• Home
  • Latest
  • Fortune 500
  • Finance
  • Tech
  • Leadership
  • Lifestyle
  • Rankings
  • Multimedia

Trendingnow

1

Erin Brockovich, the activist who defeated a utility giant and inspired a Julia Roberts film, is pushing data centers to be more transparent

2

Social Security unraveling: 7,100 workers sacked, performance metrics retired, disability claims falling

3

'Where we are today is frightening': a Pulitzer-winning historian sees a doomsday scenario involving China and the national debt

1

Erin Brockovich, the activist who defeated a utility giant and inspired a Julia Roberts film, is pushing data centers to be more transparent

2

Social Security unraveling: 7,100 workers sacked, performance metrics retired, disability claims falling

3

'Where we are today is frightening': a Pulitzer-winning historian sees a doomsday scenario involving China and the national debt
CybersecuritySecurity

Mercor, a $10 billion AI startup that works with companies including OpenAI and Anthropic, confirms major data breach

By
Beatrice Nolan
Beatrice Nolan
Tech Reporter
Down Arrow Button Icon
By
Beatrice Nolan
Beatrice Nolan
Tech Reporter
Down Arrow Button Icon
April 2, 2026, 3:00 PM ET
Image showing multiple computer screens with code.
AI recruiting startup Mercor was hit via a supply-chain cyberattack targeting LiteLLM.Getty Images

Mercor, a startup that provides training data to major AI companies, confirmed that it was the victim of a security breach that may have exposed sensitive company and user data.

Recommended Video

The three-year-old startup, which is valued at $10 billion, recruits experts in fields ranging from medicine to law to literature, to help provide data that improves the capabilities of AI models. Its customers include Anthropic, OpenAI, and Meta.

According to unconfirmed reports circulating online, datasets used by some of Mercor’s customers and information about those customers’ secretive AI projects may have been compromised in the breach.

The incident was linked to a supply-chain attack involving LiteLLM, a widely used open-source library for connecting applications to AI services.

The company confirmed to Fortune it was “one of thousands of companies” affected by the supply-chain attack on LiteLLM, which has been linked to a hacking group called TeamPCP. Mercor spokesperson Heidi Hagberg said that the company had “moved promptly” to contain and remediate the incident and said a third-party forensics investigation was underway.

“The privacy and security of our customers and contractors is foundational to everything we do at Mercor,” Hagberg said. “We will continue to communicate with our customers and contractors directly as appropriate and devote the resources necessary to resolving the matter as soon as possible.”

Mercor is widely considered one of Silicon Valley’s hottest startups, having raised $350 million in a Series C round led by venture capital firm Felicis Ventures last October. 

The TeamPCP hacking group planted malicious code inside LiteLLM, a tool used by developers to plug their applications into AI services from companies including OpenAI and Anthropic, that is typically downloaded millions of times per day, according to security firm Snyk. The code was designed to harvest credentials and spread widely across the industry before it was identified and removed within hours of discovery.

Lapsus$, a notorious extortion hacking gang, later claimed it had targeted Mercor and accessed its data. It’s not immediately clear how the gang obtained the data, and Mercor did not respond to specific questions from Fortune about the hacking group’s claims. TeamPCP is thought to have recently begun collaborating with Lapsus$ as well as other groups that specialize in ransomware and extortion, according to security researchers from the cybersecurity firm Wiz quoted in a story in Infosecurity Magazine.

TeamPCP is known for engineering so-called supply-chain attacks, in which malware is planted inside codebases or software libraries that are widely used by programmers when writing their own code. Lapsus$, by contrast, is an older hacking group, known for social engineering and phishing attacks that focus on stealing user log-in credentials and then using those credentials to gain access to and steal sensitive data.

Lapsus$ has published samples of allegedly stolen data on its leak site, according to TechCrunch, including what appeared to be Slack data, internal ticketing information, and two videos purportedly showing conversations between Mercor’s AI systems and contractors on its platform. Lapsus$ claims to have obtained as much as four terabytes of data in total, including source code and database records. A single terabyte constitutes approximately as much data as is found in 1,000 hours of video or 1,000 copies of the Encyclopedia Britannica.

Mercor may be an early indicator of a coming wave of extortion attempts stemming from the supply-chain attack. TeamPCP has publicly stated its intention to partner with ransomware and extortion groups to target affected companies at scale, according to cybersecurity trade publication Cybernews. If true, that strategy would mirror campaigns carried out in the past by hacking groups.

In 2023, an attack from the Cl0p ransomware gang that exploited a vulnerability in MOVEit, a widely used file transfer tool, breached hundreds of organizations simultaneously, ultimately affecting nearly 100 million individuals across government agencies, financial institutions, and health care providers. Extortion attempts from that campaign dragged on for months.

In 2001, Fortune first convened the smartest people we know, bringing together CEOs and founders, builders and investors, thinkers and doers. Since then, Fortune Brainstorm Tech has been the place where bold ideas collide. From June 8–10, we will return to Aspen—where it all began—to mark 25 years of Brainstorm. Register now.
About the Author
By Beatrice NolanTech Reporter
Twitter icon

Beatrice Nolan is a tech reporter on Fortune’s AI team, covering artificial intelligence and emerging technologies and their impact on work, industry, and culture. She's based in Fortune's London office and holds a bachelor’s degree in English from the University of York. You can reach her securely via Signal at beatricenolan.08

See full bioRight Arrow Button Icon

Latest in Cybersecurity

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025

Most Popular

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Fortune Secondary Logo
Rankings
  • 100 Best Companies
  • Fortune 500
  • Global 500
  • Fortune 500 Europe
  • Most Powerful Women
  • World's Most Admired Companies
  • See All Rankings
  • Lists Calendar
Sections
  • Finance
  • Fortune Crypto
  • Features
  • Leadership
  • Health
  • Commentary
  • Success
  • Retail
  • Mpw
  • Tech
  • Lifestyle
  • CEO Initiative
  • Asia
  • Politics
  • Conferences
  • Europe
  • Newsletters
  • Personal Finance
  • Environment
  • Magazine
  • Education
Customer Support
  • Frequently Asked Questions
  • Customer Service Portal
  • Privacy Policy
  • Terms Of Use
  • Single Issues For Purchase
  • International Print
Commercial Services
  • Advertising
  • Fortune Brand Studio
  • Fortune Analytics
  • Fortune Conferences
  • Business Development
  • Group Subscriptions
About Us
  • About Us
  • Press Center
  • Work At Fortune
  • Terms And Conditions
  • Site Map
  • About Us
  • Press Center
  • Work At Fortune
  • Terms And Conditions
  • Site Map
  • Facebook icon
  • Twitter icon
  • LinkedIn icon
  • Instagram icon
  • Pinterest icon

Latest in Cybersecurity

coo
ConferencesCOO Summit
The $18 expense report and the defunded intern programs: symbols of corporate America’s dysfunction
By Nick LichtenbergJune 2, 2026
12 hours ago
Sid Kosaraju, President, Crisis24 (confirmed) Jacob Silverman, Chief Executive Officer, Kroll (confirmed) (June 1 only) Moderator: Ruth Umo
ConferencesCOO Summit
Grey rhinos, black swans, and the kidnapping of Nancy Guthrie: What Corporate America still gets wrong about risk
By Nick LichtenbergJune 1, 2026
1 day ago
Malaysia bans children under 16 from using social media
AsiaSocial Media
Malaysia bans children under 16 from using social media
By The Associated Press and Eileen NgJune 1, 2026
2 days ago
How to save the internet—according to Sam Altman’s all-seeing Orb  
EuropeEurope
How to save the internet—according to Sam Altman’s all-seeing Orb  
By Sam BirchallJune 1, 2026
2 days ago
Russian spies are more aggressively trying to steal Western technology as sanctions add to mounting problems for Putin’s wartime economy
EuropeRussia
Russian spies are more aggressively trying to steal Western technology as sanctions add to mounting problems for Putin’s wartime economy
By Emma Burrows and The Associated PressMay 30, 2026
4 days ago
ts
CybersecurityLaw
Taylor Swift just exposed a blind spot in AI law — and it’s bigger than copyright
By Daryl Lim and The ConversationMay 30, 2026
4 days ago

Most Popular

Erin Brockovich, the activist who defeated a utility giant and inspired a Julia Roberts film, is pushing data centers to be more transparent
Environment
Erin Brockovich, the activist who defeated a utility giant and inspired a Julia Roberts film, is pushing data centers to be more transparent
By Marco Quiroz-GutierrezJune 1, 2026
2 days ago
Social Security unraveling: 7,100 workers sacked, performance metrics retired, disability claims falling
North America
Social Security unraveling: 7,100 workers sacked, performance metrics retired, disability claims falling
By Katie Savin, Callie Freitag, Matthew Borus and The ConversationJune 2, 2026
20 hours ago
'Where we are today is frightening': a Pulitzer-winning historian sees a doomsday scenario involving China and the national debt
Banking
'Where we are today is frightening': a Pulitzer-winning historian sees a doomsday scenario involving China and the national debt
By Nick LichtenbergJune 2, 2026
23 hours ago
The Iran conflict has disrupted oil supply. Gulf states are now looking to multi-billion-dollar investments in renewables 
Energy
The Iran conflict has disrupted oil supply. Gulf states are now looking to multi-billion-dollar investments in renewables 
By Melissa HancockJune 1, 2026
2 days ago
Cognizant CEO is swimming against the tide on AI: he's hiring over 20,000 graduates this year and says AI tokenmaxxing is a 'vanity metric'
Conferences
Cognizant CEO is swimming against the tide on AI: he's hiring over 20,000 graduates this year and says AI tokenmaxxing is a 'vanity metric'
By Preston ForeJune 1, 2026
1 day ago
Trump tells Netanyahu, 'You're f—ing crazy' and Wall Street sees it as a sign he’s losing patience with the war and wants it done
Investing
Trump tells Netanyahu, 'You're f—ing crazy' and Wall Street sees it as a sign he’s losing patience with the war and wants it done
By Jim EdwardsJune 2, 2026
23 hours ago

© 2026 Fortune Media IP Limited. All Rights Reserved. Use of this site constitutes acceptance of our Terms of Use and Privacy Policy | CA Notice at Collection and Privacy Notice | Do Not Sell/Share My Personal Information
FORTUNE is a trademark of Fortune Media IP Limited, registered in the U.S. and other countries. FORTUNE may receive compensation for some links to products and services on this website. Offers may be subject to change without notice.