Mercor AI Confirms Data Breach After Lapsus$ Claims 4TB Data Theft
Key Takeaways AI recruitment platform Mercor AI has confirmed a significant data breach after claims by the Lapsus$ hacking group. The breach originated from a supply chain attack on the open-source...
Key Takeaways
- AI recruitment platform Mercor AI has confirmed a significant data breach after claims by the Lapsus$ hacking group.
- The breach originated from a supply chain attack on the open-source LiteLLM project, affecting thousands of organizations.
- Exposed data includes 4 terabytes of proprietary source code, internal databases, and extensive user verification information.
- Lapsus$ is auctioning the stolen data on the dark web, posing substantial risks to Mercor AI and its users.
Mercor AI, a prominent AI recruitment platform, has officially acknowledged a substantial data breach. This confirmation follows assertions from the notorious Lapsus$ hacking collective, which claims to have exfiltrated 4 terabytes of the company’s sensitive data.
Table Of Content
The incident is rooted in a recent supply chain compromise affecting the open-source LiteLLM project. This security lapse has led to the exposure of Mercor’s proprietary source code, internal databases, and a vast quantity of user verification data.
Lapsus$ Claims and Data Auction
The Lapsus$ group has initiated a live auction for Mercor’s platform data on the dark web, inviting interested parties to “make an offer.” The threat actors assert they gained full access to the 4-terabyte dataset by breaching the company’s Tailscale VPN.
The stolen cache is reported to be highly detailed, comprising 939GB of platform source code, a 211GB user database, and 3TB of storage buckets containing sensitive materials such as video interviews and identity verification passports.
Mercor AI’s Official Response
In response to these extortion attempts, Mercor AI issued a public statement, reiterating that customer and contractor privacy and security are paramount. The company clarified that the breach was a direct consequence of a widespread supply chain attack involving the open-source routing library, LiteLLM.
Mercor’s security team acted swiftly to contain the incident and is currently conducting a thorough investigation. They are collaborating with leading third-party forensics experts to understand the full scope of the compromise, as detailed in their official communication:
The privacy and security of our customers and contractors is foundational to everything we do at Mercor. We recently identified that we were one of thousands of companies impacted by a supply chain attack involving LiteLLM.
Our security team moved promptly to contain and…
— Mercor (@mercor_ai) March 31, 2026
Root Cause: LiteLLM Supply Chain Attack
The origin of Mercor’s breach has been traced back to late March 2026, when a threat actor identified as TeamPCP compromised the PyPI publishing credentials for the LiteLLM library. TeamPCP subsequently injected a three-stage malicious backdoor into versions 1.82.7 and 1.82.8 of the library.
This sophisticated malware was engineered to harvest credentials and establish persistent system access. Given LiteLLM’s extensive integration into various AI applications, the malicious code executed immediately upon installation, impacting thousands of unsuspecting organizations downstream.
Implications for Mercor AI and Its Users
Founded in 2023, Mercor AI operates a highly successful AI recruitment platform, boasting over $500 million in revenue and facilitating connections between specialized domain experts and major AI firms such as OpenAI and Anthropic. The platform processes over $2 million in daily payouts.
The exposure of contractors’ personal information now poses significant operational risks for the company. The leak of internal AI source code and sensitive Know Your Customer (KYC) materials carries severe security implications for both the estimated $10 billion platform and its extensive user base.
Lapsus$ is a well-documented cybercrime syndicate renowned for targeting high-profile technology companies with aggressive extortion tactics. The group frequently resorts to public data leaks and dark web auctions to pressure victims into paying ransoms when private negotiations fail. Their involvement in the Mercor AI breach underscores a persistent trend of threat actors exploiting upstream supply chain vulnerabilities to gain access to vast corporate datasets downstream.
What You Should Do
- For Mercor AI Users/Contractors: Remain vigilant for phishing attempts and unsolicited communications. Consider changing passwords for Mercor AI and any linked accounts. Monitor credit reports and financial statements for unusual activity.
- For Organizations Using LiteLLM: Immediately verify the versions of LiteLLM in use. If versions 1.82.7 or 1.82.8 were installed, assume compromise and initiate incident response procedures, including forensic analysis and credential rotation. Update to a patched version immediately.
- Implement Supply Chain Security: Strengthen software supply chain security practices, including rigorous vetting of open-source components, dependency scanning, and integrity checks for third-party libraries.
- Enhance Network Segmentation: Review and enhance network segmentation, particularly for VPN access and critical internal systems, to limit lateral movement in case of a breach.
- Review and Update Incident Response Plans: Ensure your organization’s incident response plan is up-to-date and includes specific protocols for supply chain attacks and data breaches involving sensitive customer data.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.