logo

AI Firm Mercor Confirms Breach as Hackers Claim 4TB of Stolen Data

ID: e3c64784-ea42-5ca0-9fe6-b67579fe8206

STIX ID: report--e3c64784-ea42-5ca0-9fe6-b67579fe8206

Feed Name: HackRead

Threat Score
88/100

Date Published: 2026-04-03

Date Updated: 2026-04-22

Author: Deeba Ahmed

...
...

Mercor confirmed it was affected by a late-March-2026 supply-chain compromise of the LiteLLM PyPI package, where attackers published malicious package versions for roughly 40 minutes; researchers warn of wide exposure due to millions of downloads and LiteLLM's presence in ~36% of cloud environments, and extortion group Lapsus$ subsequently listed Mercor claiming a 4TB data theft (unverified).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.