8 Sources
[1]
Mercor says it was hit by cyberattack tied to compromise of open-source LiteLLM project | TechCrunch
Mercor, a popular AI recruiting startup, has confirmed a security incident linked to a supply chain attack involving the open-source project LiteLLM. The AI startup told TechCrunch on Tuesday that it was "one of thousands of companies" affected by a recent compromise of LiteLLM's project, which
[2]
Meta Pauses Work With Mercor After Data Breach Puts AI Industry Secrets at Risk
Meta has paused all its work with the data contracting firm Mercor while it investigates a major security breach that impacted the startup, two sources confirmed to WIRED. The pause is indefinite, the sources said. Other major AI labs are also reevaluating their work with Mercor as they assess the
[3]
Mercor says it was 'one of thousands' hit in LiteLLM attack
AI hiring startup Mercor confirmed it was "one of thousands of companies" affected by the LiteLLM supply-chain attack as the fallout from the Trivy compromise continues to spread. "We recently identified that we were one of thousands of companies impacted by a supply chain attack involving
[4]
Meta freezes AI data work after breach puts training secrets at risk
In short: Meta has suspended its collaboration with Mercor, a $10 billion AI data startup, after a supply chain attack exposed what may be the AI industry's most closely guarded secrets: not just personal data, but the training methodologies that power the world's leading large language models. The
[5]
Mercor, a $10 billion AI startup, confirms it was caught up in a major security incident | Fortune
Mercor, a startup that provides training data to major AI companies, confirmed that it was the victim of a security breach that may have exposed sensitive company and user data. The three-year old startup, which is valued at $10 billion, recruits experts in fields ranging from medicine to law to
[6]
Meta Said to Pause Work With Mercor Following Data Breach Incident
The incident reportedly involved the open-source project LiteLLM Meta has reportedly paused all work with artificial intelligence (AI) recruitment company Mercor after the company was hit by a cyberattack last week. As per the report, the Menlo Park-based tech giant was among the biggest clients
[7]
AI recruiting startup Mercor hit by cyberattack; Meta halts collaboration
As per media reports, Mercor was among thousands of firms affected by the compromise of LiteLLM. Even as Mercor has claimed that the malicious code was detected and removed, the breach drew attention because LiteLLM is widely used. LiteLLM has since strengthened its compliance measures, switching
[8]
Meta Halts Work With Mercor After Major Breach, While ChatGPT-Parent OpenAI Investigates Incident: Report
Meta Platforms, Inc. (NASDAQ:META) has reportedly paused its work with data contractor Mercor following a major security breach. Meta Freezes Mercor Work Amid Security Concerns The suspension is indefinite, with sources indicating other AI labs are also reevaluating ties with Mercor, Wired
Share
Copy Link
The $10 billion AI recruiting startup Mercor has confirmed it was compromised through a supply chain attack targeting the open-source LiteLLM library. Meta has indefinitely paused all work with the company, while OpenAI and Anthropic investigate potential exposure of their proprietary AI training methodologies. The breach, linked to hacking group TeamPCP and later claimed by Lapsus$, may have exposed up to four terabytes of sensitive data including training protocols that AI labs have spent billions developing.
Mercor, the $10 billion AI recruiting startup, has confirmed it was "one of thousands of companies" affected by a security breach tied to a supply chain attack on the open-source library LiteLLM
1
. The company, which generates AI training data for major tech firms including Meta, OpenAI, and Anthropic, disclosed the incident on March 31 after extortion hacking group Lapsus$ claimed responsibility for stealing approximately four terabytes of data from the startup2
. Mercor spokesperson Heidi Hagberg stated the company had "moved promptly" to contain and remediate the security incident, with a thorough forensics investigation now underway supported by third-party experts5
.
Source: TechCrunch
Founded in 2023 by three former high school debate teammates, Mercor facilitates more than $2 million in daily payouts and reached $500 million in annualized revenue by September 2025, up from $100 million just six months earlier
4
. The company closed a $350 million Series C round led by Felicis Ventures in October 2025, valuing it at $10 billion and making its founders the world's youngest self-made billionaires at age 221
.The breach originated from a sophisticated attack by hacking group TeamPCP, which compromised the CI/CD pipeline of LiteLLM, a Y Combinator-backed open-source library downloaded millions of times per day according to security firm Snyk
1
. On March 27, 2026, TeamPCP published two malicious versions of the LiteLLM package—1.82.7 and 1.82.8—directly to PyPI, the Python package repository4
. The tainted packages remained available for approximately 40 minutes before being identified and removed.
Source: The Register
The payload was designed to harvest environment variables, API keys, SSH keys, cloud credentials across AWS, Google Cloud, and Azure, Kubernetes configurations, CI/CD secrets, and database credentials
4
. TeamPCP had previously compromised Trivy, a widely used vulnerability scanner, to obtain credentials belonging to a LiteLLM maintainer, which they then used to execute the attack4
. This represents part of a larger supply chain hacking spree by TeamPCP that has gained momentum in recent months, with the group also targeting Checkmarx's KICS tool and reportedly breaching Cisco's internal development environment3
.Meta has indefinitely paused all work with Mercor while investigating the breach, two sources confirmed to WIRED
2
. Contractors staffed on Meta projects, including the Chordus initiative designed to teach AI models to use multiple internet sources to verify responses, cannot log hours until the project resumes, effectively leaving them without work2
. OpenAI confirmed it is investigating how its proprietary AI training methodologies may have been exposed, though the company stated the incident does not affect OpenAI user data2
.What makes this breach particularly alarming for AI labs is not just the personal data exposure affecting more than 40,000 contractors and customers, but the potential compromise of proprietary training protocols
4
. Because Mercor sits inside the data pipelines of multiple AI companies simultaneously, the breach may have exposed details about data selection criteria, labeling protocols, and training strategies that companies have spent billions developing. These AI industry secrets represent genuine competitive advantages that labs like Meta, OpenAI, and Anthropic have worked to keep confidential, as they reveal key details about how they train models powering products like ChatGPT and Claude2
.Related Stories
Lapsus$ claimed on its leak site to have obtained four terabytes of data, including 939 gigabytes of source code, a 211-gigabyte user database, and approximately three terabytes of video interview recordings and identity verification documents
4
. The group shared samples allegedly taken from Mercor that included Slack data, ticketing information, and two videos purportedly showing conversations between Mercor's AI systems and contractors on its platform1
. However, security researchers note that many cybercriminal groups now periodically adopt the Lapsus$ name, and Mercor's confirmation of the LiteLLM connection suggests the actual attacker is likely TeamPCP or an actor connected to that group2
.
Source: Fortune
According to Allan Liska, an analyst at security firm Recorded Future who specializes in ransomware, "TeamPCP is definitely financially motivated. There might be some geopolitical stuff as well, but it's hard to determine what's real and what's bluster, especially with a group this new"
2
. Wiz researchers indicated they "saw indications in Cloud, Code, and Runtime evidence that the credentials and secrets stolen in the supply chain compromises were quickly validated and used to explore victim environments and exfiltrate additional data"3
.Mercor may be merely the first downstream company to publicly confirm victimization, but it won't be the last
3
. Threat hunters at vx-underground estimate the data thieves have exfiltrated sensitive data and secrets from 500,000 machines3
. At RSA Conference last week, Mandiant Consulting CTO Charles Carmakal told reporters that Google-owned Mandiant knew of "over 1,000 impacted SaaS environments" actively dealing with the cascading effects of TeamPCP supply chain attacks. "That 1,000-plus downstream victims will probably expand into another 500, another 1,000, maybe another 10,000," Carmakal said, adding that "these actors are collaborating with a number of other actors right now"3
.TeamPCP has publicly stated its intention to partner with ransomware and extortion groups to target affected companies at scale, a strategy that mirrors campaigns like the 2023 Cl0p ransomware gang attack exploiting MOVEit vulnerabilities, which ultimately affected nearly 100 million individuals across government agencies, financial institutions, and healthcare providers
5
. The incident has prompted LiteLLM to make changes to its compliance processes, including shifting from controversial startup Delve to Vanta for compliance certifications1
. With LiteLLM present in an estimated 36% of cloud environments and serving 97 million monthly downloads, the vulnerability exposed a critical weakness in the AI supply chain that companies across the industry must now address4
.Summarized by
Navi
[1]
[3]
23 Jun 2026•Technology

16 Aug 2025•Business and Economy

27 Aug 2025•Technology

1
Science and Research

2
Technology

3
Policy and Regulation
