DataBreachCaseFile.com
MonitoringWashington AG filing · June 26, 2026

Mercor.io (LiteLLM) Reports Data Breach to Washington State

Mercor.io, operating its LiteLLM platform, filed a data breach report in Washington State on June 26, 2026, indicating an incident that exposed various sensitive data types. The breach involved information potentially including full names, email addresses, and critical system credentials. Affected individuals should review their account security and monitor for unauthorized activity.

State
Washington
Reported
June 26, 2026

What may have been exposed

  • Full Name
  • Email Address
  • Password or Credential Hash
  • API Keys and Access Tokens
  • Administrative Credentials
  • Mailing Address
  • Internal System Logs
  • Payment Card Information

Mercor.io, the operator of the LiteLLM platform, officially reported a data security incident on June 26, 2026. This report was filed with the Washington Attorney General, initiating a public record of the event. The investigation into the incident is currently listed as monitoring.

As a provider of AI infrastructure and API routing, Mercor.io handles extensive corporate data, software developer credentials, and system access logs. Its services facilitate large language model integration, often requiring deep access to client networks and internal digital assets, which makes data security paramount.

The reported breach exposed several categories of sensitive information. These include Full Name, Email Address, Password or Credential Hash, API Keys and Access Tokens, Administrative Credentials, Mailing Address, Internal System Logs, and Payment Card Information. The exposure of API keys and administrative credentials can pose significant risks, potentially allowing unauthorized access to associated systems or accounts.

Given the nature of the exposed data, individuals and entities potentially affected by this incident should take immediate steps to secure their digital presence. It is highly recommended to change passwords for any Mercor.io or LiteLLM related accounts, as well as any other online accounts where similar credentials may have been used. Enabling multi-factor authentication (MFA) on all available services adds an essential layer of security.

Monitoring account activity for any unusual or unauthorized transactions or access attempts is also a critical step. Regularly reviewing financial statements and security notifications from service providers can help identify and mitigate potential risks stemming from compromised data. These general precautions are advisable for anyone who might have had their information involved in this incident.

Source: Washington Attorney General filing

More Washington data breach cases