Do you think a $10 billion valuation makes a company unhackable? Do you assume that because a startup works with giants like Meta and OpenAI, their digital fortress is impenetrable?
If so, you’re making a dangerous mistake that could cost your NYC business everything.
The recent breach at Mercor AI is a brutal wake-up call for every CEO, IT manager, and entrepreneur in Manhattan. It wasn’t a sophisticated, direct assault on their core infrastructure that brought them down. It was a “tiny” open-source tool called LiteLLM. This one small gear in their massive machine was compromised, and as a result, 4 terabytes of sensitive data: including internal source code and candidate Social Security numbers: are now floating around the dark web.
As the CEO of New York Computer Help, I see this pattern constantly. Companies spend thousands on high-end firewalls but leave the “back door” unlocked by using unvetted third-party plugins. Let’s dive into what happened and how you can prevent your business from becoming the next headline.
The $10 Billion Reality Check
You’ve probably heard the name Mercor lately. They are the AI darling that helps companies like Meta and OpenAI source and vet talent using artificial intelligence. With a $10 billion valuation, they represent the peak of the current AI boom. But on April 1, 2026, the joke was on them: and their 40,000 contractors.
A hacking group known as TeamPCP, potentially collaborating with the notorious LAPSUS$ group, managed to exfiltrate a staggering 4TB of data. To put that in perspective, that is roughly 1 million high-resolution photos or thousands of hours of high-definition video.
The fallout was immediate. Meta, a primary partner, has already indefinitely paused all work with Mercor. When the big players lose trust in you, the valuation doesn’t matter anymore. If you are operating a business in the city, you need to understand that your reputation is your most valuable asset. Once the data leaks, the trust evaporates.
How LiteLLM Became the Trojan Horse
The “how” of this breach is what should keep you up at night. This wasn’t a case of a weak password or a phishing email. This was a supply chain attack.
Mercor used an open-source library called LiteLLM. It’s a popular tool designed to help developers connect their applications to various AI services easily. Because it’s open-source and widely used, developers often trust it blindly. TeamPCP exploited this trust by inserting malicious code directly into the LiteLLM library.
When Mercor’s developers updated their tools, they unknowingly invited the hackers right into the heart of their system.
This is the new favorite weapon for groups like LAPSUS$. Why spend months trying to crack a $10B company’s main server when you can just poison the “free” tools their developers use every day? This is why Cybersecurity for NYC Businesses has shifted from just “blocking hackers” to “vetting every single piece of software you touch.”
The 4TB Fallout: What’s Actually Out There?
When we talk about 4TB of data, it’s easy to get lost in the numbers. Let’s look at the actual inventory of what was stolen from Mercor:
- 939 GB of Platform Source Code: This is the “secret sauce.” Hackers now have the blueprint of how Mercor’s AI actually works.
- 211 GB User Database: This includes names, contact info, and sensitive personal details.
- 3 Terabytes of Video Interviews: This is perhaps the most invasive part. These are recordings of thousands of people interviewing for jobs, providing identity verification documents, and speaking candidly.
- Social Security Numbers: Sensitive PII (Personally Identifiable Information) for over 40,000 contractors.
Imagine your internal Slack conversations, your proprietary code, and your clients’ private documents being posted on a public forum. For many businesses, that is an extinction-level event. If you are worried about your own data integrity, our team provides Expert Data Recovery and protection strategies to ensure your “secret sauce” stays secret.
Why Supply Chain Attacks Are Your New Biggest Headache
You might think, “I’m not a $10B AI startup, why would they target me?”
The truth is, hackers love small to medium-sized NYC businesses because they often have the same “tools” as the giants but half the security budget. If you use a WordPress plugin, a Chrome extension, or a specialized accounting tool, you are part of a supply chain.
Statistics show that supply chain attacks increased by over 300% in the last year alone. Hackers are moving upstream. By compromising one tool used by 5,000 companies, they get 5,000 targets for the price of one.
Are you auditing your third-party integrations? If you haven’t checked what access your plugins and tools have lately, you’re essentially leaving your office keys under the doormat and hoping for the best.
Joe’s Pro Tip: The 3-Step Audit for Your Tech Stack
I don’t just want to scare you; I want to help you fix this. Here is how I recommend every NYC business owner handles their “tool debt” to avoid a Mercor-style disaster:
- Inventory Everything: You cannot protect what you don’t know you have. Sit down with your team and list every third-party integration, API, and plugin you use. You’ll be surprised how many “zombie” apps are still connected to your data.
- Apply the Principle of Least Privilege: Does that simple PDF converter plugin really need access to your entire Google Drive? Probably not. Limit the permissions of every tool to the absolute minimum it needs to function.
- Automated Monitoring: Use tools that alert you when a library or plugin you use has a known vulnerability. Don’t wait for the news to tell you that you’ve been breached.
Maintaining this level of vigilance is a full-time job. That’s why many of our clients rely on our Managed IT Services to handle the heavy lifting of security audits and real-time monitoring.
Joe Reviews: The Security of the “AI PC”
In the wake of these breaches, we’re seeing a push toward “Local AI”: running AI models on your own hardware rather than in the cloud where tools like LiteLLM are required.
I’ve been testing the latest MacBook Pro with the M4 Max chip and several NVIDIA RTX 50-series GPUs. The performance for local LLMs (Large Language Models) is staggering. By keeping the data on your own machine in your Midtown office, you eliminate the risk of a third-party cloud breach entirely.
If you are a high-end creative or tech firm in NYC, moving toward local AI processing might be the smartest security move you make this year. It’s faster, it’s private, and it doesn’t care if LiteLLM gets hacked.
The Future of AI Trust
The Mercor breach is a landmark event. It shows that even in the cutting-edge world of AI, the oldest security flaws: trusting the wrong person (or tool): are still the most dangerous.
A class-action lawsuit was filed against Mercor on April 1, 2026, alleging they failed to maintain adequate protections. You don’t want to be in that position. You don’t want to be explaining to your clients why their personal videos are on a hacker forum because you forgot to check a plugin.
Imagine a workforce where your data is locked down, your integrations are audited, and your team is trained to spot these “upstream” threats before they hit your network. That is the level of security you need in 2026.
Don’t wait for a 4TB leak to take your security seriously. The “tiny” tools in your stack are either your best friends or your biggest liabilities. It’s time to find out which ones are which.
If you’re not sure where to start, give us a call at New York Computer Help. We’ll help you lock the back door before the hackers even find the house.
Stay safe out there, NYC.
Joe Silverman
CEO, New York Computer Help
Note: Some images in this article may be AI-generated.


