DisclosureLens
MalwareTechnologyInformationRansomwareSupply Chain (3P Vendor)Data ExfiltratedData EncryptedPIIIdentity (basic)LowContained

Mercor.io Corporation

bd_87c464c27c740e3e · schema v1 · pii pii-v1

Severity

Low

Discovered

Mar 24, 2026

Filed

Jun 25, 2026

To disclose

Affected

Not disclosed

Linked

8 filings

Confidence

65%
Full breach record for Mercor.io Corporation

Mercor io Corporation notified Nebraska AG of a data breach involving unauthorized access to its systems via a supply-chain compromise (LiteLLM code scanning tool malware). The incident occurred March 24-30, 2026. Mercor detected and blocked the activity, engaged third-party experts, and is offering 24 months of credit monitoring. Personal information of experts was downloaded.

Incident timeline

Mar 24, 2026

Begins

Mar 24, 2026

Discovered

Jun 25, 2026

Filed

This filing is one of 8 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (7) · sorted by filing gap

Show 3 more filingsup to 24d gap

Filing propagation · 8 filings · 8 states

View merged incident ↗

Pattern: first filing Jun 1 (IL), last Jun 26 (TX) — a 25-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.