
Mercor, an AI recruiting startup, has disclosed a significant security breach tied to a supply chain attack involving the open-source project LiteLLM. In a statement to TechCrunch, the company revealed that it was among the numerous organizations impacted by the breach associated with the hacking group TeamPCP. The news of the breach coincided with claims from the extortion hacking group Lapsus$, which asserted that they had targeted Mercor and accessed its sensitive data. However, the specifics of how Lapsus$ obtained the information remain unclear. Founded in 2023, Mercor collaborates with notable companies like OpenAI and Anthropic, employing domain experts such as scientists and medical professionals from countries like India. The startup boasts over $2 million in daily payouts and achieved a valuation of $10 billion after a $350 million Series C funding round led by Felicis Ventures in October 2025. Heidi Hagberg, a spokesperson for Mercor, emphasized that the company acted swiftly to contain the breach and is currently conducting a comprehensive investigation with the assistance of leading third-party forensic experts. "We will continue to communicate with our customers and contractors directly and allocate the necessary resources to resolve this issue promptly," she stated. Earlier, Lapsus$ claimed responsibility for the data breach on their leak site, providing a sample of data that allegedly belonged to Mercor. TechCrunch verified that the sample included references to internal Slack communications and ticketing information, as well as two videos that purportedly showcased interactions between Mercor's AI systems and its contractors. Hagberg declined to provide further details on the connection between Mercor's breach and Lapsus$, nor could she confirm if any customer or contractor data had been compromised. The LiteLLM compromise initially came to light last week when malicious code was found in a package linked to the Y Combinator-backed project. Although the harmful code was removed swiftly, the incident raised alarms due to LiteLLM's extensive use, with millions of downloads daily, according to security firm Snyk. In response to the breach, LiteLLM announced changes to its compliance processes, including a shift from the controversial startup Delve to Vanta for compliance certifications. Investigations into the full extent of the incident and its impact on affected companies are ongoing.
In a significant turn of events, a Florida teenager has decided to withdraw his lawsuit against Meta, just days before w...
CNN | Jul 22, 2026, 21:35
In a significant development, U.S. Treasury Secretary Scott Bessent reiterated his stern warnings to Chinese artificial ...
TechCrunch | Jul 22, 2026, 21:00
In a significant shift within India's technology job market, specialized artificial intelligence (AI) skills are increas...
Business Today | Jul 23, 2026, 04:00
ServiceNow, a prominent U.S. enterprise software provider renowned for streamlining workflows in IT and HR functions, is...
TechCrunch | Jul 23, 2026, 06:50
In a bold accusation, Michael Kratsios, science and technology adviser to President Donald Trump, has charged that the C...
Business Today | Jul 23, 2026, 05:20