Threats & Adversaries · Supply Chain
Mercor AI Confirms Data Theft via LiteLLM Supply Chain Breach Mercor AI, an AI recruiting startup, publicly confirmed it was breached through the LiteLLM supply chain compromise linked to the TeamPCP cybercriminal group. The attackers used compromised credentials from the supply chain phase to access Mercor's cloud environment, enabling extensive post-compromise enumeration and exfiltration of 4TB of data. The stolen data includes source code, user databases, and biometric identity documents, raising privacy and regulatory risks under GDPR, CCPA, and possibly HIPAA.
This confirmation moves the TeamPCP campaign from theoretical risk to confirmed operational impact. Public threat intelligence sources currently show no TeamPCP indicators, complicating detection and response. The stolen credentials and sensitive data enable future intrusions without requiring new supply chain exploits, changing the threat model for affected organizations.
4 sources · Apr 1
NVD KEV
Known exploited · CISA KEV
CISA federal remediation date Apr 9
Timeline Sources Apr 1 SANS ISC
TeamPCP Supply Chain Campaign: Update 005 - First Confirmed Victim Disclosure, Post-Compromise Cloud Enumeration Documented, and Axios Attribution Narrows
TeamPCP Supply Chain Campaign: Update 005 - First Confirmed Victim Disclosure, Post-Compromise Cloud Enumeration Documented, and Axios Attribution Narrows, Author: Kenneth Hartman
original Mar 31 Dark Reading
TeamPCP Breaches Cloud, SaaS Instances with Stolen Credentials
The threat group's shift to speedy attacks on AWS, Azure, and SaaS instances shows organizations need to respond quickly to compromised credentials.
original Mar 31 SecurityWeek
TeamPCP Moves From OSS to AWS Environments
After validating stolen credentials using TruffleHog, the hacking group started AWS services enumeration and lateral movement activities.
original Part of the PlainSec briefing for 2026-04-02
Every edition of this story: Mercor AI Confirms Data Theft via LiteLLM Supply Chain Breach
More from today
Threats & Adversaries · Supply Chain
Mercor AI Confirms Data Theft via LiteLLM Supply Chain Breach Mercor AI, an AI recruiting startup, publicly confirmed it was breached through the LiteLLM supply chain compromise linked to the TeamPCP cybercriminal group. The attackers used compromised credentials from the supply chain phase to access Mercor's cloud environment, enabling extensive post-compromise enumeration and exfiltration of 4TB of data. The stolen data includes source code, user databases, and biometric identity documents, raising privacy and regulatory risks under GDPR, CCPA, and possibly HIPAA.
This confirmation moves the TeamPCP campaign from theoretical risk to confirmed operational impact. Public threat intelligence sources currently show no TeamPCP indicators, complicating detection and response. The stolen credentials and sensitive data enable future intrusions without requiring new supply chain exploits, changing the threat model for affected organizations.
4 sources · Apr 1
NVD KEV
Known exploited · CISA KEV
CISA federal remediation date Apr 9
Timeline Sources Apr 1 SANS ISC
TeamPCP Supply Chain Campaign: Update 005 - First Confirmed Victim Disclosure, Post-Compromise Cloud Enumeration Documented, and Axios Attribution Narrows
TeamPCP Supply Chain Campaign: Update 005 - First Confirmed Victim Disclosure, Post-Compromise Cloud Enumeration Documented, and Axios Attribution Narrows, Author: Kenneth Hartman
original Mar 31 Dark Reading
TeamPCP Breaches Cloud, SaaS Instances with Stolen Credentials
The threat group's shift to speedy attacks on AWS, Azure, and SaaS instances shows organizations need to respond quickly to compromised credentials.
original Mar 31 SecurityWeek
TeamPCP Moves From OSS to AWS Environments
After validating stolen credentials using TruffleHog, the hacking group started AWS services enumeration and lateral movement activities.
original Part of the PlainSec briefing for 2026-04-02
Every edition of this story: Mercor AI Confirms Data Theft via LiteLLM Supply Chain Breach
More from today