HackingStolen CredentialsSupply Chain (3P Vendor)Data ExfiltratedCustomer Data InvolvedPIIIDENTITY_BASICLowResolved
Mercor.io Corporation
bd_4b2b7aca4d4faac0 · schema v1 · pii pii-v1
Full breach record for Mercor.io Corporation →Mercor.io Corporation disclosed a data breach resulting from malware inserted into LiteLLM's code scanning tool, a third-party software supply chain compromise. The unauthorized actor accessed Mercor's systems between March 24 and March 30, 2026, and exfiltrated data. Mercor detected and blocked the activity, engaged third-party experts, and is offering 24 months of credit monitoring to affected individuals. The investigation is complete.
California clockConsumers notified Jun 25, 2026 → AG copy submitted Jun 25, 20260d ✓ CA AG copy ≤15d
⚠ no discovery dateNo discovery date was extracted, so no notification clock can be evaluated.
This filing is one of 6 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_a5f5a6a4aeaf7dc7Vermont State AGfiled 2026-06-25Verified
- bd_b03231cefec241c9Indiana State AGfiled 2026-06-25Verified
- bd_ef03878ae6857228New Hampshire State AGfiled 2026-06-25Verified
- bd_fbf3b700b3f6f295Texas State AGfiled 2026-06-26(1d gap)Verified
Show 1 more filing ↓Show fewer ↑up to 24d gap
- bd_fc1f4ab8435c65faMassachusetts State AGfiled 2026-06-01(24d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-625431
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 25, 2026
- Raw hash
- e2193f4ee4aa289ef6627e503cf573b6534b0efcbacf49c467ae3ab34d8337e4
Reporting entity
- Name
- Mercor.io Corporationnorm: mercorio
Victim entity
- Name
- Mercor.io Corporationnorm: mercorio
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- Jun 25, 2026
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASIC
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1195 Supply Chain CompromiseT1041 Exfiltration Over C2 Channel
- Threat actor
- External
- Third party
- via LiteLLM
- Initial access
- supply_chain
Compliance
- Compliance flags
- CA AG copy ≤15d · 0d
- Discovery-date grounding
- no discovery dateNo discovery date was extracted, so no notification clock can be evaluated.
- Clock breakdown
Statute Window Elapsed Threshold Status California Consumers notified: Jun 25, 2026→ AG copy submitted: Jun 25, 20260d 15 calendar days CA AG copy ≤15d
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.