JAS
← All insights
· 8 min readRecruitment TechnologyData BreachAI RecruitingCybersecurity

The $10 Billion AI Recruiting Platform Used by OpenAI and Meta Just Got Hacked. 4 Terabytes of Candidate Data Stolen.

Mercor, the AI recruiting startup valued at $10 billion and used by OpenAI, Anthropic, and Meta, suffered a massive data breach. Meta paused all work. Here is what it means for recruitment agencies.

Mercor is an AI recruiting startup valued at $10 billion. Its clients include OpenAI, Anthropic, and Meta, three of the most important AI companies in the world. On 31 March 2026, hackers stole up to 4 terabytes of candidate data from Mercor's systems. Meta immediately paused all work with the platform. The company that AI's biggest players trusted to find their talent just became the biggest data liability in recruiting history.

What Was Stolen

The breach was a supply chain attack. Hackers, claiming to be associated with the Lapsus$ group, compromised the open-source LiteLLM project, which Mercor used as part of its AI infrastructure. Through this vector, they gained access to Mercor's systems and extracted massive amounts of data.

The stolen data includes over 200 gigabytes from an unnamed database and a 3 terabyte drive containing video and verification data. In a recruiting context, this means candidate interviews, identity verification documents, assessment recordings, and personal information: the most sensitive data a recruiting platform can hold.

But the breach may have exposed something even more valuable than candidate data. Mercor's platform uses AI to match candidates to roles for some of the most advanced AI companies in the world. The stolen data may include data selection criteria, labelling protocols, and training strategies that these AI companies spent billions developing. The intellectual property exposure could dwarf the privacy implications.

The Client Response

Meta's response was immediate and unambiguous. The company "indefinitely" paused all work with Mercor. For a platform that counted Meta as one of its flagship clients, this is a devastating signal to the market. When your biggest client publicly walks away, every other client reassesses.

OpenAI took a different approach, stating that it is investigating but has not paused its projects with Mercor. Anthropic has not made a public statement. The divergent responses suggest that even among Mercor's clients, there is disagreement about how serious the breach is, or how much they can afford to step away from the platform while their hiring needs remain urgent.

The Deeper Problem: AI Recruiting Platforms and Data Risk

Mercor is not the first AI recruiting platform to face scrutiny for how it handles candidate data, but the scale of this breach is unprecedented.

Traditional recruitment agencies hold candidate data too. But they hold it in smaller volumes, across distributed systems, with human oversight at every stage. A breach at a single recruitment agency might expose thousands of records. A breach at a centralised AI platform exposes millions.

This is the fundamental data risk that AI recruiting platforms create. By centralising candidate data from multiple clients into a single platform, they create a single point of failure that affects every client simultaneously. When Mercor was breached, every company that used the platform was potentially exposed. The efficiency of centralisation becomes a liability when the central system is compromised.

For the candidates whose data was stolen, the consequences are severe. Video interviews, identity documents, and assessment data cannot be changed like a password. Once this information is in the hands of malicious actors, the candidates have no recourse. Their biometric data, their interview performances, their personal identification documents: all permanently compromised.

The Buying-Data Revelation

A separate but related detail emerged during reporting on the breach. Mercor was reportedly looking to buy work product from candidates' previous employers to use as AI training data. This means the platform was not just collecting data that candidates voluntarily provided during the recruiting process. It was actively seeking to acquire data about candidates from other sources: data the candidates may not have known was being collected or used.

This practice, if confirmed, raises serious questions about consent and data governance in AI recruiting. Candidates who submit their information to a recruiting platform expect that data to be used for matching them to roles. They do not expect the platform to purchase additional data about them from third parties and feed it into AI training systems.

What This Means for Recruitment Agencies

The Mercor breach is the strongest argument for traditional recruitment agencies that has emerged in years. Here is why.

The trust argument: Clients considering AI recruiting platforms must now factor in the risk that a single breach could expose their entire candidate pipeline, their hiring strategies, and potentially their proprietary assessment methodologies. A recruitment agency with a 20-person team and local data storage presents a fundamentally smaller attack surface.

The compliance argument: With the EU AI Act classifying recruitment AI as high-risk (enforcement begins August 2026), the regulatory scrutiny on AI recruiting platforms will intensify. A breach of this scale at a high-risk AI system will draw attention from regulators who are already looking for enforcement targets. Recruitment agencies that maintain human oversight at every stage of the process are in a structurally better compliance position.

The candidate experience argument: Candidates whose data was compromised in the Mercor breach will think twice before submitting their information to another AI platform. Some of the best candidates, the ones who are in demand and can be selective about where they apply, may refuse to use AI recruiting platforms entirely. A recruitment agency that can guarantee human handling of sensitive data has a candidate attraction advantage.

The relationship argument: When Meta paused work with Mercor, every open role that was being processed through the platform was disrupted. Clients who depended on a single AI platform for their recruiting pipeline lost access to that pipeline overnight. Clients who work with recruitment agencies have relationships with individual consultants who can continue operating regardless of what happens to any single technology platform.

The Irony

Mercor's pitch to clients was straightforward: AI recruiting is faster, more efficient, and more scalable than traditional recruitment. The breach proves that scalability cuts both ways. When the system works, it works at scale. When it fails, it fails at scale.

Four terabytes of candidate data stolen in a single incident. The platform designed to make recruiting more efficient just created the biggest data liability in recruiting history. And the companies that build the most powerful AI systems in the world, OpenAI, Anthropic, Meta, trusted their most sensitive hiring data to a platform that could not keep it safe.

For recruitment agencies, the message is clear. Your human-run process is not just a different approach to recruiting. After Mercor, it is the safer one.