All Incidents
An Extortion Crew Stole 4 Terabytes From an AI Recruiting Firm. The Attack Came Through a Tool Nobody Was Watching.
BreakingAPR 1, 2026SECURITY FAILURE

An Extortion Crew Stole 4 Terabytes From an AI Recruiting Firm. The Attack Came Through a Tool Nobody Was Watching.

Mercor is an AI recruiting startup. Its job is to evaluate candidates using artificial intelligence. Its source code, its candidate data, its infrastructure — 4 terabytes of it — was stolen by an extortion crew that got in through a compromised open source project called LiteLLM. Mercor says it was "one of thousands" of companies hit the same way.

Here is what happened. A tool that thousands of AI companies depend on to route calls between AI models was compromised at the source. A malicious update. Nobody caught it. The update propagated across the ecosystem automatically. The attackers walked in through the front door of every company that trusted the dependency without verifying it.

Mercor's response: we were not specifically targeted. We were collateral damage in a supply chain attack. That is supposed to be reassuring. It is not. It means the attack surface is the entire AI infrastructure stack. It means every company running AI tools built on open source dependencies is one compromised package away from the same call.

4 terabytes. 939 gigabytes of source code alone. Now being auctioned to the highest bidder. And the AI company whose entire product is evaluating human judgment had no human in the loop watching the tools it trusted to run its own systems.

HOFFICIALHITL Score
HITL Score0/100
Why this matters to youNo jargon — just what it means

Mercor's whole business is using AI to judge job candidates — so you'd expect it to guard the data people trust it with. Instead, a criminal crew stole 4 terabytes of its files: source code, candidate data, the works. They didn't pick the lock on Mercor's door — they slipped in through a popular free tool called LiteLLM that thousands of AI companies all rely on. One poisoned update quietly spread, and everyone who trusted it got robbed at once.

Why that's a big deal: Mercor's defense was "we weren't targeted, we were just collateral." That's not comforting — it means the weak spot is the entire shared plumbing of AI, and any company built on these borrowed tools is one bad update away from the same call.

So how does it touch you? If you ever applied for a job through a service like this, your personal information could be in that stolen pile — now being auctioned to the highest bidder. And nobody was watching the tools that held it.

🖤 Explained by Babycakes.
Read the full source →
Source: TECHCRUNCH / THE REGISTER