Apps & Consumer
Mercor confirms security incident linked to LiteLLM compromise
Mercor, a $10 billion AI recruiting startup, confirmed a security incident linked to a supply chain attack on the open-source LiteLLM project, though the extent remains unclear.
AI recruiting startup Mercor has confirmed a security incident, stating it was hit by a cyberattack linked to a supply chain attack—a cyberattack targeting the software supply chain—involving the open-source project LiteLLM. On Tuesday, the company confirmed to TechCrunch that it was one of thousands of companies affected by the compromise of the open-source LiteLLM project, which has been linked to the hacking group TeamPCP. The confirmation comes as the extortion hacking group Lapsus$ claimed it had targeted Mercor and gained access to its data.
It is not immediately clear how Lapsus$ obtained stolen data from Mercor. Founded in 2023, Mercor works with companies, including OpenAI and Anthropic, to train AI models by contracting specialized domain experts, such as scientists, doctors, and lawyers, from markets including India. The startup says it facilitates more than $2 million in daily payouts. Additionally, the company was valued at $10 billion following a $350 million Series C round—a late-stage funding round—led by Felicis Ventures in October 2025.
Mercor spokesperson Heidi Hagberg confirmed to TechCrunch that the company moved promptly to contain and remediate the security incident. Hagberg stated that the company is conducting a thorough investigation supported by leading third-party forensics experts. She added, “We will continue to communicate with our customers and contractors directly as appropriate and devote the resources necessary to resolving the matter as soon as possible.”
The compromise of the open-source LiteLLM project originally surfaced last week. According to data from security firm Snyk, the LiteLLM library is downloaded millions of times per day. The incident has prompted LiteLLM to make changes to its compliance processes, including shifting its compliance certifications from its former compliance provider Delve to its current compliance provider Vanta. However, it remains unclear how many companies were affected by the LiteLLM-related incident or whether any data exposure occurred, as investigations continue.
Why it matters
The incident highlights the vulnerability of the AI software supply chain, where a compromise of an open-source library can affect thousands of companies, including startups like Mercor.