Mercor AI Confirms Data Breach Following Lapsus$ Claims of 4TB Data Theft
ID: 2d1eed8a-a4ed-5be2-adbe-768b0ce329e2
STIX ID: report--2d1eed8a-a4ed-5be2-adbe-768b0ce329e2
Feed Name: cybersecurityNews.com
Threat Score
Mercor AI confirmed a major breach after the Lapsus$ group claimed to have stolen 4 TB of data following a supply-chain compromise of the open-source LiteLLM PyPI package; a malicious three-stage backdoor (introduced by actor TeamPCP in LiteLLM v1.82.7/1.82.8) reportedly harvested credentials, enabled persistent access, and led to exfiltration of platform source code, a 211 GB user database, and 3 TB of KYC/video assets, which are now being auctioned on the dark web.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
