Mercor says it was hit by cyberattack tied to compromise of open-source LiteLLM project

Mercor says it was hit by cyberattack tied to compromise of open-source LiteLLM project

Mercor, an AI recruiting startup, has disclosed a significant security breach tied to a supply chain attack involving the open-source project LiteLLM. In a statement to TechCrunch, the company revealed that it was among the numerous organizations impacted by the breach associated with the hacking group TeamPCP. The news of the breach coincided with claims from the extortion hacking group Lapsus$, which asserted that they had targeted Mercor and accessed its sensitive data. However, the specifics of how Lapsus$ obtained the information remain unclear. Founded in 2023, Mercor collaborates with notable companies like OpenAI and Anthropic, employing domain experts such as scientists and medical professionals from countries like India. The startup boasts over $2 million in daily payouts and achieved a valuation of $10 billion after a $350 million Series C funding round led by Felicis Ventures in October 2025. Heidi Hagberg, a spokesperson for Mercor, emphasized that the company acted swiftly to contain the breach and is currently conducting a comprehensive investigation with the assistance of leading third-party forensic experts. "We will continue to communicate with our customers and contractors directly and allocate the necessary resources to resolve this issue promptly," she stated. Earlier, Lapsus$ claimed responsibility for the data breach on their leak site, providing a sample of data that allegedly belonged to Mercor. TechCrunch verified that the sample included references to internal Slack communications and ticketing information, as well as two videos that purportedly showcased interactions between Mercor's AI systems and its contractors. Hagberg declined to provide further details on the connection between Mercor's breach and Lapsus$, nor could she confirm if any customer or contractor data had been compromised. The LiteLLM compromise initially came to light last week when malicious code was found in a package linked to the Y Combinator-backed project. Although the harmful code was removed swiftly, the incident raised alarms due to LiteLLM's extensive use, with millions of downloads daily, according to security firm Snyk. In response to the breach, LiteLLM announced changes to its compliance processes, including a shift from the controversial startup Delve to Vanta for compliance certifications. Investigations into the full extent of the incident and its impact on affected companies are ongoing.

Sources : TechCrunch

Published On : Apr 01, 2026, 02:05

Cybersecurity
Florida Teen Withdraws Lawsuit Against Meta, Shifting Focus to Recovery

In a significant turn of events, a Florida teenager has decided to withdraw his lawsuit against Meta, just days before w...

CNN | Jul 22, 2026, 21:35
Florida Teen Withdraws Lawsuit Against Meta, Shifting Focus to Recovery
AI
U.S. Treasury Issues Stark Warning to Chinese AI Firms Amid Distillation Controversy

In a significant development, U.S. Treasury Secretary Scott Bessent reiterated his stern warnings to Chinese artificial ...

TechCrunch | Jul 22, 2026, 21:00
U.S. Treasury Issues Stark Warning to Chinese AI Firms Amid Distillation Controversy
Computing
AI Skills Outshine Experience in India's Tech Job Market

In a significant shift within India's technology job market, specialized artificial intelligence (AI) skills are increas...

Business Today | Jul 23, 2026, 04:00
AI Skills Outshine Experience in India's Tech Job Market
Startups
ServiceNow Invests $40 Million in Indian Banking Software Firm to Enhance Financial Services

ServiceNow, a prominent U.S. enterprise software provider renowned for streamlining workflows in IT and HR functions, is...

TechCrunch | Jul 23, 2026, 06:50
ServiceNow Invests $40 Million in Indian Banking Software Firm to Enhance Financial Services
AI
Allegations Fly as US Claims Chinese AI Model Breached Intellectual Property

In a bold accusation, Michael Kratsios, science and technology adviser to President Donald Trump, has charged that the C...

Business Today | Jul 23, 2026, 05:20
Allegations Fly as US Claims Chinese AI Model Breached Intellectual Property
View All News