actors could potentially exploit these to gain unauthorized access to other systems, compromise linked accounts, or infiltrate integrated client environments.

Individuals who receive a notification regarding this breach should immediately review the contents of their notice from Mercor.io. It is recommended to change any passwords or API keys that may have been exposed, especially if they are reused across multiple services.

Enabling multi-factor authentication (MFA) on all online accounts wherever possible is a strong protective measure. Additionally, monitoring account statements and being alert for any suspicious activity is advisable to help mitigate potential risks associated with data exposures.

Source: Washington Attorney General filing

More Washington data breach cases