Supply Chain Attack on LiteLLM Exposes AI Data, Disrupts Industry Partnerships

Thumbnail Image

The information displayed in the AIM should not be reported as representing the official views of the OECD or of its member countries.

A supply chain attack on the open-source AI tool LiteLLM compromised Mercor, an AI recruiting startup, exposing sensitive customer data and AI training information. The breach, claimed by Lapsus$, affected thousands of firms, led Meta to halt collaboration with Mercor, and raised concerns over AI data security and national security risks.[AI generated]

Why's our monitor labelling this an incident or hazard?

Both incidents involve AI systems and their development/use. The Mercor supply chain attack directly led to exposure of sensitive customer data and AI training data, constituting harm to property and potentially national security (harm to communities). The Anthropic leak, while not a hack, exposed source code that could enable future attacks on the AI system, representing realized harm through data exposure and potential future harm. Therefore, these are AI Incidents as the harms have materialized and the AI systems are central to the events.[AI generated]
AI principles
Privacy & data governanceRobustness & digital security

Industries
Digital securityBusiness processes and support services

Affected stakeholders
Business

Harm types
Economic/PropertyReputationalHuman or fundamental rights

Business function:
Human resource management

AI system task:
Organisation/recommenders


Articles about this incident or hazard