Mercor Confirms Hack Linked to LiteLLM Breach

Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- Mercor confirmed a security incident linked to a supply‑chain attack on the open‑source LiteLLM project, saying it was “one of thousands of companies” affected.
- TeamPCP is identified as the hacking group behind the LiteLLM compromise, and Lapsus$ claimed to have targeted Mercor and accessed its data.
- Mercor works with customers such as OpenAI and Anthropic, facilitates over $2 million in daily payouts, and was valued at $10 billion after a $350 million Series C round in October 2025.
- Heidi Hagberg, Mercor spokesperson, said the company moved promptly to contain the incident and is conducting a third‑party forensic investigation.
- Lapsus$ posted a data sample on its leak site—including Slack and ticketing information and videos of AI‑contractor conversations—though Mercor did not confirm any data exfiltration.
- LiteLLM discovered malicious code in its package last week; the code was removed within hours, and the project switched compliance certification from Delve to Vanta.
- LiteLLM’s breach left the number of affected companies and any data exposure unclear as investigations continue.
Why it matters: The breach forces Mercor to allocate resources to a third‑party forensic investigation and ongoing communication with customers and contractors, while the uncertainty over data exposure for partners such as OpenAI and Anthropic remains unresolved, highlighting the operational and reputational stakes for AI‑driven talent platforms.



