2026 Mercor — Lapsus$ ~4TB claim; Mercor cites LiteLLM supply chain; scope under forensics
Data compromised
Potentially source code, internal collaboration data, database segments, contractor/resume and media files—scope per ongoing investigation and unverified actor claims
Technical writeup
On March 31, 2026, the extortion group Lapsus$ claimed a large breach of Mercor, an AI expert-hiring and evaluation platform, alleging roughly four terabytes of data taken (some roundups cited ~1 TB in aggregate claims—figures vary by source and should be treated as unverified until forensics confirm). Summaries cited source code, database material (e.g., resumes), and large file stores (some reporting referenced video interviews and identity-style documents). Mercor confirmed to TechCrunch a security incident tied to the broader March 2026 compromise of the open-source LiteLLM project (TeamPCP-style supply-chain malware), describing itself as one of many affected organizations and noting forensic investigation; the company did not in initial statements fully corroborate every volume or category claimed on extortion channels. Additional trade reporting described alleged Tailscale VPN access as part of actor narratives. Public victim counts were not finalized at early disclosure. Late March 2026 tech-security discourse often grouped Mercor with adjacent stories (e.g., Claude Code npm source-map exposure, Axios npm compromise, LiteLLM supply chain) as part of a concentrated AI/dev-tooling incident cluster. May 31, 2026 leak-site monitors also re-listed Mercor under Lapsus$ with acquisition-only messaging (no new public leak planned per OSINT summaries)—treated as follow-on to the March 2026 incident unless a separate disclosure emerges.
Root cause
Cyberattack; extortion claims; company-linked supply-chain context (LiteLLM compromise per Mercor); technical path under investigation
References
- https://techcrunch.com/2026/03/31/mercor-says-it-was-hit-by-cyberattack-tied-to-compromise-of-open-source-litellm-project/
- https://techstartups.com/2026/03/31/lapsus-claims-massive-breach-of-ai-hiring-startup-mercor-says-4tb-of-data-taken-via-tailscale-vpn/
- https://fortune.com/2026/04/02/mercor-ai-startup-security-incident-10-billion/