Mercor
Profile
Organisation tracking is available to eligible accounts.
Profile narrative
Mercor is an AI‑focused recruiting startup that provides a platform using artificial intelligence to source, screen and match candidates for employers. The company has been described as a ten‑billion‑dollar valued business, indicating a significant market presence and investor confidence. Its core service leverages proprietary AI models to automate parts of the hiring pipeline, including video interview analysis and skills assessment. Mercor operates primarily in the technology and professional services sectors, serving clients that seek data‑driven talent acquisition solutions. The firm’s positioning as a high‑value AI recruiter distinguishes it from traditional staffing agencies and many earlier‑stage AI hiring tools. Its reliance on open‑source components, such as the LiteLLM library, is a notable aspect of its technical stack.
In March 2026 Mercor disclosed a data breach after attackers compromised a malicious version of the LiteLLM library, exfiltrating roughly four terabytes of data that included personal information, source code, video interviews and proprietary AI training details. The breach prompted multiple class‑action lawsuits, led Meta to suspend its collaboration with Mercor and triggered investigations by OpenAI and other AI laboratories, while the hacking group Lapsus$ claimed responsibility and offered the stolen data for sale. A prior incident in April 2025 involved malicious code injected into the same LiteLLM library, a flaw identified by Snyk researchers that allowed threat actors to access internal systems and exfiltrate Slack messages, ticketing data, video recordings, contractor credentials, payment details and additional AI training information. Lapsus$ also claimed responsibility for that earlier breach, with investigators linking the initial compromise to the group TeamPCP, and Mercor engaged third‑party forensics experts to investigate both events. These incidents highlight the supply‑chain risks associated with the company’s use of open‑source software and have become part of its public record.
Incidents
2 incidents linked to this organisation.