Mercor says it was hit by cyberattack tied to compromise of open source LiteLLM project
Mercor, a leading AI recruiting platform, has confirmed a recent cybersecurity incident connected to a supply chain compromise involving the open source LiteLLM project. The breach affected Mercor alongside thousands of other companies that utilize LiteLLM, after malicious code was introduced by the hacking group TeamPCP.
According to TechCrunch, Mercor was named by the extortion group Lapsus$ as a victim, with claims that the group accessed sensitive company data. The full extent of the data breach remains unclear, and details on how Lapsus$ obtained the information have not been disclosed.
Mercor’s Response
The company, backed by high-profile partners like OpenAI and Anthropic, is valued at $10 billion and manages over $2 million in payments daily to subject matter experts worldwide.
Mercor's spokesperson, Heidi Hagberg, emphasized that the company acted swiftly to contain the incident and has involved top cybersecurity experts for a comprehensive investigation. Ongoing communication with clients and contractors is a priority as the situation develops. However, Mercor has not confirmed whether any client or contractor data has been compromised or misused.
The Broader LiteLLM Impact
The LiteLLM breach came to light last week when malware was detected in one of its widely-used packages. Given LiteLLM's massive user base, the incident prompted the project to enhance compliance measures and shift certification partners. While the malicious code was quickly removed, the wider impact is still under investigation.
The number of affected companies and the scale of possible data exposures are yet to be determined.
For more details, refer to the original article: TechCrunch - Mercor says it was hit by cyberattack tied to compromise of open source LiteLLM project.