來源Wired AI•較早收集於 33m
Meta 暫停與 Mercor 合作因資料外洩

#data-breach#ai-security#training-datamercormetamercor
Meta 因外洩暫停 Mercor,危及 AI 訓練機密—立即審核供應商!
30 秒速覽
有什麼變化
Meta 因資料外洩暫停與 Mercor 合作
為什麼重要
此事件凸顯 AI 資料供應鏈風險,促使 AI 公司重新評估供應商安全。可能引發產業廣泛審查及資料合作轉移,延緩部分 AI 開發時程。
下一步行動
立即審核如 Mercor 等 AI 資料供應商的安全態勢。
誰應關注:Researchers & Academics
關鍵要點
- •Meta 因資料外洩暫停與 Mercor 合作
- •主要 AI 實驗室調查安全事件
- •外洩風險暴露 AI 模型訓練機密
- •Mercor 是領先 AI 資料供應商
深度解析
背景與延伸:來自公開資料,非原文內容。引用 8 個來源。
增強重點摘要
- •The breach originated from a supply chain attack on the open-source LiteLLM library, where threat actor TeamPCP injected a malicious backdoor into versions 1.82.7 and 1.82.8 to harvest credentials.
- •The hacking group Lapsus$ has claimed responsibility for exfiltrating 4TB of Mercor data, including source code, internal databases, Slack communications, and sensitive KYC/identity verification documents.
- •Mercor, a $10 billion valuation startup, serves as a critical infrastructure provider for AI labs by managing a network of over 30,000 expert contractors used for model evaluation and training.
技術深入
- •Attack Vector: Supply chain compromise of the LiteLLM Python library via unauthorized PyPI package publishing.
- •Malware Mechanism: Three-stage malicious backdoor designed for credential harvesting and establishing persistent system access.
- •Exfiltrated Data: Allegedly includes 939GB of source code, a 211GB user database, and 3TB of storage buckets containing video interviews and identity verification passports.
- •Infrastructure Impact: Attackers reportedly leveraged access to the company's Tailscale VPN to facilitate the large-scale data exfiltration.
前景展望基於引用來源的 AI 分析
AI labs will mandate stricter third-party library auditing.
The widespread impact of the LiteLLM supply chain attack highlights critical vulnerabilities in the AI development pipeline, forcing companies to move away from implicit trust in open-source dependencies.
Mercor faces significant long-term attrition of its expert contractor base.
The exposure of sensitive KYC and identity verification documents creates severe privacy risks for contractors, likely damaging trust in the platform's ability to protect personal data.
時間線
2023-01
Mercor is founded by Brendan Foody, Adarsh Hiremath, and Surya Midha.
2025-10
Mercor raises a $350 million Series C funding round, reaching a $10 billion valuation.
2026-03
TeamPCP compromises LiteLLM PyPI credentials, injecting malicious code into versions 1.82.7 and 1.82.8.
2026-03
Mercor detects anomalous system activity on March 30-31, 2026.
2026-04
Mercor publicly confirms the security incident and initiates a third-party forensic investigation.
- 2023-01Mercor is founded by Brendan Foody, Adarsh Hiremath, and Surya Midha.
- 2025-10Mercor raises a $350 million Series C funding round, reaching a $10 billion valuation.
- 2026-03TeamPCP compromises LiteLLM PyPI credentials, injecting malicious code into versions 1.82.7 and 1.82.8.
- 2026-03Mercor detects anomalous system activity on March 30-31, 2026.
- 2026-04Mercor publicly confirms the security incident and initiates a third-party forensic investigation.
來源 (8)
Factual claims are grounded in the sources below. Forward-looking analysis is AI-generated interpretation.
1Google Search Sourcevertexaisearch.cloud.google.com2Google Search Sourcevertexaisearch.cloud.google.com3Google Search Sourcevertexaisearch.cloud.google.com4Google Search Sourcevertexaisearch.cloud.google.com5Google Search Sourcevertexaisearch.cloud.google.com6Google Search Sourcevertexaisearch.cloud.google.com7Google Search Sourcevertexaisearch.cloud.google.com8Google Search Sourcevertexaisearch.cloud.google.com
AI 週報
閱讀本週精選 AI 大事摘要 →
AI 策展新聞聚合。所有內容版權歸原始發布者所有。
原始來源: Wired AI ↗
每週電子報
每週一封,可隨時退訂。