GLOBALMalwareRansomwareLapsus$LapsusRansom DemandedActor NamedMedium
Mercor GmbH
bd_7103683d9cf399b5 · schema v1 · pii pii-v1
Full breach record for Mercor GmbH →Threat-actor claim — not a regulatory filing
This row is a claim by the ransomware group Lapsus$ on its public extortion blog. It has not been validated by the victim or any regulator. Treat attribution and counts as the threat actor's assertion until a regulatory filing or victim disclosure corroborates them.
Group activity: Not FoundDiscovered: 2026-05-31
Source: Ransomware.live
Post text · scraped from the leak site
This data has been acquired by a private party. No public leak will occur.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Unverified claimView incident
No regulatory filing corroborates this yet. If an SEC 8-K, state-AG notice, or victim statement lands, DisclosureLens will merge it into an incident and link it here.
Source provenance
- Source URL
- https://www.ransomware.live/id/TUVSQ09SQGxhcHN1cyQ=
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 31, 2026
- Raw hash
- c1770b429a7560d26e1b187f408a30efd323ef367c601ab01da8486afc8064a7
Reporting entity
- Name
- lapsus$
Victim entity
- Name
- Mercor GmbHnorm: mercor
What this source establishes
- Source ceiling
- A leak-site claim can't tell us: discovery date · materiality · notification · affected count · confirmed data types · compliance clock. These stay blank until a regulatory filing or victim disclosure lands.
- Attack vector
- Ransomware· lapsus$
- Threat actor
- Lapsus$ExternalFinancial
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.