Mercor, AI Recruiting Firm, Confirms Data Breach Linked to LiteLLM Supply Chain Attack
**Mercor**, a recruiting firm specializing in AI talent, has confirmed a security incident stemming from a supply chain attack targeting the open-source **LiteLLM** project. The breach potentially exposed sensitive data belonging to **Mercor**'s customers and contractors, including **OpenAI**.
A platform that helps AI industry leaders improve their models on Wednesday confirmed a security incident tied to a recent supply chain attack.
**Mercor**, a prominent recruiting firm that works with companies like **OpenAI** to source experts and train AI models, was one of the thousands of organizations impacted by the compromise of the open-source **LiteLLM** project, according to a company statement. As of October 2025, the company was reportedly valued at $10 billion.
βThe privacy and security of our customers and contractors is foundational to everything we do at **Mercor**,β said **Mercor** spokesperson Heidi Hagberg. βOur security team moved promptly to contain and remediate the incident.β
**Investigation Underway**
**Mercor** is currently conducting a thorough investigation into the breach, with the assistance of external forensics experts.
TechCrunch was first to report **Mercor**βs confirmation of the security incident.
**Lapsus$ Claims Responsibility**
While the **LiteLLM** attack has been reportedly linked to a group called **TeamPCP**, the hacking group **Lapsus$** claimed on its website that it had obtained hundreds of gigabytes of **Mercor**'s data. Heidi Hagberg did not immediately respond to questions about **Lapsus$**βs claims.
**LiteLLM's Response**
**LiteLLM** confirmed the hack on its systems last week, stating that it was βinvestigating a suspected supply chain attack involving unauthorized PyPI package publishes.β The open-source project indicated that a userβs PyPI account may have been βcompromised and used to distribute malicious code.β
A clean version of **LiteLLM** was released Monday, according to a **LiteLLM** security post.