Esc
SafetyCase Closed

Mercor $10B Data Breach via LiteLLM Supply Chain Attack

Is this a scandal?

No longer — the story has resolved. Noise 1/100, cooling down, across 0 sources.

SCAND-48523as of Methodology
Cite this incident"Mercor $10B Data Breach via LiteLLM Supply Chain Attack." SCAND.Ai incident SCAND-48523, noise 1/100 as of September 3, 2026. https://scand.ai/scandal/mercor-litellm-data-breach-analysis
FORECASTForecast, not fact

Regulatory bodies are likely to mandate stricter 'Software Bill of Materials' (SBOM) requirements for AI companies to track deep dependencies. We can also expect a shift toward 'air-gapped' or highly restricted environments for AI coding assistants to prevent them from accessing production secrets.

1

Noise 1/100 — louder than 92% of tracked AI controversies.

AI-assisted analysis · How we work

Why it matters

This incident demonstrates how open-source dependencies create systemic risk for AI infrastructure, potentially forcing stricter vendor security audits across the industry.

Key points

  1. Mercor confirmed a supply-chain attack via the open-source LiteLLM library compromised its systems.
  2. Hacking group Lapsus$ claimed responsibility for stealing data through poisoned PyPI packages.
  3. The breach has triggered at least seven lawsuits against the $10 billion valued startup.
  4. Reports indicate Mercor is losing major enterprise customers following the security disclosure.
  5. Attackers allegedly bypassed Trivy scanners to inject malicious code into the dependency chain.

The story

Mercor, a $10 billion AI recruiting startup, confirmed it suffered a data breach resulting from a supply-chain attack involving the open-source library LiteLLM. The company stated in an email to users that attackers compromised the dependency to steal credentials and access sensitive data. Security researchers reported that the hacking group Lapsus$ claimed responsibility for the intrusion, which allegedly involved poisoning the PyPI package and bypassing Trivy scanners. Following the disclosure, Mercor faces at least seven lawsuits and reports indicate significant customer churn among major tech clients. This incident highlights critical vulnerabilities in AI software supply chains, where third-party open-source components serve as high-value targets for credential theft. Industry analysts suggest the breach may accelerate enterprise demands for rigorous dependency vetting and software bill of materials compliance within AI development workflows.

Who's involved

Critic
TeamPCP

The threat actor responsible for the initial compromise of the Trivy security scanner and the poisoning of LiteLLM.

Critic
Lapsus$

The hacking group currently auctioning the stolen 4TB of Mercor data on the dark web.

Neutral
Mercor

The victimized AI startup currently facing a massive data exfiltration crisis and potential legal liabilities.

Neutral
Aqua Security

The provider of the Trivy scanner which served as the initial entry point for the attack chain.

Neutral
LiteLLM Maintainers

The open-source developers whose project was hijacked to distribute malware via PyPI.

Most contested claim

TeamPCP compromised Trivy and directly enabled the LiteLLM poisoning that led to Mercor's breach

Biggest open question

Specific version number and payload type of poisoned LiteLLM package unverified by primary technical disclosure

Read the full story

How we got here

Software supply chain attacks targeting open-source package registries have become a recurring pattern in cybersecurity, predating the current AI infrastructure boom. Historically, threat actors have employed dependency confusion, typosquatting, and maintainer account takeovers to inject malicious code into widely used libraries. The compromise of security tooling itself represents a more sophisticated variant of this pattern, where defenders' own utilities are subverted to establish trust and bypass scrutiny. In the context of AI development, the reliance on numerous specialized Python packages creates an expansive attack surface where a single compromised dependency can propagate rapidly across organizations. The integration of AI coding assistants introduces a novel exfiltration vector, as these tools often possess broad file system and network permissions to function effectively. This convergence of traditional supply chain risks with new AI-native development workflows creates compound vulnerabilities that existing security frameworks may not adequately address. Prior incidents have demonstrated that downstream victims often face liability despite being indirect targets of the initial compromise.

The full story

Mercor, an AI recruiting and training data startup valued at $10 billion, confirmed it suffered a significant security incident stemming from a supply chain attack involving the open-source project LiteLLM. According to TechCrunch, Mercor acknowledged that the breach was tied to the compromise of LiteLLM, a popular library used for managing large language model API calls. Fortune reported that Mercor explicitly characterized the event as a “supply-chain attack,” confirming the company’s status as a victim in what has become a high-profile cybersecurity case within the AI sector.

The attack sequence, as described across multiple reports, began with the compromise of Aqua Security’s Trivy scanner. A threat actor identified as TeamPCP allegedly gained access to credentials through Trivy on March 19, 2026. This initial foothold reportedly enabled the subsequent poisoning of the LiteLLM package on PyPI. On March 25, 2026, version 1.82.8 of LiteLLM was uploaded containing a malicious .pth payload designed to harvest developer credentials. This poisoned dependency served as the vector for infiltrating Mercor’s internal environment.

Following the installation of the compromised library, malware leveraged permissions granted to developer AI assistants to exfiltrate approximately 4TB of data to a spoofed domain on March 30, 2026. The stolen dataset allegedly includes proprietary databases, source code, and biometric files. By April 1, 2026, the hacking group Lapsus$ began auctioning this data on dark web marketplaces. LinkedIn commentary corroborated the narrative that the breach highlighted software supply chain vulnerabilities, specifically noting the connection between the LiteLLM attack and the Lapsus$ data claims.

The fallout for Mercor has been immediate and severe. Yahoo Finance reported that the startup is facing lawsuits and is reportedly losing major customers in the wake of the disclosure. TechBuzz.ai described the situation as an “existential crisis,” noting that the company is bleeding clients following the breach. Quantnest.in detailed that at least seven class-action lawsuits have been triggered by the exposure of user data. Techloy.com confirmed that Mercor notified affected users via email, attributing the breach directly to the LiteLLM supply chain compromise.

While Mercor has confirmed the supply chain nature of the incident, the specific technical attribution to TeamPCP and the precise mechanics of the Trivy compromise remain primarily sourced from social media commentary and secondary analysis rather than official forensic disclosures. The assertion that TeamPCP was responsible for the Trivy compromise appears in X (formerly Twitter) commentary but lacks independent verification in the provided primary sources. Similarly, while Lapsus$ is widely cited as the group auctioning the data, the direct link between TeamPCP’s initial intrusion and Lapsus$’s possession of the exfiltrated data remains a point of inference in the available reporting.

Mercor’s position as a provider of AI training data to major firms like OpenAI, Anthropic, and Meta adds systemic significance to the breach. The incident illustrates how trust in open-source ecosystems can be weaponized against high-value targets. The attackers exploited the implicit trust developers place in package registries and security tools, turning a defensive utility (Trivy) and a functional library (LiteLLM) into offensive instruments. The use of AI assistant permissions for exfiltration further underscores the emerging risk surface created by integrating autonomous coding agents into development workflows without adequate sandboxing or egress controls.

What's confirmed, what's disputed

  • ConfirmedMercor confirmed it was hit by a supply-chain attack involving LiteLLM
  • ConfirmedLapsus$ began auctioning stolen Mercor database, source code, and biometric files on April 1, 2026
  • DisputedVersion 1.82.8 of LiteLLM was poisoned on PyPI with a malicious .pth payload on March 25, 2026
  • ConfirmedMercor is facing at least seven class-action lawsuits following the breach
  • DisputedTeamPCP gained access to credentials through Aqua Security's Trivy tool on March 19, 2026
  • ConfirmedMercor is reportedly losing big-name customers after the breach

The strongest case each way

Critic's case

The attack demonstrates catastrophic failure in dependency vetting and AI assistant permission scoping, suggesting Mercor prioritized velocity over security hygiene despite handling sensitive biometric and training data for critical AI infrastructure.

Defender's case

Supply chain attacks against trusted security tools and package registries represent advanced persistent threats that even well-resourced organizations struggle to prevent; Mercor's transparent disclosure and user notification demonstrate responsible incident response despite being victimized by sophisticated adversaries.

Times this happened before

  • SolarWinds Orion Supply Chain Compromise · 2020Widespread federal agency breaches; CISA emergency directive; lasting shift toward zero-trust architecture
  • Codecov Bash Uploader Supply Chain Attack · 2021Credential harvesting via CI/CD tool compromise; accelerated adoption of artifact signing

What's at stake

Mercor, valued at $10 billion, faces immediate commercial damage including customer churn and seven class-action lawsuits following the exfiltration of 4TB of sensitive data including biometrics and source code. The breach exposes users whose personal and professional data was stored on the platform to identity theft and privacy harms. Downstream AI companies relying on Mercor for training data face potential contamination risks and contractual uncertainties. The broader AI infrastructure ecosystem confronts heightened scrutiny of open-source dependencies, potentially forcing costly security audits and slowing development velocity. If Mercor loses key enterprise customers, the $10B valuation may prove unsustainable, triggering cascading losses for investors and employees.

$10 billionCompany valuation at risk
4TBData volume exfiltrated
7Class-action lawsuits filed

What we still don't know

  • Specific version number and payload type of poisoned LiteLLM package unverified by primary technical disclosure
  • Attribution of Trivy compromise to TeamPCP lacks independent forensic confirmation

Join the Discussion

Discuss this story

Community comments coming in a future update

Be the first to share your perspective. Subscribe to comment.

Noise Level

Quiet1?Noise Score (0–100): how loud a controversy is. Composite of reach, engagement, star power, cross-platform spread, polarity, duration, and industry impact — with 7-day decay.
Decay: 5%
Reach
0
Engagement
0
Star Power
25
Duration
0
Cross-Platform
0
Polarity
85
Industry Impact
95

The timeline

  1. Lapsus$ Auction Begins

    The hacking group lists the stolen Mercor database, source code, and biometric files for sale.

  2. Mercor Data Exfiltration

    Malware leverages developer AI assistant permissions to exfiltrate 4TB of data to a spoofed domain.

  3. LiteLLM Poisoned on PyPI

    Version 1.82.8 of LiteLLM is uploaded with a malicious .pth payload that harvests credentials.

  4. Trivy Scanner Compromised

    TeamPCP gains access to credentials through Aqua Security's Trivy tool.

The full record

Sources & methodology

The records from this story's original coverage were pruned, so items marked located later were found by searching for it afterwards. The summary above has since been rewritten to take them into account — it is not the text first published. How we score →

Where the sources disagree

In dispute TeamPCP compromised Trivy and directly enabled the LiteLLM poisoning that led to Mercor's breach

Established Mercor confirmed a supply chain attack via LiteLLM; Lapsus$ is auctioning stolen data; Trivy compromise is alleged but not independently verified

What's being under-reported

No defender-side coverage yet

The critic side is sourced here; no defending voice has been captured yet.

  • Coverage: 0 social posts, 0 news-outlet items.
  • Voices: 2 critics, 0 defenders.

Missing perspective from Aqua Security and LiteLLM maintainers regarding their own incident response and remediation steps. Without their accounts, the narrative remains victim-centric and may overlook upstream security failures or successful mitigation efforts that could inform industry best practices. Technical forensic details from primary investigators are also absent, leaving attribution claims partially unsubstantiated.

Who changed their mind, and why
  • MercorShifted from silent investigation to public confirmation of supply chain attack and user notification (was: No public statement prior to TechCrunch and Fortune reporting)
  • Lapsus$Escalated from data exfiltration to active dark web auction monetization (was: Unknown pre-auction posture)

The forecast

Regulatory bodies are likely to mandate stricter 'Software Bill of Materials' (SBOM) requirements for AI companies to track deep dependencies. We can also expect a shift toward 'air-gapped' or highly restricted environments for AI coding assistants to prevent them from accessing production secrets.

Forecast, not fact — an editorial estimate we score when this resolves.

You're up to date

That's the complete picture as of — nothing more to know right now. We'll update this page the moment it changes.