Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Critical CyberPanel RCE Chain (CVE-2024-7067) Lets Attackers Gain Server Shell
August 20, 2026
ZombieLoad Flaw Exploits Intel CPUs, Exposes Sensitive Data
August 20, 2026
Critical Firefox Extensions Exploit Cloudflare to Steal Crypto Wallets
August 20, 2026
Home/CyberSecurity News/Mercor AI Confirms Data Breach After Lapsus$ Claims 4TB Data Theft
CyberSecurity News

Mercor AI Confirms Data Breach After Lapsus$ Claims 4TB Data Theft

Key Takeaways AI recruitment platform Mercor AI has confirmed a significant data breach after claims by the Lapsus$ hacking group. The breach originated from a supply chain attack on the open-source...

Sarah simpson
Sarah simpson
April 1, 2026 4 Min Read
58 0

Key Takeaways

  • AI recruitment platform Mercor AI has confirmed a significant data breach after claims by the Lapsus$ hacking group.
  • The breach originated from a supply chain attack on the open-source LiteLLM project, affecting thousands of organizations.
  • Exposed data includes 4 terabytes of proprietary source code, internal databases, and extensive user verification information.
  • Lapsus$ is auctioning the stolen data on the dark web, posing substantial risks to Mercor AI and its users.

Mercor AI, a prominent AI recruitment platform, has officially acknowledged a substantial data breach. This confirmation follows assertions from the notorious Lapsus$ hacking collective, which claims to have exfiltrated 4 terabytes of the company’s sensitive data.

Table Of Content

  • Key Takeaways
  • Lapsus$ Claims and Data Auction
  • Mercor AI’s Official Response
  • Root Cause: LiteLLM Supply Chain Attack
  • Implications for Mercor AI and Its Users
  • What You Should Do

The incident is rooted in a recent supply chain compromise affecting the open-source LiteLLM project. This security lapse has led to the exposure of Mercor’s proprietary source code, internal databases, and a vast quantity of user verification data.

Lapsus$ Claims and Data Auction

The Lapsus$ group has initiated a live auction for Mercor’s platform data on the dark web, inviting interested parties to “make an offer.” The threat actors assert they gained full access to the 4-terabyte dataset by breaching the company’s Tailscale VPN.

The stolen cache is reported to be highly detailed, comprising 939GB of platform source code, a 211GB user database, and 3TB of storage buckets containing sensitive materials such as video interviews and identity verification passports.

Mercor AI’s Official Response

In response to these extortion attempts, Mercor AI issued a public statement, reiterating that customer and contractor privacy and security are paramount. The company clarified that the breach was a direct consequence of a widespread supply chain attack involving the open-source routing library, LiteLLM.

Mercor’s security team acted swiftly to contain the incident and is currently conducting a thorough investigation. They are collaborating with leading third-party forensics experts to understand the full scope of the compromise, as detailed in their official communication:

The privacy and security of our customers and contractors is foundational to everything we do at Mercor. We recently identified that we were one of thousands of companies impacted by a supply chain attack involving LiteLLM.

Our security team moved promptly to contain and…

— Mercor (@mercor_ai) March 31, 2026

Root Cause: LiteLLM Supply Chain Attack

The origin of Mercor’s breach has been traced back to late March 2026, when a threat actor identified as TeamPCP compromised the PyPI publishing credentials for the LiteLLM library. TeamPCP subsequently injected a three-stage malicious backdoor into versions 1.82.7 and 1.82.8 of the library.

This sophisticated malware was engineered to harvest credentials and establish persistent system access. Given LiteLLM’s extensive integration into various AI applications, the malicious code executed immediately upon installation, impacting thousands of unsuspecting organizations downstream.

Implications for Mercor AI and Its Users

Founded in 2023, Mercor AI operates a highly successful AI recruitment platform, boasting over $500 million in revenue and facilitating connections between specialized domain experts and major AI firms such as OpenAI and Anthropic. The platform processes over $2 million in daily payouts.

The exposure of contractors’ personal information now poses significant operational risks for the company. The leak of internal AI source code and sensitive Know Your Customer (KYC) materials carries severe security implications for both the estimated $10 billion platform and its extensive user base.

Lapsus$ is a well-documented cybercrime syndicate renowned for targeting high-profile technology companies with aggressive extortion tactics. The group frequently resorts to public data leaks and dark web auctions to pressure victims into paying ransoms when private negotiations fail. Their involvement in the Mercor AI breach underscores a persistent trend of threat actors exploiting upstream supply chain vulnerabilities to gain access to vast corporate datasets downstream.

What You Should Do

  • For Mercor AI Users/Contractors: Remain vigilant for phishing attempts and unsolicited communications. Consider changing passwords for Mercor AI and any linked accounts. Monitor credit reports and financial statements for unusual activity.
  • For Organizations Using LiteLLM: Immediately verify the versions of LiteLLM in use. If versions 1.82.7 or 1.82.8 were installed, assume compromise and initiate incident response procedures, including forensic analysis and credential rotation. Update to a patched version immediately.
  • Implement Supply Chain Security: Strengthen software supply chain security practices, including rigorous vetting of open-source components, dependency scanning, and integrity checks for third-party libraries.
  • Enhance Network Segmentation: Review and enhance network segmentation, particularly for VPN access and critical internal systems, to limit lateral movement in case of a breach.
  • Review and Update Incident Response Plans: Ensure your organization’s incident response plan is up-to-date and includes specific protocols for supply chain attacks and data breaches involving sensitive customer data.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackBreachExploitMalwareSecurityThreat

Share Article

Sarah simpson

Sarah simpson

Sarah is a cybersecurity journalist specializing in threat intelligence and malware analysis. With over 8 years of experience covering APT groups, zero-day exploits, and advanced persistent threats, Sarah brings deep technical expertise to breaking cybersecurity news. Previously, she worked as a security researcher at leading threat intelligence firms, where she analyzed malware samples and tracked cybercriminal operations. Sarah holds a Master's degree in Computer Science with a focus on cybersecurity and is a regular contributor to major security conferences.

Previous Post

Google Gmail Now Lets Users Change @gmail.com Addresses

Next Post

XLoader Malware Uses Decoy Servers to Hide C2 Traffic

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Critical Zimbra RCE Vulnerability CVE-2022-27925 Actively Exploited
August 20, 2026
T-Mobile Physically Disconnects Network to Expel Chinese Hackers
August 20, 2026
CISA Warns of Active Attacks Exploiting Siemens S7 PLCs
August 20, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us