AI recruiting startup Mercor, valued at $10 billion following a $350 million Series C in October 2025, confirmed a security incident linked to a supply chain attack on the open-source LiteLLM project that affected thousands of companies. Extortion group Lapsus$ claimed responsibility for targeting Mercor specifically, sharing sample data including Slack references and videos allegedly showing contractor conversations on Mercor's platform. The LiteLLM compromise, attributed to hacking group TeamPCP, involved malicious code in the Y Combinator-backed project's package that was removed within hours of discovery. Mercor, which works with OpenAI and Anthropic and facilitates over $2 million in daily payouts to contractors including specialized experts from India, declined to confirm whether customer or contractor data was accessed while conducting forensic investigation.
Aug 8, 2026 · 2 sources
Aug 10, 2026 · 1 source
Aug 10, 2026 · 3 sources
Aug 10, 2026 · 8 sources
Story comments
Loading comments…