Mercor.io Corporation
ent_52e5a77aa2c2d697e5c13d44
Disclosures
6
State AG · 6 jurisdictions
Incidents
1
filings grouped by incident
Max affected reported
21,677
nationwide · State AG IN
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Mercor.io Corporation
- Normalized
- mercorio— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (6)newest first
- ⭐Texas State AGas victim2026-06-26
Mercor.io Corporation based in San Francisco, California, a other entity reported a data breach to the Texas Attorney General. The breach was discovered on 2026-03-27 and reported on 2026-06-26. 2,025 Texas residents were affected. 21,677 individuals affected in total. Types of information involved: Name of individual;Address;Social Security Number Information;Driver’s License number;Government-issued ID number (e.g. passport, state ID card);Date of Birth. Consumers were notified via Email.
- 🐻California State AGas victim2026-06-25
Mercor.io Corporation disclosed a data breach resulting from malware inserted into LiteLLM's code scanning tool, a third-party software supply chain compromise. The unauthorized actor accessed Mercor's systems between March 24 and March 30, 2026, and exfiltrated data. Mercor detected and blocked the activity, engaged third-party experts, and is offering 24 months of credit monitoring to affected individuals. The investigation is complete.
- 🍁Vermont State AGas victim2026-06-25
Mercor.io Corporation reported a data breach to the Vermont Attorney General. The breach was reported to the AGO on 2026-06-25. The reporting organization type is Other Commercial. 35 Vermont residents were affected. Categories of data breached: Social Security Numbers, Government ID Numbers.
- 🏎️Indiana State AGas victim2026-06-25
Mercor.io Corporation reported a data breach to the Indiana Attorney General. The breach occurred on 2026-03-24 and was reported on 2026-06-25. 238 Indiana residents were affected. 21,677 individuals affected in total.
- ⛰️New Hampshire State AGas victim2026-06-25
Mercor.io Corporation notified the New Hampshire Attorney General of a security event involving the LiteLLM supply chain. An unauthorized actor exploited malware in LiteLLM code scanning tools to access Mercor's systems between March 24-30, 2026. The incident affected approximately 68 New Hampshire residents, exposing passport numbers, driver's license numbers, and other government IDs. Mercor engaged forensic investigators, notified law enforcement, and is offering 24 months of credit monitoring via TransUnion.
- 🏛️Massachusetts State AGas victim2026-06-01
Mercor.io Corporation notified Massachusetts residents of a data breach involving unauthorized access to systems via compromised LiteLLM code scanning tool malware. The incident occurred March 24-30, 2026, resulting in the exfiltration of personal information. Mercor offered 24 months of credit monitoring through TransUnion and enhanced security controls.