Policy3 min read
Mercor Confirms Data Breach Via LiteLLM Supply Chain Attack — A Warning Shot for AI Infrastructure Security
AI recruiting startup Mercor has confirmed a cyberattack tied to a compromise of the widely-used open-source LiteLLM gateway project, with a Lapsus$-affiliated extortion crew claiming responsibility — exposing a critical security gap in the AI startup ecosystem's reliance on shared open-source infrastructure.