{"id":107882,"date":"2026-04-01T10:28:36","date_gmt":"2026-04-01T10:28:36","guid":{"rendered":"https:\/\/neclink.com\/index.php\/2026\/04\/01\/mercor-says-it-was-hit-by-cyberattack-tied-to-compromise-of-open-source-litellm-project\/"},"modified":"2026-04-01T10:28:36","modified_gmt":"2026-04-01T10:28:36","slug":"mercor-says-it-was-hit-by-cyberattack-tied-to-compromise-of-open-source-litellm-project","status":"publish","type":"post","link":"https:\/\/neclink.com\/index.php\/2026\/04\/01\/mercor-says-it-was-hit-by-cyberattack-tied-to-compromise-of-open-source-litellm-project\/","title":{"rendered":"Mercor says it was hit by cyberattack tied to compromise of open-source LiteLLM project"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div>\n<p id=\"speakable-summary\" class=\"wp-block-paragraph\"><a href=\"https:\/\/www.mercor.com\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Mercor<\/a>, a popular AI recruiting startup, has confirmed a security incident linked to a supply chain attack involving the open-source project LiteLLM.<\/p>\n<p class=\"wp-block-paragraph\">The AI startup told TechCrunch on Tuesday that it was \u201cone of thousands of companies\u201d affected by a recent compromise of LiteLLM\u2019s project, which was linked to a hacking group called TeamPCP. Confirmation of the incident comes as extortion hacking group Lapsus$ claimed it had targeted Mercor and gained access to its data.<\/p>\n<p class=\"wp-block-paragraph\">It\u2019s not immediately clear how the Lapsus$ gang obtained the stolen data from Mercor as part of TeamPCP\u2019s cyberattack.<\/p>\n<p class=\"wp-block-paragraph\">Founded in 2023, Mercor works with companies including OpenAI and Anthropic to train AI models by contracting specialized domain experts such as scientists, doctors, and lawyers from markets including India. The startup says it facilitates more than $2 million in daily payouts and was <a href=\"https:\/\/techcrunch.com\/2025\/10\/27\/mercor-quintuples-valuation-to-10b-with-350m-series-c\/\" target=\"_blank\" rel=\"noreferrer noopener\">valued at $10 billion<\/a> following a $350 million Series C round led by Felicis Ventures in October 2025.<\/p>\n<p class=\"wp-block-paragraph\">Mercor spokesperson Heidi Hagberg confirmed to TechCrunch that the company had \u201cmoved promptly\u201d to contain and remediate the security incident.<\/p>\n<p class=\"wp-block-paragraph\">\u201cWe are conducting a thorough investigation supported by leading third-party forensics experts,\u201d said Hagberg. \u201cWe will continue to communicate with our customers and contractors directly as appropriate and devote the resources necessary to resolving the matter as soon as possible.\u201d<\/p>\n<p class=\"wp-block-paragraph\">Earlier, Lapsus$ claimed responsibility for the apparent data breach on its leak site and shared a sample of data allegedly taken from Mercor, which TechCrunch reviewed. The sample included material referencing Slack data and what appeared to be ticketing data, as well as two videos purportedly showing conversations between Mercor\u2019s AI systems and contractors on its platform.<\/p>\n<div class=\"wp-block-techcrunch-inline-cta\">\n<div class=\"inline-cta__wrapper\">\n<p>Techcrunch event<\/p>\n<div class=\"inline-cta__content\">\n<p>\n\t\t\t\t\t\t\t\t\t<span class=\"inline-cta__location\">San Francisco, CA<\/span><br \/>\n\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"inline-cta__separator\">|<\/span><br \/>\n\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"inline-cta__date\">October 13-15, 2026<\/span>\n\t\t\t\t\t\t\t<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<\/div>\n<p class=\"wp-block-paragraph\">Hagberg declined to answer follow-up questions on whether the incident was connected to claims by Lapsus$, or whether any customer or contractor data had been accessed, exfiltrated, or misused.<\/p>\n<p class=\"wp-block-paragraph\">The compromise of LiteLLM <a href=\"https:\/\/techcrunch.com\/2026\/03\/26\/delve-did-the-security-compliance-on-litellm-an-ai-project-hit-by-malware\/\" target=\"_blank\" rel=\"noreferrer noopener\">originally surfaced<\/a> last week after malicious code was discovered in a package associated with the Y Combinator-backed startup\u2019s open-source project. While the malicious code was identified and removed within hours, the incident drew scrutiny due to LiteLLM\u2019s widespread use around the internet, with the library downloaded millions of times per day, per security firm Snyk. The incident also prompted LiteLLM to make changes to its compliance processes, including <a href=\"https:\/\/techcrunch.com\/2026\/03\/30\/popular-ai-gateway-startup-litellm-ditches-controversial-startup-delve\/\" target=\"_blank\" rel=\"noreferrer noopener\">shifting from controversial startup Delve<\/a> to Vanta for compliance certifications.<\/p>\n<p class=\"wp-block-paragraph\">It remains unclear how many companies were affected by the LiteLLM-related incident or whether any data exposure occurred, as investigations continue.<\/p>\n<\/div>\n<p><br \/>\n<br \/><a href=\"https:\/\/techcrunch.com\/2026\/03\/31\/mercor-says-it-was-hit-by-cyberattack-tied-to-compromise-of-open-source-litellm-project\/\">Source link <\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Mercor, a popular AI recruiting startup, has confirmed a security incident linked to a supply chain attack involving the open-source project LiteLLM. The AI startup<\/p>\n","protected":false},"author":1,"featured_media":107883,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"footnotes":""},"categories":[178],"tags":[],"class_list":["post-107882","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-tech"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/neclink.com\/index.php\/wp-json\/wp\/v2\/posts\/107882","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/neclink.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/neclink.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/neclink.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/neclink.com\/index.php\/wp-json\/wp\/v2\/comments?post=107882"}],"version-history":[{"count":0,"href":"https:\/\/neclink.com\/index.php\/wp-json\/wp\/v2\/posts\/107882\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/neclink.com\/index.php\/wp-json\/wp\/v2\/media\/107883"}],"wp:attachment":[{"href":"https:\/\/neclink.com\/index.php\/wp-json\/wp\/v2\/media?parent=107882"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/neclink.com\/index.php\/wp-json\/wp\/v2\/categories?post=107882"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/neclink.com\/index.php\/wp-json\/wp\/v2\/tags?post=107882"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}