Mercor AI Confirms Data Theft via LiteLLM Supply Chain Breach

Mercor AI, an AI recruiting startup, publicly confirmed it was breached through the LiteLLM supply chain compromise linked to the TeamPCP cybercriminal group. The attackers used compromised credentials from the supply chain phase to access Mercor's cloud environment, enabling extensive post-compromise enumeration and exfiltration of 4TB of data. The stolen data includes source code, user databases, and biometric identity documents, raising privacy and regulatory risks under GDPR, CCPA, and possibly HIPAA. This confirmation moves the TeamPCP campaign from theoretical risk to confirmed operational impact. Public threat intelligence sources currently show no TeamPCP indicators, complicating detection and response. The stolen credentials and sensitive data enable future intrusions without requiring new supply chain exploits, changing the threat model for affected organizations.

Part of the PlainSec briefing for 2026-04-02

Sources