Skip to content
AI startup Mercor confirms security incident linked to LiteLLM supply chain attack

AI startup Mercor confirms security incident linked to LiteLLM supply chain attack

Scworld April 1, 2026

AI recruiting startup Mercor has confirmed it was affected by a security incident, which appears to be linked to a supply chain attack targeting the open-source project LiteLLM. The company stated it was one of thousands of organizations impacted by the compromise. This confirmation follows claims by the extortion hacking group Lapsus$ that it had targeted Mercor and accessed its data, according to a recent report by TechCrunch.

The incident at Mercor is believed to stem from malicious code injected into the LiteLLM project, an open-source tool used by numerous companies to manage AI model interactions. A hacking group known as TeamPCP has been linked to this compromise. While Mercor is investigating the full extent of the breach with third-party experts, the group Lapsus$ has claimed responsibility and released a sample of data allegedly stolen from Mercor, including Slack and ticketing information. It is unclear how Lapsus$ obtained this data in relation to the TeamPCP attack on LiteLLM.

Extracted Entities

Companies (1)

Tools (1)