ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

AI recruitment startup Mercor says March data breach exposed client information

AI recruitment startup Mercor said a data security incident in March compromised the sensitive personal data of its clients and customers.

 

Mercor is an AI hiring startup that uses artificial intelligence to screen candidates, conduct interviews and match talent with employers. Founded in 2023, the company serves businesses seeking engineers and other skilled professionals.

 

In a data security incident notice published on its website, Mercor said that in late March, Mercor was affected by a supply chain cyber attack involving LiteLLM, a widely used open-source software tool. The AI startup firm immediately launched an investigation, with assistance from external cyber security experts, to determine the nature and scope of the incident.

 

Mercor said its investigation found the breach stemmed from a supply chain attack in which a threat actor distributed compromised versions of LiteLLM to steal credentials from affected systems. The company said its security team identified the unauthorized activity during the relevant period, acted quickly to contain it, and worked with Google’s Mandiant, Latacora, industry peers and law enforcement to investigate the incident and coordinate its response.

 

Mercor’s investigation identified that of its “nearly five million experts, only a very limited subset had sensitive information affected. There is no evidence that any of this data has been used fraudulently.”

 

Mercor said the breach had a limited impact on customer data because many of its customers operate on their own platforms instead of the company’s systems. It added that company representatives remained in regular contact with customers throughout the investigation and shared findings specific to each of them.

 

No employee data was affected, Mercor confirmed.

 

Following the security incident, Meta said it has ended its work with Mercor and is no longer using the startup’s services. The company said the decision was made as part of its security review process after the incident.

 

Several lawsuits were filed against Mercor alleging that the breach exposed personal data as well as the company’s internal practices for collecting and using contractor information. Plaintiffs claim the company monitored contractor activity, shared data with clients, used interview recordings to train AI systems without adequate disclosure, and may have violated regulations through its handling of background checks and third-party content.

 

Mercor has, however, denied the allegations, stating that the claims are speculative and that it complies with all applicable laws and regulations.


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543