Mercor, an AI hiring and recruiting startup, experienced a data breach stemming from a supply-chain compromise of the LiteLLM project in April 2026. Reports indicate that the Lapsus$ group exfiltrated approximately 4 TB of data. While Mercor has acknowledged being among the thousands of companies affected by the LiteLLM compromise, a formal breach notice or an official incident statement from Mercor has not been publicly released.
The exfiltrated data reportedly includes source code, a 211 GB user database, and 3 TB of storage containing video interviews and passport scans for more than 30,000 contractors. It remains unclear if any other types of data, such as medical records, financial data, or Social Security numbers, were compromised, as the available sources do not confirm their exposure. No specific states affected by this breach have been identified in the available information.
More details about the full scope and impact of this data breach may emerge in the future, as official notifications can sometimes be delayed.