[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f1gwfz6fidyzgy":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"modifiedDate":12,"contentUpdatedAt":12,"source":13,"sourceUrl":14,"sourceUrls":15,"pwnCount":18,"affectedCount":19,"affectedCountStatus":20,"affectedCountLowerBound":19,"affectedCountUnit":21,"hasEnglishDescription":4,"severity":22,"dataClasses":23,"description":30,"seoTitle":31,"seoTitleEn":32,"seoDescription":31,"seoDescriptionEn":33,"logoUrl":34,"isVerified":4,"isSensitive":4,"isSpamList":35,"isMalware":35,"company":36},"6a6ac83a954449b58d0f301e","Mercor2026","Mercor 2026 Data Breach","mercor-2026","mercor.com","2026-03-24T00:00:00.000Z","2026-07-30T03:42:50.836Z","California and Texas Attorney General records","https:\u002F\u002Foag.ca.gov\u002Fecrime\u002Fdatabreach\u002Freports\u002Fsb24-625431",[14,16,17],"https:\u002F\u002Foag.ca.gov\u002Fsystem\u002Ffiles\u002FMercor%20-%20Consumer%20Notice.pdf","https:\u002F\u002Foag.my.site.com\u002Fdatasecuritybreachreport\u002Fapex\u002FDataSecurityReportsPage",null,2025,"lower_bound","people","Low",[24,25,26,27,28,29],"Names","Physical addresses","Dates of birth","Social security numbers","Driver's license numbers","Government IDs","\u003Cp>\u003Cstrong>The 2026 Mercor data breach\u003C\u002Fstrong> involved unauthorized access to company systems after malware was inserted into certain versions of a LiteLLM tool used by the company. A Texas regulator record confirms that at least 2,025 people were affected; the nationwide total has not been disclosed.\u003C\u002Fp>\n\u003Cp>Mercor.io Corporation is a U.S. work platform connecting professionals with artificial-intelligence projects. The incident was a software supply-chain attack that reached company systems through a tool used by the platform.\u003C\u002Fp>\n\u003Ch2>How Did the Incident Occur?\u003C\u002Fh2>\n\u003Cp>In late March 2026, LiteLLM disclosed that an unauthorized actor had inserted malware into certain versions of a widely used code-scanning tool. Mercor was one of the organizations using the tool, and the malware enabled access to some Mercor systems between March 24 and March 30. The company detected and blocked the activity and began reviewing the downloaded data.\u003C\u002Fp>\n\u003Ch2>What Information Was Affected?\u003C\u002Fh2>\n\u003Cp>According to the Texas record, the information could have included names, addresses, dates of birth, Social Security numbers, driver's licenses, and government identification such as passports or state IDs, depending on the person. The person-specific field is redacted in the public sample notice, so no broader data category has been added.\u003C\u002Fp>\n\u003Ch2>How Did Mercor Respond?\u003C\u002Fh2>\n\u003Cp>The company detected and blocked the unauthorized activity, investigated with external security specialists, and enhanced its security and monitoring controls. Notice recipients were offered 24 months of credit monitoring and identity-restoration support.\u003C\u002Fp>\n\u003Ch2>What Should Affected People Do?\u003C\u002Fh2>\n\u003Cp>Notice recipients should review credit reports and financial accounts for unfamiliar activity. People whose Social Security or government-ID information was involved may consider a credit freeze or fraud alert. Unexpected messages sent in Mercor's name or referring to a work opportunity should be verified through the platform's known official channels.\u003C\u002Fp>","","Mercor Data Breach (At Least 2,025 People Affected)","At least 2,025 people were affected in the Mercor breach. Review the LiteLLM supply-chain attack, affected data, and response.","\u002Fuploads\u002Flogo\u002Fmercor.png",false,{"name":37,"sector":38,"country":39,"website":10,"websiteArchiveUrl":31,"websiteStatus":31,"websiteCheckedAt":18},"Mercor.io Corporation","Technology","United States"]