Mercor's whole business is using AI to judge job candidates — so you'd expect it to guard the data people trust it with. Instead, a criminal crew stole 4 terabytes of its files: source code, candidate data, the works. They didn't pick the lock on Mercor's door — they slipped in through a popular free tool called LiteLLM that thousands of AI companies all rely on. One poisoned update quietly spread, and everyone who trusted it got robbed at once.
Why that's a big deal: Mercor's defense was "we weren't targeted, we were just collateral." That's not comforting — it means the weak spot is the entire shared plumbing of AI, and any company built on these borrowed tools is one bad update away from the same call.
So how does it touch you? If you ever applied for a job through a service like this, your personal information could be in that stolen pile — now being auctioned to the highest bidder. And nobody was watching the tools that held it.
