HackingStolen CredentialsSupply Chain (3P Vendor)Data ExfiltratedCustomer Data InvolvedIDENTITY_GOVERNMENTIDENTITY_BASICMediumContained
Mercor.io Corporation
bd_ef03878ae6857228 · schema v1 · pii pii-v1
Full breach record for Mercor.io Corporation →Mercor.io Corporation notified the New Hampshire Attorney General of a security event involving the LiteLLM supply chain. An unauthorized actor exploited malware in LiteLLM code scanning tools to access Mercor's systems between March 24-30, 2026. The incident affected approximately 68 New Hampshire residents, exposing passport numbers, driver's license numbers, and other government IDs. Mercor engaged forensic investigators, notified law enforcement, and is offering 24 months of credit monitoring via TransUnion.
This filing is one of 6 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_4b2b7aca4d4faac0California State AGfiled 2026-06-25Candidate
- bd_a5f5a6a4aeaf7dc7Vermont State AGfiled 2026-06-25Verified
- bd_b03231cefec241c9Indiana State AGfiled 2026-06-25Verified
- bd_fbf3b700b3f6f295Texas State AGfiled 2026-06-26(1d gap)Verified
Show 1 more filing ↓Show fewer ↑up to 24d gap
- bd_fc1f4ab8435c65faMassachusetts State AGfiled 2026-06-01(24d gap)Verified
Source provenance
- Source URL
- https://www.doj.nh.gov/sites/g/files/ehbemt721/files/remote-docs/mercor.io-corporation-20260625.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 25, 2026
- Raw hash
- 021183fe762483a56df0cc2fc343aa00eaae822f5ed9ef41ccb9ce5fddad120a
Reporting entity
- Name
- Mercor.io Corporationnorm: mercorio
Victim entity
- Name
- Mercor.io Corporationnorm: mercorio
Incident
- Discovered
- Mar 24, 2026
- Materiality determined
- —
- Notification sent
- Jun 25, 2026
- Affected individuals
- 68
- Data types
- IDENTITY_GOVERNMENTIDENTITY_BASIC
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1195 Supply Chain CompromiseT1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Initial access
- supply_chain
Compliance
- Time to disclose
- 13 weeks(93 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.