Mercor.io Corporation Data Breach Investigation

Data Breach Blog

Data Breach

Mercor.io Corporation Data Breach Investigation

Almeida Law Group Calendar Icon

Date of data breach:

June 25, 2026

by: Almeida Law Group

Almeida Law Group is investigating a data breach at Mercor.io Corporation. The breach occurred on March 24th, 2026. If you were affected, contact Almeida Law Group.


About Mercor.io Corporation

Mercor.io Corporation is an AI-driven recruiting and talent platform founded in 2023 and headquartered at 181 Fremont St., Floor 33, San Francisco, California. The company connects professionals — including specialists in medicine, law, and other fields — with AI companies such as OpenAI, Anthropic, Meta, and Google to help train AI models and chatbots. Because its platform conducts AI-driven video interviews and handles contractor onboarding, it collects a broad range of sensitive personal and financial information about the individuals who work through it.


What Happened?

Mercor.io Corporation was listed in a California Attorney General sample breach notice filed on June 25th, 2026.

The incident was a supply-chain attack. On March 24th, 2026, a threat group known as TeamPCP published malware-laced versions of LiteLLM (v1.82.7 and v1.82.8), an open-source AI proxy library, to the PyPI software repository. The malicious packages were available for roughly 40 minutes to three hours before being quarantined. Mercor had installed the compromised package, which allowed unauthorized actors to access its systems between March 24th and March 30th, 2026. The cybercriminal group Lapsus$ subsequently claimed responsibility for exfiltrating approximately 4 terabytes of data and listed Mercor on its leak site. TeamPCP and Lapsus$ are reported to have been collaborating. Mercor publicly confirmed the breach on March 31st, 2026, but did not file the California Attorney General breach notice until June 25th, 2026 — approximately three months later. The breach affected more than 40,000 contractors.

According to court filings, hacker claims, and news reporting, compromised data may include candidate profiles, full names, Social Security numbers, email addresses, work history, resumes, recorded AI video interviews, facial biometric data, government-issued identity documents (including passports), W-9 tax forms, banking information, background-check records, and personal-device screenshots. Mercor’s own breach notice uses a template with a placeholder for individual-specific data types, so the exact categories affected vary per recipient. The company is offering 24 months of complimentary credit monitoring and identity restoration services through TransUnion, with an enrollment deadline of October 1st, 2026.

As of late April 2026, at least seven class-action lawsuits had been filed against Mercor. Key cases include Ananthula, et al. v. Mercor.io Corporation, et al., No. 3:26-cv-03362 (N.D. Cal., filed April 21st, 2026), a ten-count putative class action naming Mercor alongside Delve AI and LiteLLM (BerriAI); Gill v. Mercor.io Corp. (N.D. Cal., filed April 1st, 2026); Deboni v. Mercor.io Corporation, Case 3:26-cv-02821; Esson v. Mercor; and a suit filed in Texas federal court. Legal theories include negligence, breach of implied contract, FCRA violations, Illinois BIPA, the Illinois AI Video Interview Act, and unjust enrichment, among others. Meta indefinitely paused its contracts with Mercor following the breach, and OpenAI stated it was investigating its own exposure.


Key Facts at a Glance

  • Company or Organization: Mercor.io Corporation
  • Industry: Artificial Intelligence / AI Training Data / Recruiting Technology
  • Location: 181 Fremont St., Floor 33, San Francisco, CA 94105
  • Incident type: Supply-chain cyberattack (malware-laced third-party software package; unauthorized data access and exfiltration)
  • Date of breach: March 24th, 2026
  • Date of consumer notification: June 25th, 2026
  • Total persons affected: Over 40,000 contractors
  • Identity theft protection offered: 24 months of complimentary credit monitoring and identity restoration services through TransUnion (via Cyberscout)
  • Enrollment deadline: October 1st, 2026
  • Litigation status: At least seven class-action lawsuits filed as of late April 2026, including Ananthula et al. v. Mercor.io Corporation et al., No. 3:26-cv-03362 (N.D. Cal.); Gill v. Mercor.io Corp. (N.D. Cal.); Deboni v. Mercor.io Corporation, Case 3:26-cv-02821; Esson v. Mercor; and a Texas federal court action
  • Source: California Attorney General sample breach notice, https://oag.ca.gov/ecrime/databreach/reports/sb24-625431; TechCrunch, https://techcrunch.com/2026/04/09/after-data-breach-10b-valued-startup-mercor-is-having-a-month/; Fortune, https://fortune.com/2026/04/02/mercor-ai-startup-security-incident-10-billion/; The Next Web, https://thenextweb.com/news/meta-mercor-breach-ai-training-secrets-risk; Hausfeld LLP, https://www.hausfeld.com/en-us/what-we-do/current-claims/mercor-data-breach

What Should You Do?

If you received a notice from Mercor, enroll in the 24-month TransUnion credit monitoring service before the October 1st, 2026 deadline by visiting https://bfs.cyberscout.com/activate with your unique activation code. Beyond that, consider placing a fraud alert or credit freeze with the three major credit bureaus — Equifax, Experian, and TransUnion — to make it harder for someone to open new accounts in your name. Review your credit reports for free at AnnualCreditReport.com and watch your existing financial accounts closely for any unusual activity. If you believe your identity has been misused, visit IdentityTheft.gov for step-by-step guidance on reporting and recovery. Given that Social Security numbers, government IDs, banking information, and biometric data may have been involved, acting promptly is especially important.


Your Legal Rights

If your personal information was involved in this breach, you may have legal rights depending on the facts of the incident and the law in your state. Almeida Law Group represents consumers in data breach and privacy litigation and can help you evaluate whether you may have a claim. Contact us at (708) 529-5418 or through our contact page for a free case evaluation.

Were You a Victim of a Data Breach?

"*" indicates required fields

By clicking the SEND button and submitting this form, I consent to receive communications from Almeida Law Group LLC and their co-counsel by phone call, email, and/or SMS regarding this matter and other potential legal matters. I understand that message and data rates may apply and that consent to such contact is not required for use of these services. Message frequency varies. Reply STOP to opt-out and HELP for help. I also agree to the Privacy Policy. I understand that my information may be shared with advertising partners to deliver targeted advertisements and optimize outreach efforts. I confirm that I am at least 18 years old. I have read and understand the disclaimer above. I agree my use of this site and the information provided here is not intended to create and does not create an attorney client relationship with the Almeida Law Group and/or attorneys employed by the Firm. No attorney client relationship is intended or created unless and until an engagement agreement is signed by all relevant parties. The contents of this site constitute attorney advertising and not legal advice; therefore you should not act or rely upon any information contained herein, and should always seek the advice of an attorney.

Resourceful. Resilient. Relentless.

Contact us today to get the justice you and your family deserve.