MalwareRansomwareSupply Chain (3P Vendor)Data ExfiltratedData EncryptedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
Mercor.io Corporation
bd_fc1f4ab8435c65fa · schema v1 · pii pii-v1
Full breach record for Mercor.io Corporation →Mercor.io Corporation notified Massachusetts residents of a data breach involving unauthorized access to systems via compromised LiteLLM code scanning tool malware. The incident occurred March 24-30, 2026, resulting in the exfiltration of personal information. Mercor offered 24 months of credit monitoring through TransUnion and enhanced security controls.
Massachusetts clock⏱ MA AG >30d10 weeks discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
This filing is one of 6 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_4b2b7aca4d4faac0California State AGfiled 2026-06-25(24d gap)Candidate
- bd_a5f5a6a4aeaf7dc7Vermont State AGfiled 2026-06-25(24d gap)Verified
- bd_b03231cefec241c9Indiana State AGfiled 2026-06-25(24d gap)Verified
- bd_ef03878ae6857228New Hampshire State AGfiled 2026-06-25(24d gap)Verified
Show 1 more filing ↓Show fewer ↑up to 25d gap
- bd_fbf3b700b3f6f295Texas State AGfiled 2026-06-26(25d gap)Verified
Source provenance
- Source URL
- https://www.mass.gov/doc/2026-1030-mercorio-corporation/download
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 1, 2026
- Raw hash
- 24cdbc119ffa2bb6379d3bef5d364e57725844aae8d0b3233f4cffa36b556191
Reporting entity
- Name
- Mercor.io Corporationnorm: mercorio
Victim entity
- Name
- Mercor.io Corporationnorm: mercorio
Incident
- Discovered
- Mar 24, 2026
- Materiality determined
- —
- Notification sent
- Jun 25, 2026
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1195 Supply Chain CompromiseT1486 Data Encrypted for Impact
- Threat actor
- ExternalFinancial
- Initial access
- supply_chain
Compliance
- Time to disclose
- 10 weeks(69 days from discovery to filing)
- Compliance flags
- MA AG >30d
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.