AI Firm Mercor Confirms Breach as Hackers Claim 4TB of Stolen Data
ID: e3c64784-ea42-5ca0-9fe6-b67579fe8206
STIX ID: report--e3c64784-ea42-5ca0-9fe6-b67579fe8206
Feed Name: HackRead
Threat Score
Mercor confirmed it was affected by a late-March-2026 supply-chain compromise of the LiteLLM PyPI package, where attackers published malicious package versions for roughly 40 minutes; researchers warn of wide exposure due to millions of downloads and LiteLLM's presence in ~36% of cloud environments, and extortion group Lapsus$ subsequently listed Mercor claiming a 4TB data theft (unverified).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
