Mercor faces cyberattack linked to LiteLLM supply chain compromise.
Article excerpt
Highlighted: the sentence this signal was extracted from
Mercor faces cyberattack linked to LiteLLM supply chain compromise. News summary. Mercor, an AI recruiting startup, confirmed a security breach due to a supply chain attack involving the open-source LiteLLM project, which was compromised by a hacking group called TeamPCP. The incident also saw the extortion group Lapsus$ claim responsibility for targeting Mercor and accessing its data. Founded in 2023, Mercor partners with companies like OpenAI and Anthropic to provide domain experts for AI model training. The startup, valued at $10 billion after a Series C funding round, handles over $2 million in daily payouts. Mercor is actively investigating the breach with third-party forensics experts. The LiteLLM project, backed by Y Combinator, had its malicious code swiftly removed, drawing significant scrutiny due to its extensive use. The incident led to compliance process changes within LiteLLM.
