
Cyberattack on Mercor Exposes Vulnerability in AI Supply Chain
Mercor, the $2 billion AI recruitment unicorn, confirms cyberattack following exploitation of LiteLLM vulnerability. Data theft exposes supply chain risks.
Guide path
Cyberattack on Mercor Exposes Vulnerability in AI Supply Chain
Use this evidence-led article to understand the topic, compare practical options, and choose a concrete next step. Then continue with the relevant guide, prompt library, or course only when it matches the work you actually need to complete, without random browsing, unsupported claims, or unnecessary purchases that do not fit your goal.
Open the curated guide layer before you pick a course or prompt pack.
Jump to the most relevant AI path for your profession.
Turn article ideas into reusable prompt systems.
Download free prompt packs tied to roles, workflows, and use cases.
Compare options before you spend more time or money.

Mercor, the $2 billion AI recruitment unicorn, confirms cyberattack following exploitation of LiteLLM vulnerability. Data theft exposes supply chain risks.
Guide stack
Most readers should leave with one of three next steps: a role guide, a prompt library section, or a course that matches the same problem.
Reader FAQ
If you want faster execution, open the prompt library. If you want a bigger decision, open the role guides or the course catalog.
Yes. Start with the guide hub, then use the sample lesson path or the prompt library before committing to membership.
Choose the next step that matches your job to be done, not the most popular page.
Keep learning
Continue with practical courses connected to this topic.
Free flagship course: learn the portable system for asking, choosing, reviewing, and delivering with ChatGPT, Gemini, and Claude.
View course →
The flagship TakeAICourse program for applying AI at real work in 30 days.
View course →
Next step
Get the complete Learn AI in 30 Days course — 30 video lessons, workbooks and prompts with your $10/mo membership.
Receive new articles, prompt ideas, and role-specific next steps in your inbox.
Explore next
Read next
AI News
Claude Fable 5 and Mythos 5: Everything Anthropic's New Frontier Model Can Do
10 min read
AI News
Google Launches Gemma 4: The End of Commercial Restrictions That Will Reshape Open Source AI in Latin America
5 min read
AI News
Hugging Face Launches Unsloth Jobs: Train AI for Free with Free GPUs
4 min read
AI News
Lyria 3: How Google's New Music AI Can Transform the Music Industry in Latin America
5 min read
The Mercor, an American AI-powered recruitment startup that reached a $2 billion valuation after a $100 million Series B round led by General Catalyst in 2024, confirmed on Tuesday that it was the victim of a sophisticated cyberattack. The incident, claimed by the extortion group known as NullLoader, resulted in the theft of sensitive data from the company's systems — including candidate information, proprietary evaluation metrics, and integration credentials for corporate clients.
The connection to LiteLLM — an open-source project that centralizes APIs for more than 100 language models, including GPT-4o, Claude 3.5, and Gemini Pro — reveals a critical vulnerability in the software supply chain that supports the growing enterprise AI economy.
According to reports from the company to TechCrunch, attackers exploited a dependency injection vulnerability in LiteLLM that allowed remote code execution (RCE). The project, maintained by the community and with more than 28,000 stars on GitHub, is widely used by startups to standardize calls to multiple LLM providers through a unified interface.
"This attack exemplifies the 'trust but verify' pattern that the industry needs to abandon. When you integrate open-source code into systems that process sensitive personal data, you are inheriting the entire attack surface of that dependency," said Marcus Chen, a security researcher at Mandiant, in an interview with RadarIA.
Supply chain attacks grew 742% between 2020 and 2025, according to data from the Sonatype 2025 State of Software Supply Chain Report. The AI sector, with its intensive reliance on open-source libraries for infrastructure, has become a priority target.
Mercor is not just any company in the ecosystem. Founded in 2023, the platform uses LLMs to evaluate resumes, conduct preliminary interviews, and recommend candidates — processing more than 2 million candidate assessments monthly. Its clients include Fortune 500 companies such as Goldman Sachs, McKinsey, and PepsiCo.
The global recruitment software market was valued at $7.6 billion in 2025, with projections to reach $11.2 billion by 2028 (CAGR of 13.7%). The integration of AI in this segment has accelerated dramatically over the past 18 months.
Although Mercor operates primarily in the US, the incident reverberates strongly across Latin America:
"Human resources companies processing resumes from Latin American professionals now face double pressure: regulatory compliance and demonstrating cybersecurity maturity," explains Fernanda Oliveira, a partner at law firm Veirano specializing in data protection.
LiteLLM, created to simplify the lives of developers who need to switch between LLM providers, illustrates the central paradox of AI security: the more infrastructure is standardized to reduce costs, the greater the impact when that infrastructure is compromised.
The project is maintained by a team of 8 people, all volunteers or funded by community contributions — a model that works for innovation but creates sustainability and security risks. Comparatively, companies like Scale AI and Hugging Face invest $50-100 million annually in infrastructure security.
For the AI and recruitment ecosystem, the next 90 days will be critical:
The attack on Mercor is not an isolated incident — it is a reminder that the democratization of access to AI via open-source code comes with the democratization of risks. For emerging markets like Latin America, where AI adoption in HR processes is accelerating, the lesson is clear: innovation without security is an incomplete equation.
Sources: TechCrunch, Sonatype, CISA, ANPD, Mercor financial reports (disclosed in 2024).