Mercor hit by supply chain cyberattack as hacking group Lapsus$ claims 4TB data theft
AI recruiting startup Mercor has confirmed a security incident linked to a supply chain attack involving LiteLLMDealroom has a profile for this one. Try Dealroom →, an open-source AI software library used across thousands of companies.
Mercor said it was "one of thousands of companies" affected by the compromise, tied to a hacking group called TeamPCP.
Separately, extortion group Lapsus$ claimed responsibility for targeting Mercor specifically, alleging it obtained approximately 4TB of data — including 939GB of source code, 211GB of database content, video files, and data from the company's Tailscale VPN. Mercor said it has moved to contain the incident and has engaged third-party forensics experts.
Founded in 2023, Mercor works with companies including OpenAI and AnthropicDealroom has a profile for this one. Try Dealroom → to train AI models by contracting specialised domain experts — scientists, doctors, and lawyers — primarily from markets including India. The company facilitates more than $2 million in daily payouts and was valued at $10 billion following a $350 million Series C round led by Felicis Ventures in October 2025.
The LiteLLM compromise surfaced in March 2026 after malicious code was discovered in a package associated with the Y Combinator-backed project. The code was identified and removed within hours, but LiteLLM's library is downloaded millions of times per day, making the potential scope of the attack very large.
Mercor has declined to confirm whether any customer or contractor data was accessed, exfiltrated, or misused — leaving the full scope of the breach unclear. The connection between TeamPCP's LiteLLM attack and Lapsus$'s claimed data has also not been established.
Given that Mercor holds sensitive personal and professional data on contractors across multiple countries, as well as proprietary data from AI lab clients including OpenAI and Anthropic, the potential consequences of a material breach are significant.
Lapsus$ is a financially motivated extortion group with a track record of high-profile breaches including Uber, Rockstar GamesDealroom has a profile for this one. Try Dealroom →, and Nvidia. Its involvement raises the likelihood of attempted extortion regardless of how the data was obtained.
The LiteLLM supply chain attack is a warning shot for the AI software ecosystem. LiteLLM is used by thousands of companies as a gateway layer for calling AI models — meaning a single compromised dependency can expose a vast number of downstream platforms simultaneously.
As AI infrastructure becomes more interconnected and dependent on open-source components, supply chain security is moving from a background concern to a front-line risk. The fact that a $10 billion company was caught in this net underscores how quickly open-source vulnerabilities can propagate through the industry.
Sources:
Mercor's LinkedIn post
Dominic Alvieri's X post
TechCrunch
The Record
The Register
CyberNews
Cryptika
J.V.