Mercor.io Corporation
ent_52e5a77aa2c2d697e5c13d44
Disclosures
8
State AG · 8 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
21,677
nationwide · State AG TX
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Mercor.io Corporation
- Normalized
- mercorio— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (8)newest first
- Texas State AGas victim2026-06-26
Mercor.io Corporation based in San Francisco, California, a other entity reported a data breach to the Texas Attorney General. The breach was discovered on 2026-03-27 and reported on 2026-06-26. 2,025 Texas residents were affected. 21,677 individuals affected in total. Types of information involved: Name of individual;Address;Social Security Number Information;Driver’s License number;Government-issued ID number (e.g. passport, state ID card);Date of Birth. Consumers were notified via Email.
- California State AGas victim2026-06-25
Mercor.io Corporation disclosed a data breach resulting from malware inserted into LiteLLM's code scanning tool, a third-party software supply chain compromise. The unauthorized actor accessed Mercor's systems between March 24 and March 30, 2026, and exfiltrated data. Mercor detected and blocked the activity, engaged third-party experts, and is offering 24 months of credit monitoring to affected individuals. The investigation is complete.
- Nebraska State AGas victim2026-06-25
Mercor io Corporation notified Nebraska AG of a data breach involving unauthorized access to its systems via a supply-chain compromise (LiteLLM code scanning tool malware). The incident occurred March 24-30, 2026. Mercor detected and blocked the activity, engaged third-party experts, and is offering 24 months of credit monitoring. Personal information of experts was downloaded.
- Vermont State AGas victim2026-06-25
Mercor.io Corporation reported a data breach to the Vermont Attorney General. The breach was reported to the AGO on 2026-06-25. The reporting organization type is Other Commercial. 35 Vermont residents were affected. Categories of data breached: Social Security Numbers, Government ID Numbers.
- Indiana State AGas victim2026-06-25
Mercor.io Corporation reported a data breach to the Indiana Attorney General. The breach occurred on 2026-03-24 and was reported on 2026-06-25. 238 Indiana residents were affected. 21,677 individuals affected in total.
- New Hampshire State AGas victim2026-06-25
Mercor.io Corporation experienced a supply chain attack via LiteLLM's code scanning tool, allowing unauthorized access to systems between March 24-30, 2026. Malware installed by the actor enabled data exfiltration. Approximately 68 New Hampshire residents had government IDs (passport/driver's license numbers) exposed. The company engaged forensics, notified law enforcement, and is offering credit monitoring.
- Massachusetts State AGas victim2026-06-25
Mercor.io Corporation experienced a data breach due to malware inserted into a third-party code scanning tool provided by LiteLLM. The unauthorized actor accessed Mercor's systems between March 24-30, 2026, and exfiltrated data. Mercor detected and blocked the activity, engaged third-party security experts, and is offering 24 months of credit monitoring to affected individuals. The incident is contained.
- Illinois State AGas victim2026-06-01
MERCOR.IO CORPORATION filed a data-breach notice with the Illinois Attorney General in June 2026 (case 26-06-1276). The register records the breach as discovered on March 27, 2026. Personal information types reported: drivers license, medical information, passport number, ssn. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.