If you worked with Mercor to train AI models, your data may be compromised
Mercor is one of those companies that most people outside the AI industry have never heard of, but it's deeply embedded in how the most powerful AI models in the world get trained. Founded in 2023 and valued at $10 billion — extraordinary for a three-year-old company — Mercor connects AI companies including OpenAI and Anthropic with specialized human contractors: doctors, lawyers, scientists, engineers, subject-matter experts across dozens of fields. These contractors review AI outputs, provide expert feedback, and generate specialized training data that teaches models how to reason about medicine, law, science, and other complex domains.
Mercor operates across multiple markets, with India being one of its significant contractor bases. Indian doctors, lawyers, and technical experts have been part of Mercor's workforce providing this AI training expertise. Which is exactly why this security breach is particularly relevant for Indian professionals who may have been part of that system.
Mercor has now confirmed it was hit by a security breach. Two hacking groups are involved. The data potentially stolen includes contractor credentials, professional information, and internal company data. Here's what happened and what it means.
The LiteLLM supply chain attack — how the breach started
The breach originated not with Mercor itself, but with an open-source tool called LiteLLM. To understand why this matters, you need to understand what a supply chain attack is.
A supply chain attack works like this: instead of attacking a company directly — which is hard when the company has good security — attackers find a widely-used software library or tool that the target company depends on, and infect that tool. When the company updates or installs the infected tool, the malware comes with it. It's the software equivalent of poisoning the water supply rather than attacking individual homes.
LiteLLM is a tool used by developers to connect their applications to AI services from providers like OpenAI and Anthropic. It's enormously popular — downloaded millions of times per day. A hacking group called TeamPCP planted malicious code inside LiteLLM to extract and harvest credentials from any system that installed the compromised version. The malicious code was identified and removed within hours, but by that point it had already spread widely across the industry. Mercor was one of thousands of companies affected.
Lapsus$ enters the picture
The Mercor story gets more complicated because a second hacking group got involved. Lapsus$ — a cybercrime group with a significant history of high-profile breaches — claimed responsibility for specifically targeting Mercor on its leak site.
Lapsus$ is notable for a few reasons. Unlike purely financially motivated hacking groups, Lapsus$ often publicizes its attacks aggressively, sharing stolen data samples to prove the breach and create leverage for extortion. The group has previously breached companies including Microsoft, Samsung, Nvidia, Uber, and Rockstar Games. Their typical approach involves social engineering — tricking employees into giving up login credentials or access — combined with phishing attacks.
What Lapsus$ posted as a sample of the stolen Mercor data included material from Slack communications, ticketing system data, and two videos purportedly showing conversations between Mercor's AI systems and contractors on the platform. The relationship between the TeamPCP LiteLLM attack and Lapsus$'s claims isn't fully clear — it's possible Lapsus$ obtained the data through the supply chain attack, conducted their own separate breach, or acquired the data from TeamPCP. The investigation is ongoing.
What data was stolen — the full picture
The confirmed and alleged stolen data is extensive. On the company side: source code, internal Slack communications, database records, and ticketing system information. On the contractor side — which is where Indian professionals come in — the exposure is more personal: professional credentials, payment information, government ID documents that contractors submitted during verification, biometric data collected during interview processes, resumes and work history, and work activity tracking data.
Additionally, proprietary AI training data and confidential client information related to partnerships with OpenAI and Anthropic may have been exposed. The videos in the leaked sample showing contractor-AI interactions are particularly significant because they reveal the actual methodology of how AI training was being conducted — which is commercially sensitive information for both Mercor and its clients.
The total alleged data volume from Lapsus$ is 4TB. That's a large enough dataset to contain detailed records on a significant number of contractors and company operations.
Why Indian contractors specifically should be concerned
India is one of Mercor's key operating markets. Mercor specifically recruited Indian professionals — doctors, lawyers, software engineers, academics — to provide expert training data for AI models. The pitch was appealing: high-paying remote work using your professional expertise, contributing to frontier AI development.
If you participated in this work, the data Mercor held about you is potentially very sensitive. Government ID documents for verification — meaning Aadhaar, PAN, or passport information. Bank account or payment details for receiving compensation. Biometric data from interview processes. Your professional credentials and background. Work activity logs showing what you worked on.
In India, this combination of data — government IDs, biometrics, payment info — is the type that can be used for identity fraud, financial fraud, and creating fraudulent documents. Anyone who worked with Mercor as a contractor should monitor their financial accounts for unusual activity, be alert to phishing attempts that reference their Mercor work history, and consider whether any documents submitted to Mercor need to be reported to relevant authorities as potentially compromised.
The broader AI supply chain security problem
The Mercor breach is not an isolated incident. It's part of a pattern that security researchers have been flagging for months: the AI industry's rapid growth has created a complex supply chain of tools, libraries, APIs, and third-party contractors that hasn't received the same security scrutiny as the core AI products.
LiteLLM, the tool at the center of this breach, is downloaded millions of times per day by developers building AI-powered applications. A successful compromise of that tool doesn't just affect one company — it potentially affects thousands of companies simultaneously, all of whom installed the same infected version. TeamPCP specifically targets these high-leverage points in the development toolchain because the blast radius of a successful attack is enormous.
For Indian developers building applications on top of OpenAI, Anthropic, or other AI API providers — many of whom likely use LiteLLM or similar integration tools — the lesson is to treat open-source AI integration libraries with the same security scrutiny as any other critical dependency. Regularly check for security advisories. Pin to specific verified versions rather than automatically accepting updates. Review your access logs for anomalous API calls that might indicate credential harvesting.
Mercor's response
Mercor confirmed it was affected and described itself as "one of the thousands of companies" impacted by the LiteLLM compromise — language that is technically accurate but also frames the breach in the most favorable possible context. The company said it engaged third-party forensic experts and is communicating directly with affected customers and contractors. The investigation is ongoing.
Whether the Lapsus$ breach represents a separate, more targeted attack on Mercor specifically — beyond the broad LiteLLM supply chain incident — remains under investigation. The distinction matters because a targeted breach would suggest a more serious and specific security failure at Mercor, while the supply chain framing suggests broader industry-wide impact that Mercor happened to be caught in.
TamilTech's take
The Mercor breach matters for Indian professionals at two levels. First, practically: if you worked as a Mercor contractor, take the potential data exposure seriously and monitor your accounts. Second, structurally: this breach reveals that the people who actually do the work of training AI models — the doctors, lawyers, scientists whose expertise makes these systems functional — have real personal data exposure in the supply chains of the companies building the most powerful AI tools in the world. The AI industry's security posture needs to extend all the way through to the contractors who make the training data, not just to the core model infrastructure. Indian professionals deserve to know when that security failed, and Mercor's framing of this as a broad industry impact rather than a specific failure is the kind of response that makes affected contractors feel like an afterthought.




Comments (0)
Be the first to comment!