Genuine Compliance Matters: Lawsuit Filed Against Mercor, Delve & LiteLLM Following TeamPCP Cyber…
On Wednesday 8th April 2026, a class action 42 page legal filing against Mercor, Delve and LiteLLM was lodged in Texas.
Genuine Compliance Matters: Lawsuit Filed Against Mercor, Delve & LiteLLM Following TeamPCP Cyber Attack

On Wednesday 8th April 2026, a class action 42 page legal filing against Mercor, Delve and LiteLLM was lodged in Texas.
As is tradition, I took a read through the filing, here are some of the key excerpts from the filing;
“The breach was not a random event. It was the foreseeable result of a chain of negligence and fraud that began with Delve…”
The law suit claims that Mercor sold, licenced or otherwise provided randomly captured screenshots from “invasive monitoring software” Insightful (previously called Workpuls) required by Mercor to be used by Contractors, along with Contractor personal information to LiteLLM to train models.
The filing claims that beginning in or around 2023 to at least March 2026, Delve systematically fabricated compliance certifications for its customers (LiteLLM being one of those)
Representations by LiteLLM are claimed to be false or misleading, since their security certifications were obtained through a provider that it is claimed fabricated compliance reports (they’re talking about Delve)
Late March, TeamPCP strikes at LiteLLM via supply chain attack, compromising the PyPI publishing credentials for the LiteLLM library and injected a three-stage malicious backdoor into LiteLLM versions 1.82.7 and 1.82.8, accessing API keys, taking credentials.
“Following the discovery of the compromise, LiteLLM severed ties with Delve and announced it would pursue recertification through Vanta”
“This remedial action constitutes an implicit acknowledgement that Delve-obtained certifications were inadequate”
“four terabytes of sensitive information, inc: a 211-gigabyte user database; 939 gigabytes of platform source code; approximately three terabytes of storage buckets containing video interviews and identity verification passports; TailScale VPN configuration data…”
“Mercor sold, licensed, or otherwise provided contractor data — including personal information, recorded interviews, Insightful screen captures, and work product — to the John Doe Defendants for use in training and developing large language models”
“The fabrication of compliance certifications by Delve was confirmed by internal evidence made public in March 2026”
“Delve intended that its certifications be relied upon by its customers and by the downstream users and consumers of its customers’ services”
There is a lot of irony in perhaps Delve not having a clue about legal liability and the hot water they could find themselves in when falsifying information in relation to compliance.
As an industry, can we all mutually agree not to let 21 year olds start a compliance company again for a while.
Any questions? Reach out! - https://x.com/Alph4betSoup

My Medium articles are free for anyone to read, and always will be. I believe that information should be free, particularly in a research context.
If you find my research or other articles useful, entertaining, or insightful, you can buy me a drink to say thanks
메타데이터
- post_id
- dfb4e165e27c
- slug
- genuine-compliance-matters-lawsuit-filed-against-mercor-delve-litellm-following-teampcp-cyber-dfb4e165e27c
- url
- https://medium.com/@ItsNotNicole/genuine-compliance-matters-lawsuit-filed-against-mercor-delve-litellm-following-teampcp-cyber-dfb4e165e27c
- canonical_url
- https://medium.com/@ItsNotNicole/genuine-compliance-matters-lawsuit-filed-against-mercor-delve-litellm-following-teampcp-cyber-dfb4e165e27c
- author_url
- https://medium.com/@ItsNotNicole
- status
- ok
- fetched_at
- 2026-06-23 03:48:11