• Home
  • Latest
  • Fortune 500
  • Finance
  • Tech
  • Leadership
  • Lifestyle
  • Rankings
  • Multimedia

Trendingnow

1

Former U.S. Secret Service agent says bringing your authentic self to work stifles teamwork: 'You don’t get high performers, you get sloppiness'

2

Current price of oil as of June 22, 2026

3

Current price of silver as of Monday, June 22, 2026

1

Former U.S. Secret Service agent says bringing your authentic self to work stifles teamwork: 'You don’t get high performers, you get sloppiness'

2

Current price of oil as of June 22, 2026

3

Current price of silver as of Monday, June 22, 2026
CybersecuritySecurity

Mercor, a $10 billion AI startup that works with companies including OpenAI and Anthropic, confirms major data breach

By
Beatrice Nolan
Beatrice Nolan
Tech Reporter
Down Arrow Button Icon
By
Beatrice Nolan
Beatrice Nolan
Tech Reporter
Down Arrow Button Icon
April 2, 2026, 3:00 PM ET
Image showing multiple computer screens with code.
AI recruiting startup Mercor was hit via a supply-chain cyberattack targeting LiteLLM.Getty Images
Add Fortune on Google for similar content.

Mercor, a startup that provides training data to major AI companies, confirmed that it was the victim of a security breach that may have exposed sensitive company and user data.

Recommended Video

The three-year-old startup, which is valued at $10 billion, recruits experts in fields ranging from medicine to law to literature, to help provide data that improves the capabilities of AI models. Its customers include Anthropic, OpenAI, and Meta.

According to unconfirmed reports circulating online, datasets used by some of Mercor’s customers and information about those customers’ secretive AI projects may have been compromised in the breach.

The incident was linked to a supply-chain attack involving LiteLLM, a widely used open-source library for connecting applications to AI services.

The company confirmed to Fortune it was “one of thousands of companies” affected by the supply-chain attack on LiteLLM, which has been linked to a hacking group called TeamPCP. Mercor spokesperson Heidi Hagberg said that the company had “moved promptly” to contain and remediate the incident and said a third-party forensics investigation was underway.

“The privacy and security of our customers and contractors is foundational to everything we do at Mercor,” Hagberg said. “We will continue to communicate with our customers and contractors directly as appropriate and devote the resources necessary to resolving the matter as soon as possible.”

Mercor is widely considered one of Silicon Valley’s hottest startups, having raised $350 million in a Series C round led by venture capital firm Felicis Ventures last October. 

The TeamPCP hacking group planted malicious code inside LiteLLM, a tool used by developers to plug their applications into AI services from companies including OpenAI and Anthropic, that is typically downloaded millions of times per day, according to security firm Snyk. The code was designed to harvest credentials and spread widely across the industry before it was identified and removed within hours of discovery.

Lapsus$, a notorious extortion hacking gang, later claimed it had targeted Mercor and accessed its data. It’s not immediately clear how the gang obtained the data, and Mercor did not respond to specific questions from Fortune about the hacking group’s claims. TeamPCP is thought to have recently begun collaborating with Lapsus$ as well as other groups that specialize in ransomware and extortion, according to security researchers from the cybersecurity firm Wiz quoted in a story in Infosecurity Magazine.

TeamPCP is known for engineering so-called supply-chain attacks, in which malware is planted inside codebases or software libraries that are widely used by programmers when writing their own code. Lapsus$, by contrast, is an older hacking group, known for social engineering and phishing attacks that focus on stealing user log-in credentials and then using those credentials to gain access to and steal sensitive data.

Lapsus$ has published samples of allegedly stolen data on its leak site, according to TechCrunch, including what appeared to be Slack data, internal ticketing information, and two videos purportedly showing conversations between Mercor’s AI systems and contractors on its platform. Lapsus$ claims to have obtained as much as four terabytes of data in total, including source code and database records. A single terabyte constitutes approximately as much data as is found in 1,000 hours of video or 1,000 copies of the Encyclopedia Britannica.

Mercor may be an early indicator of a coming wave of extortion attempts stemming from the supply-chain attack. TeamPCP has publicly stated its intention to partner with ransomware and extortion groups to target affected companies at scale, according to cybersecurity trade publication Cybernews. If true, that strategy would mirror campaigns carried out in the past by hacking groups.

In 2023, an attack from the Cl0p ransomware gang that exploited a vulnerability in MOVEit, a widely used file transfer tool, breached hundreds of organizations simultaneously, ultimately affecting nearly 100 million individuals across government agencies, financial institutions, and health care providers. Extortion attempts from that campaign dragged on for months.

Subscribe to Fortune Gulf Brief. Every Tuesday, this new newsletter delivers clear-eyed, authoritative intelligence on the deals, decisions, policies, and power shifts shaping one of the world’s most consequential regions, written for the people who need to act on it. Sign up here.
About the Author
By Beatrice NolanTech Reporter
Twitter icon

Beatrice Nolan is a tech reporter on Fortune’s AI team, covering artificial intelligence and emerging technologies and their impact on work, industry, and culture. She's based in Fortune's London office and holds a bachelor’s degree in English from the University of York. You can reach her securely via Signal at beatricenolan.08

See full bioRight Arrow Button Icon
Add Fortune on Google for similar content.

Latest in Cybersecurity

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025

Most Popular

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Fortune Secondary Logo
Rankings
  • 100 Best Companies
  • Fortune 500
  • Global 500
  • Fortune 500 Europe
  • Most Powerful Women
  • World's Most Admired Companies
  • See All Rankings
  • Lists Calendar
Sections
  • Finance
  • Fortune Crypto
  • Features
  • Leadership
  • Health
  • Commentary
  • Success
  • Retail
  • Mpw
  • Tech
  • Lifestyle
  • CEO Initiative
  • Asia
  • Politics
  • Conferences
  • Europe
  • Newsletters
  • Personal Finance
  • Environment
  • Magazine
  • Education
Customer Support
  • Frequently Asked Questions
  • Customer Service Portal
  • Privacy Policy
  • Terms Of Use
  • Single Issues For Purchase
  • International Print
Commercial Services
  • Advertising
  • Fortune Brand Studio
  • Fortune Analytics
  • Fortune Conferences
  • Business Development
  • Group Subscriptions
About Us
  • About Us
  • Press Center
  • Work At Fortune
  • Terms And Conditions
  • Site Map
  • About Us
  • Press Center
  • Work At Fortune
  • Terms And Conditions
  • Site Map
  • Facebook icon
  • Twitter icon
  • LinkedIn icon
  • Instagram icon
  • Pinterest icon

Latest in Cybersecurity

ravi
CommentaryAI agents
Yale School of Management: surveillance pricing is just the beginning. AI agents will be the real test of corporate trust
By Ravi Dhar and Jon IwataJune 23, 2026
2 hours ago
SpaceX and Tesla founder Elon Musk
InvestingElon Musk
SpaceX’s drop-off sees Elon Musk’s net worth fall $240 billion—roughly the same value as computing giant IBM
By Eleanor PringleJune 23, 2026
2 hours ago
d
EnvironmentConsumer electronics
Almost 4 in 10 Americans have a ‘junk drawer’ full of their old electronics. It’s because of a very specific anxiety
By Eric Williams, Payam Saeedi, Stacey Watson and The ConversationJune 21, 2026
2 days ago
zak
CybersecuritySocial Media
The U.K. just banned social media for kids under 16. The founder of ‘safe TikTok’ says the U.S. is next
By Nick LichtenbergJune 21, 2026
2 days ago
p
CommentaryInternet
GoDaddy Corporate Domains chief: The next Internet land rush is happening right now
By Phil LodicoJune 20, 2026
3 days ago
The week that changed AI: Inside Trump’s Anthropic crackdown, and how a phone call from Amazon CEO Andy Jassy triggered the chaos
AIAnthropic
The week that changed AI: Inside Trump’s Anthropic crackdown, and how a phone call from Amazon CEO Andy Jassy triggered the chaos
By Sebastian Herrera and Beatrice NolanJune 18, 2026
5 days ago

Most Popular

Former U.S. Secret Service agent says bringing your authentic self to work stifles teamwork: 'You don’t get high performers, you get sloppiness'
Success
Former U.S. Secret Service agent says bringing your authentic self to work stifles teamwork: 'You don’t get high performers, you get sloppiness'
By Sydney LakeJune 21, 2026
2 days ago
Current price of oil as of June 22, 2026
Personal Finance
Current price of oil as of June 22, 2026
By Joseph HostetlerJune 22, 2026
1 day ago
Current price of silver as of Monday, June 22, 2026
Personal Finance
Current price of silver as of Monday, June 22, 2026
By Joseph HostetlerJune 22, 2026
1 day ago
The Fed is fed up with inflation and will bring down the hammer with a series of rate hikes this year, reversing earlier cuts, BofA says
Economy
The Fed is fed up with inflation and will bring down the hammer with a series of rate hikes this year, reversing earlier cuts, BofA says
By Jason MaJune 22, 2026
21 hours ago
NBC’s Tom Llamas climbed from 15-year-old intern to the top anchor chair—and still isn’t satisfied: ‘If you're not growing, you're dying'
Success
NBC’s Tom Llamas climbed from 15-year-old intern to the top anchor chair—and still isn’t satisfied: ‘If you're not growing, you're dying'
By Preston ForeJune 21, 2026
2 days ago
By 7 a.m., Bank of America’s CEO has already read 5 newspapers, his email inbox, and hit the gym—he says if you’re late to meetings, you’re ‘selfish’
Success
By 7 a.m., Bank of America’s CEO has already read 5 newspapers, his email inbox, and hit the gym—he says if you’re late to meetings, you’re ‘selfish’
By Preston ForeJune 22, 2026
22 hours ago

© 2026 Fortune Media IP Limited. All Rights Reserved. Use of this site constitutes acceptance of our Terms of Use and Privacy Policy | CA Notice at Collection and Privacy Notice | Do Not Sell/Share My Personal Information
FORTUNE is a trademark of Fortune Media IP Limited, registered in the U.S. and other countries. FORTUNE may receive compensation for some links to products and services on this website. Offers may be subject to change without notice.