Mercor attributes cyberattack to compromised LiteLLM open-source project

Mercor, a prominent AI recruiting startup, has acknowledged a security breach stemming from a supply chain attack that compromised the open-source project LiteLLM.
The company informed TechCrunch on Tuesday that it was among numerous organizations impacted by the recent LiteLLM compromise, which has been attributed to a hacking collective known as TeamPCP. This confirmation follows claims by the extortion group Lapsus$ that it successfully targeted Mercor and accessed its data.
The precise method by which Lapsus$ obtained the stolen data from Mercor as part of TeamPCP's cyberattack is not yet known.
Established in 2023, Mercor collaborates with firms like OpenAI and Anthropic to train AI models by engaging specialized domain experts—including scientists, doctors, and lawyers—from markets such as India. The startup reports facilitating over $2 million in daily payouts and was valued at $10 billion after a $350 million Series C funding round led by Felicis Ventures in October 2025.
Mercor spokesperson Heidi Hagberg confirmed to TechCrunch that the company acted swiftly to contain and address the security incident.
"We are conducting a comprehensive investigation with the support of leading third-party forensic experts," Hagberg stated. "We will maintain direct communication with our customers and contractors as needed and are dedicating all necessary resources to resolve this issue promptly."
Previously, Lapsus$ claimed responsibility for the apparent data breach on its leak site and shared a sample of data allegedly taken from Mercor, which TechCrunch has reviewed. The sample included references to Slack data, apparent ticketing information, and two videos purportedly showing interactions between Mercor's AI systems and contractors on its platform.
Hagberg declined to comment on whether the incident is connected to Lapsus$'s claims or whether any customer or contractor data was accessed, exfiltrated, or misused.
The LiteLLM compromise came to light last week after malicious code was detected in a package related to the Y Combinator-backed open-source project. Although the malicious code was identified and removed within hours, the incident attracted significant attention due to LiteLLM's extensive adoption across the internet—with the library being downloaded millions of times daily, according to security firm Snyk. The event also led LiteLLM to revise its compliance procedures, including switching from the controversial startup Delve to Vanta for compliance certifications.
As investigations proceed, it remains uncertain how many companies were affected by the LiteLLM-related incident or whether any data was exposed.
Related article
Mercor’s Brendan Foody Accuses Sequoia of ‘Dual-Pricing’ Valuation Tricks
Recently, founders and those who have become investors have been sharing on X their horror stories about mistreatment by VCs. Complaints range from VCs falling asleep during pitch meetings to investors suggesting that a founder should fire a co-found
Mercor Secures $350M Series C at $10B Valuation, Quintupling Its Worth
Mercor, a platform connecting AI labs with specialized domain professionals to train their foundational AI models, has secured $350 million in funding at a valuation of $10 billion, the company confirmed to TechCrunch.Felicis Ventures, which previous
21-Year-Old Founders' AI Recruiting Startup Mercor Raises $100M at $2B Valuation
Mercor, the AI-driven recruiting startup launched by three 21-year-old Thiel Fellows, has just secured a whopping $100 million in its Series B funding round, as confirmed to TechCrunch. Felicis, based in Menlo Park, spearheaded the investment, pushing Mercor's valuation to a staggering $2 billion—ei
Related Special Topic Recommendations
Comments (0)
0/500

Mercor, a prominent AI recruiting startup, has acknowledged a security breach stemming from a supply chain attack that compromised the open-source project LiteLLM.
The company informed TechCrunch on Tuesday that it was among numerous organizations impacted by the recent LiteLLM compromise, which has been attributed to a hacking collective known as TeamPCP. This confirmation follows claims by the extortion group Lapsus$ that it successfully targeted Mercor and accessed its data.
The precise method by which Lapsus$ obtained the stolen data from Mercor as part of TeamPCP's cyberattack is not yet known.
Established in 2023, Mercor collaborates with firms like OpenAI and Anthropic to train AI models by engaging specialized domain experts—including scientists, doctors, and lawyers—from markets such as India. The startup reports facilitating over $2 million in daily payouts and was valued at $10 billion after a $350 million Series C funding round led by Felicis Ventures in October 2025.
Mercor spokesperson Heidi Hagberg confirmed to TechCrunch that the company acted swiftly to contain and address the security incident.
"We are conducting a comprehensive investigation with the support of leading third-party forensic experts," Hagberg stated. "We will maintain direct communication with our customers and contractors as needed and are dedicating all necessary resources to resolve this issue promptly."
Previously, Lapsus$ claimed responsibility for the apparent data breach on its leak site and shared a sample of data allegedly taken from Mercor, which TechCrunch has reviewed. The sample included references to Slack data, apparent ticketing information, and two videos purportedly showing interactions between Mercor's AI systems and contractors on its platform.
Hagberg declined to comment on whether the incident is connected to Lapsus$'s claims or whether any customer or contractor data was accessed, exfiltrated, or misused.
The LiteLLM compromise came to light last week after malicious code was detected in a package related to the Y Combinator-backed open-source project. Although the malicious code was identified and removed within hours, the incident attracted significant attention due to LiteLLM's extensive adoption across the internet—with the library being downloaded millions of times daily, according to security firm Snyk. The event also led LiteLLM to revise its compliance procedures, including switching from the controversial startup Delve to Vanta for compliance certifications.
As investigations proceed, it remains uncertain how many companies were affected by the LiteLLM-related incident or whether any data was exposed.
Mercor’s Brendan Foody Accuses Sequoia of ‘Dual-Pricing’ Valuation Tricks
Recently, founders and those who have become investors have been sharing on X their horror stories about mistreatment by VCs. Complaints range from VCs falling asleep during pitch meetings to investors suggesting that a founder should fire a co-found
Mercor Secures $350M Series C at $10B Valuation, Quintupling Its Worth
Mercor, a platform connecting AI labs with specialized domain professionals to train their foundational AI models, has secured $350 million in funding at a valuation of $10 billion, the company confirmed to TechCrunch.Felicis Ventures, which previous
21-Year-Old Founders' AI Recruiting Startup Mercor Raises $100M at $2B Valuation
Mercor, the AI-driven recruiting startup launched by three 21-year-old Thiel Fellows, has just secured a whopping $100 million in its Series B funding round, as confirmed to TechCrunch. Felicis, based in Menlo Park, spearheaded the investment, pushing Mercor's valuation to a staggering $2 billion—ei





Home






