AI recruiting startup Mercor hit by cyberattack; Meta halts collaboration

AI recruiting startup Mercor hit by cyberattack; Meta halts collaboration



A few days ago, artificial intelligence (AI) recruiting startup Mercor confirmed it was hit by a security incident linked to the open-source tool LiteLLM.

Media reports indicate Mercor was among thousands of firms affected by the compromise of LiteLLM, attributed to a hacking group called TeamPCP.

The extortion group Lapsus$ has claimed responsibility, publishing stolen data samples on its leak site, according to TechCrunch. These included Slack messages, internal ticket records, and two videos showing Mercor’s AI interacting with contractors. However, it remains unclear how Lapsus$ obtained Mercor’s data during the attack.

Mercor said the malicious code was swiftly detected and removed. Nevertheless, the breach drew attention because LiteLLM is widely used, with millions of daily downloads, said TechCrunch, citing security firm Snyk.

LiteLLM has since strengthened its compliance measures, switching from the now-controversial compliance startup Delve to Vanta for certifications.

Founded in 2023, Mercor connects companies, including OpenAI, Meta, and Anthropic, with domain experts such as scientists, doctors, and lawyers, primarily from India. The platform processes more than $2 million in daily payouts.