AI data firm Mercor has confirmed a significant data breach affecting its clients, including OpenAI and Anthropic. The breach resulted from a supply chain attack on the open-source library LiteLLM, exploited by hacker group TeamPCP to steal credentials. Subsequently, hacker group Lapsus$ claimed to have accessed up to 4TB of Mercor's data, including source code and internal communications. Mercor has responded by implementing containment measures and launching a third-party forensic investigation. Unverified reports indicate potential exposure of client datasets and confidential AI project information. The breach highlights vulnerabilities in widely-used open-source libraries like LiteLLM, which receives millions of downloads daily.