Connect with us

Hi, what are you looking for?

Top Stories

Mercor Cyberattack Linked to LiteLLM Compromise; Meta Suspends Collaboration

Mercor confirms a security breach linked to LiteLLM, affecting thousands of firms and prompting Meta to suspend collaboration amidst potential extortion threats.

Artificial intelligence recruiting startup Mercor confirmed it was the target of a security incident linked to the open-source tool LiteLLM. The incident, which occurred recently, reportedly impacted thousands of firms, with the compromised tool attributed to a hacking group known as TeamPCP.

According to media reports, the extortion group Lapsus$ has claimed responsibility, releasing samples of stolen data on its leak site. This data includes internal Slack messages, ticket records, and videos showcasing interactions between Mercor’s AI and contractors. As of now, the specifics of how Lapsus$ acquired the data during the breach remain uncertain.

In response to the incident, Mercor stated that the malicious code was quickly detected and removed. However, the breach has raised eyebrows given LiteLLM’s extensive usage, with millions of daily downloads, as noted by cybersecurity firm Snyk. Following the incident, LiteLLM has reinforced its compliance measures by transitioning from the compliance startup Delve to Vanta for its certifications.

Founded in 2023, Mercor connects various companies, including heavyweights like OpenAI, Meta, and Anthropic, with domain experts such as scientists, doctors, and lawyers, primarily sourced from India. The platform has been processing over $2 million in daily payouts, and it reached a valuation of $10 billion after a $350 million Series C funding round led by Felicis Ventures in October 2022.

In the wake of the breach, Meta has paused its collaboration with Mercor and is conducting its own investigation, although no timeline for resuming work has been provided, as reported by Wired. Other AI firms are also reassessing their engagements as they evaluate the impact of the incident.

Mercor emphasized its commitment to security, stating, “Our security team moved promptly to contain and remediate the incident.” The company is conducting a thorough investigation with the support of leading third-party forensic experts, according to a statement cited by Business Insider.

Security analysts warn that Mercor may be an early target in a broader wave of extortion attempts stemming from the LiteLLM security breach. TeamPCP has indicated plans to collaborate with ransomware groups to target additional affected companies, a tactic that mirrors patterns observed in previous large-scale cyberattacks, according to Cybernews.

This incident highlights the vulnerabilities within the technology landscape, particularly as reliance on open-source tools grows. As companies increasingly integrate AI solutions into their operations, the potential for cyber threats escalates, necessitating robust security measures and vigilant oversight. The ramifications of the Mercor breach may resonate throughout the industry, prompting heightened scrutiny and a reevaluation of cybersecurity practices across technology firms.

See also
Staff
Written By

The AiPressa Staff team brings you comprehensive coverage of the artificial intelligence industry, including breaking news, research developments, business trends, and policy updates. Our mission is to keep you informed about the rapidly evolving world of AI technology.

You May Also Like

AI Cybersecurity

Meta has suspended all collaborations with Mercor after a major AI data breach compromised sensitive datasets, prompting industry-wide reevaluations of security practices.

AI Education

Speechify launches on-device Voice AI for over 1 billion Windows users, enhancing productivity with seamless text-to-speech and voice typing across multiple applications.

AI Regulation

LiteLLM, a popular open-source AI project with 3.4 million daily downloads, faces a malware scandal after serious security breaches despite holding SOC 2 and...

AI Tools

SentinelOne and Snyk unveil advanced AI security tools, including Prompt AI Agent Security, to tackle growing cyber risks and enhance data protection for AI...

AI Business

Salesforce partners with NVIDIA to integrate AI agents into business workflows, leveraging the Nemotron 3 Nano's 1M token context for enhanced operational efficiency.

AI Cybersecurity

Nightfall AI secures $32M investment to revolutionize data loss prevention for remote work, capturing over 20% ownership and addressing urgent cybersecurity challenges.

AI Business

Barndoor.ai unveils Venn.ai, empowering businesses to seamlessly integrate AI with tools like Salesforce and Google Docs while ensuring user security and oversight.

AI Research

Humans& secures $480M and achieves a Level 3 rating on TechCrunch's new scale, while Thinking Machines Lab faces turmoil after losing half its founding...

© 2025 AIPressa · Part of Buzzora Media · All rights reserved. This website provides general news and educational content for informational purposes only. While we strive for accuracy, we do not guarantee the completeness or reliability of the information presented. The content should not be considered professional advice of any kind. Readers are encouraged to verify facts and consult appropriate experts when needed. We are not responsible for any loss or inconvenience resulting from the use of information on this site. Some images used on this website are generated with artificial intelligence and are illustrative in nature. They may not accurately represent the products, people, or events described in the articles.