Breaches · 166 days ago
A supply-chain compromise in the open-source AI runtime LiteLLM has escalated beyond a startup data breach to disrupt commercial relationships and AI training workflows. The standard breach response focusing on Mercor's internal systems misses the broader impact on customers who rely on Mercor and LiteLLM-based tooling, as they pause operations and reassess dependencies in their AI pipelines.
Mercor confirmed it was affected by a supply-chain attack involving LiteLLM, prompting Meta to halt its collaboration and launch an investigation. This shift from breach disclosure to vendor and forensic scrutiny signals real business interruption for technology companies using Mercor's AI training data services and those embedding LiteLLM in production.
The incident highlights how vulnerabilities in open-source AI infrastructure can cascade into operational disruptions across multiple organizations. The risk extends to external contractors, customer workflows, and any services built on compromised components, underscoring the need to track vendor exposure and supply-chain dependencies in AI model development.
3 sources covering this story
Mercor Hit by LiteLLM Supply Chain Attack
The AI recruiting firm is investigating the incident as Lapsus$ claimed the theft of 4TB of Mercor data.
The Record from Recorded Future
Mercor confirms security incident tied to LiteLLM supply chain attack
Although the LiteLLM attack was reportedly tied to a group called TeamPCP, the hacking gang Lapsus$ claimed on its website that it obtained hundreds of gigabytes of Mercor’s data.
Mercor says it was hit by cyberattack tied to compromise of open source LiteLLM project | TechCrunch
The AI recruiting startup confirmed a security incident after an extortion hacking crew took credit for stealing data from the company's systems.
Part of the PlainSec briefing for 2026-04-05