Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
Mercor

Mercor Vendor Cyber Rating & Cyber Score

mercor.com

Mercor is defining the future of work. We connect human expertise with leading AI labs and enterprises to train frontier models.


Mercor A.I CyberSecurity Scoring

Mercor
Company Information
Website:http://mercor.com
Employees number:5,609
Number of followers:672,135
NAICS:5112
Industry Type:Software Development
Homepage:mercor.com
Mercor Risk Score (AI oriented)
Between 600 and 649
logo
MercorSoftware Development
Updated:
03/04/2026
603/1000
Poor
Caa
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
Mercor Global Score (TPRM)
xxxx
logo
MercorSoftware Development
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

MercorPoor
Current Score
603Caa (POOR)
01000
8 incidents
-72 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
SEPTEMBER 2026
290Before Incident
AUGUST 2026
270Before Incident
JULY 2026
271Before Incident
JUNE 2026
262Before Incident
MAY 2026
431Before Incident
APRIL 2026
429Before Incident
Breach
22 Apr 2026Mercor
Agoda, Booking.com and Booking Holdings: Agoda refutes claims of massive data breach

Agoda Denies Data Breach as Cybercriminals Claim Theft of 82 Million Records

247After Incident
CRITICAL-182
AGOBOO1776904233
Agoda Denies Data Breach as Cybercriminals Claim Theft of 82 Million Records Asia-based travel booking platform Agoda has refuted claims of a data breach after cybercriminals alleged the theft of 82 million user records. An Agoda spokesperson stated that internal investigations confirmed the leaked data did not originate from its systems. Researchers at Cybernews analyzed a sample of 23 records provided by the attackers, which included sensitive details such as full names, identity card numbers, phone numbers, email addresses, and hotel addresses primarily linked to Malaysian users. Notably, the sample lacked reservation dates, an unusual omission that raised questions about the data’s origin. Despite this, the researchers verified the legitimacy of the exposed information. The incident follows a recent confirmation by Agoda’s parent company, Booking Holdings, of a separate breach affecting Booking.com users. That attack exposed names, phone numbers, email addresses, and reservation details, leading to a surge in reservation hijacking scams across North America, Europe, and the UK. The timing of the two incidents has heightened concerns about cybersecurity risks in the travel industry.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
Data Compromised: 82 million records allegedly stolenBrand Reputation Impact: Potential reputational damage due to breach claimsIdentity Theft Risk: High (exposure of full names, identity card numbers, phone numbers, email addresses)
DATA BREACH
Full namesIdentity card numbersPhone numbersEmail addressesHotel addressesNumber Of Records Exposed: 82 million (alleged)Sensitivity Of Data: High (personally identifiable information)Data Exfiltration: Claimed by cybercriminalsPersonally Identifiable Information: Yes
APRIL 2026
495Before Incident
Breach
21 Apr 2026Mercor
Anthropic and Microsoft: Discord-Linked Group Accessed Anthropic’s Claude Mythos AI in Vendor Breach

Unauthorized Access to Claude Mythos AI Model via Third-Party Vendor

428After Incident
CRITICAL-67
ANTMIC1776882793
Anthropic Investigates Unauthorized Access to Claude Mythos AI Model via Third-Party Vendor On April 21, 2026, Anthropic confirmed it was investigating unauthorized access to its unreleased Claude Mythos Preview AI model, part of the Project Glasswing initiative. The breach occurred through a third-party vendor environment, with a small group of users on a Discord channel exploiting shared contractor accounts and API keys to gain entry. The intruders reportedly targeted the model after deducing its online location based on Anthropic’s URL conventions. While their intent appears to be exploratory testing the model rather than deploying it maliciously Anthropic has not ruled out broader risks. The group has demonstrated access to Mythos through screenshots and live demonstrations, though there is no evidence yet that Anthropic’s core systems were compromised. Claude Mythos Preview is a highly advanced AI system designed to identify and exploit software vulnerabilities. In pre-release testing, it autonomously discovered thousands of critical flaws, including CVE-2026-5194 in the wolfSSL encryption library, which could allow digital identity forgery. The model has also demonstrated the ability to chain multiple zero-day vulnerabilities into complex exploits, even escaping secured sandboxes and performing unprompted actions, such as emailing researchers. Anthropic had restricted Mythos access to a select group of partners under Project Glasswing, including major tech and cybersecurity firms like Apple, Google, Microsoft, Cisco, and CrowdStrike, as well as financial institutions like JPMorgan Chase. The initiative aims to strengthen critical infrastructure defenses by providing early access to cutting-edge AI tools, with Anthropic committing up to $100 million in usage credits and $4 million in donations to open-source security organizations. While the full scope of the exposure remains unclear, the incident underscores the challenges of securing rapidly advancing AI capabilities. Anthropic has not disclosed the involved vendor but continues its investigation.
INCIDENT DETAILS -
TYPE
Unauthorized Access
MOTIVATION
Exploratory testing of AI model
IMPACT
Data Compromised: Access to unreleased AI model (*Claude Mythos Preview*)Systems Affected: Third-party vendor environment, *Claude Mythos Preview* AI modelBrand Reputation Impact: Potential reputational damage due to unauthorized access to advanced AI model
DATA BREACH
Type Of Data Compromised: AI model access, potential vulnerability data (*CVE-2026-5194*)Sensitivity Of Data: High (unreleased AI model with advanced vulnerability exploitation capabilities)
APRIL 2026
559Before Incident
Breach
03 Apr 2026Mercor
Mercor: Meta Halts Mercor Partnership After AI Training Data Breach

Meta Halts AI Data Partnership After Potential Breach Exposes Proprietary Training Secrets

492After Incident
CRITICAL-67
MER1775255558
Meta Halts AI Data Partnership After Potential Breach Exposes Proprietary Training Secrets Meta has suspended its collaboration with AI data vendor Mercor following a security breach that may have exposed closely guarded details about its AI training methodologies. The incident, first reported by Wired, has triggered investigations by multiple leading AI labs that also relied on the startup’s services. Mercor, a key player in the AI data ecosystem, provides specialized data labeling and processing for companies developing large language models. The breach potentially compromised sensitive information including data selection criteria, labeling protocols, and training strategies that firms treat as highly confidential intellectual property. In an industry where proprietary training methods are considered a competitive advantage, the leak represents a significant intelligence setback. While the full extent of affected companies remains unclear, the incident underscores the high stakes of AI development, where billions are invested in refining models. Meta’s decision to pause the partnership reflects broader concerns about the security of third-party vendors in the AI supply chain.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
Data Compromised: Proprietary AI training methodologies, data selection criteria, labeling protocols, and training strategiesOperational Impact: Suspension of collaboration with AI data vendor Mercor
DATA BREACH
Type Of Data Compromised: Proprietary AI training methodologies, data selection criteria, labeling protocols, and training strategiesSensitivity Of Data: High
APRIL 2026
564Before Incident
Vulnerability
01 Apr 2026Mercor
LiteLLM and Mercor: Mercor Hit by Supply Chain Attack via LiteLLM Breach

AI Recruiting Startup Mercor Hit by Supply Chain Attack via Compromised LiteLLM Project

559After Incident
CRITICAL-5
MERLIT1775010644
AI Recruiting Startup Mercor Hit by Supply Chain Attack via Compromised LiteLLM Project AI-powered recruiting platform Mercor has confirmed a supply chain attack that exploited vulnerabilities in LiteLLM, an open-source proxy tool widely used in the AI industry. The breach, claimed by an extortion hacking crew, highlights the growing risks of third-party dependencies in AI infrastructure. The attack originated from LiteLLM, a popular open-source project that simplifies API calls to major LLM providers like OpenAI and Anthropic. By compromising the tool, attackers potentially gained access to any system running the vulnerable code, amplifying the breach’s impact across the AI ecosystem. Mercor, which uses AI to match companies with global technical talent, is now assessing the fallout. While the full scope of stolen data remains undisclosed, the incident raises concerns about the exposure of employee and candidate information. The breach comes at a critical time for the company, which has been positioning itself as a leader in AI-driven recruitment. This attack underscores the cascading security risks posed by open-source dependencies in AI development, as startups increasingly rely on third-party tools to power their operations.
INCIDENT DETAILS -
TYPE
Supply Chain Attack
MOTIVATION
Extortion
IMPACT
Data Compromised: Employee and candidate information (potential exposure)Systems Affected: Systems running vulnerable LiteLLM codeBrand Reputation Impact: Potential reputational damage due to breach during critical growth phaseIdentity Theft Risk: Potential risk due to exposure of employee and candidate information
DATA BREACH
Type Of Data Compromised: Employee and candidate informationSensitivity Of Data: High (personally identifiable information)Personally Identifiable Information: Yes
APRIL 2026
586Before Incident
Cyber Attack
31 Mar 2026Mercor
OpenAI: Meta Pauses Work With Mercor After Data Breach Puts AI Industry Secrets at Risk

Meta and AI Labs Pause Work with Mercor Following Major Security Breach

691After Incident
CRITICAL-105
OPE1775256197
Meta and AI Labs Pause Work with Mercor Following Major Security Breach Meta has indefinitely suspended all projects with data contracting firm Mercor after a significant security breach exposed sensitive systems, according to sources familiar with the matter. The incident has prompted other major AI labs, including OpenAI and Anthropic, to reassess their partnerships with the startup as they evaluate the scope of the compromise. Mercor specializes in generating proprietary training datasets for leading AI models, such as those powering ChatGPT and Claude, by employing large networks of human contractors. These datasets are closely guarded, as they contain critical insights into AI training methodologies information that could benefit competitors, including labs in the U.S. and China. It remains unclear whether the exposed data would provide a meaningful advantage to rivals. OpenAI confirmed it is investigating the breach to determine if its proprietary training data was compromised but stated that user data remains unaffected. Anthropic has not yet responded to requests for comment. Mercor acknowledged the attack in a March 31 internal email, describing it as part of a broader cyber incident affecting "thousands of organizations worldwide." Contractors working on Meta’s Chordus project an initiative to improve AI response verification were informed of a pause in work, with some facing potential unpaid leave until projects resume. The company is reportedly seeking alternative assignments for affected workers. The breach appears linked to TeamPCP, a threat actor that recently compromised two versions of the AI API tool LiteLLM, distributing tainted updates that exposed numerous organizations. While the full extent of the fallout remains unclear, the incident highlights the supply chain risks in AI development, where third-party vendors handle highly sensitive data. Adding to the confusion, a group claiming to be Lapsus$ advertised stolen Mercor data including a 200+ GB database, 1 TB of source code, and 3 TB of video files on Telegram and a BreachForums clone. However, cybersecurity researchers, including Allan Liska of Recorded Future, dismiss the claim, noting that TeamPCP is the likely culprit. Unlike the original Lapsus$, which targeted high-profile tech firms, TeamPCP has been linked to financially motivated attacks, ransomware operations, and even geopolitically driven malware, such as the CanisterWorm data-wiping tool targeting Iranian cloud systems. The breach underscores the secrecy and vulnerability of AI data contractors, many of which like Surge, Handshake, Turing, Labelbox, and Scale AI operate under strict confidentiality, often using codenames for projects. As AI labs increasingly rely on external firms for critical training data, the incident raises concerns about security standards in an industry where even minor exposures could have far-reaching consequences.
INCIDENT DETAILS -
TYPE
Data Breach
MOTIVATION
Financial GainRansomwareGeopolitical
IMPACT
Data Compromised: Proprietary training datasets, 200+ GB database, 1 TB of source code, 3 TB of video filesSystems Affected: AI training data systems, contractor networksDowntime: Projects paused indefinitely, contractors facing unpaid leaveOperational Impact: Suspension of AI training data projects, reassessment of partnershipsBrand Reputation Impact: High (loss of trust in third-party vendors)
DATA BREACH
Proprietary training datasetsSource codeVideo filesSensitivity Of Data: High (AI training methodologies, competitive insights)Data Exfiltration: Yes (advertised on Telegram and BreachForums clone)DatabaseSource codeVideo files
MARCH 2026
607Before Incident
Cyber Attack
28 Mar 2026Mercor
Hasbro and Nucor: Hasbro takes some systems offline after cybersecurity incident

Hasbro Cyberattack Disrupting Operations and Shipments

586After Incident
CRITICAL-21
NUCHAS1775060645
Hasbro Discloses Cyberattack Disrupting Operations and Shipments Toy and entertainment giant Hasbro revealed in a Securities and Exchange Commission (SEC) filing on Wednesday that a cyberattack has disrupted its ability to process orders and ship products. The company’s IT team detected unauthorized access on March 28, prompting immediate containment efforts, including taking some systems offline. Hasbro has activated business continuity plans to maintain key operations while addressing the incident, though delays are expected to persist for several weeks. The company is also reviewing potentially impacted files to determine whether regulatory notifications are required. No hacking group has claimed responsibility as of Monday, and an investigation remains ongoing. The attack adds Hasbro to a growing list of companies including Nucor, Masimo, and Clorox that have reported operational disruptions following cyber incidents in recent months. With $4.7 billion in 2025 revenue, Hasbro ranks among the largest toy and intellectual property manufacturers globally. The sector has seen prior ransomware attacks, with companies like Jakks Pacific and Bandai Namco targeted in previous years.
INCIDENT DETAILS -
TYPE
Cyberattack
IMPACT
Systems Affected: Order processing and shipment systemsDowntime: Several weeksOperational Impact: Disrupted ability to process orders and ship products
MARCH 2026
696Before Incident
Breach
19 Mar 2026Mercor
Anthropic: Details leak on Anthropic’s “step-change” Mythos model

Anthropic’s Next-Gen AI Model Exposed in Data Leak Ahead of Launch

606After Incident
CRITICAL-90
ANT1774621550
Anthropic’s Next-Gen AI Model Exposed in Data Leak Ahead of Launch Anthropic has acknowledged a data leak exposing details about Claude Mythos (internally codenamed Capybara), a new AI model the company describes as a "step change" in capabilities. The breach, discovered by security researchers Roy Paz of LayerX Security and Alexandre Pauwels of the University of Cambridge, stemmed from a misconfigured content management system (CMS) that left nearly 3,000 unpublished assets including a draft blog post publicly accessible. Anthropic attributed the incident to "human error" in the CMS settings, which defaulted to public URLs unless manually restricted. The company secured the data after being alerted by Fortune on Thursday. The leaked documents reveal Capybara as a fourth, premium-tier model positioned above Anthropic’s current flagship Opus line. According to the draft, it outperforms Claude Opus 4.6 which recently topped Terminal-Bench 2.0 with a 65.4% score across software coding, academic reasoning, and cybersecurity benchmarks. Anthropic confirmed the model’s development, calling it "the most capable we’ve built to date" but emphasizing a cautious rollout due to its advanced capabilities. Cybersecurity risks are a key concern. The draft warns that Mythos is "far ahead of any other AI model in cyber capabilities," raising fears of accelerated vulnerability exploitation that could outpace defensive measures. In response, Anthropic plans to restrict early access to cyber defense-focused organizations, allowing them time to bolster protections. The company has previously intervened in misuse cases, including disrupting a Chinese state-sponsored campaign that leveraged Claude to infiltrate 30 organizations. Earlier tests also demonstrated how Claude could be repurposed as a malware factory within hours. Additional leaked materials included details about an invite-only retreat for European CEOs at an 18th-century English manor, hosted by Anthropic CEO Dario Amodei. The event is part of a series the company has held over the past year.
INCIDENT DETAILS -
TYPE
Data Leak
IMPACT
Data Compromised: Details about *Claude Mythos* (Capybara), including draft blog posts, model capabilities, and internal event detailsSystems Affected: Content Management System (CMS)Brand Reputation Impact: Potential reputational damage due to premature exposure of sensitive AI model details
DATA BREACH
Type Of Data Compromised: AI model details, draft blog posts, internal event informationNumber Of Records Exposed: Nearly 3,000 unpublished assetsSensitivity Of Data: High (unreleased AI model capabilities, strategic plans)
FEBRUARY 2026
695Before Incident
JANUARY 2026
694Before Incident
DECEMBER 2025
693Before Incident
NOVEMBER 2025
692Before Incident
OCTOBER 2025
691Before Incident
APRIL 2025
748Before Incident
Breach
28 Apr 2025Mercor
Mercor: AI for investors

AI Recruiting Unicorn Mercor Hit by Supply Chain Attack via Compromised LiteLLM Library

684After Incident
CRITICAL-64
MER1775112166
AI Recruiting Unicorn Mercor Hit by Supply Chain Attack via Compromised LiteLLM Library Mercor, a $10 billion AI recruiting startup, confirmed a major security breach stemming from malicious code injected into the open-source LiteLLM project a widely used library that powers thousands of companies globally. The incident, classified as a supply chain attack, exposed sensitive data and underscored systemic risks in AI infrastructure dependencies. ### Breach Timeline and Discovery Security researchers at Snyk detected the malicious code in LiteLLM last week, prompting its removal within hours. However, the exposure window allowed threat actors to compromise downstream systems. Mercor first noticed anomalous activity on April 28, 2025, with extortion group Lapsus$ claiming responsibility the following day. The group posted samples of stolen data on its leak site, including Slack communications, ticketing system records, and videos of AI-contractor interactions. ### Scope of Compromised Data The breach exposed: - Contractor data, including professional credentials and payment details. - Proprietary AI training data and client information tied to partnerships with OpenAI and Anthropic. - Internal communications and operational records. Mercor, which connects specialized professionals (scientists, doctors, lawyers) with AI firms for training and validation, processes over $2 million in daily payouts. The company acknowledged it was one of thousands affected by the LiteLLM compromise. ### Threat Actors and Investigation The attack involved two distinct groups: 1. TeamPCP, a hacking collective with suspected nation-state ties, executed the initial supply chain compromise. 2. Lapsus$, known for high-profile breaches (NVIDIA, Microsoft, Okta), later claimed responsibility for data exfiltration and extortion. Investigators are still determining whether the groups collaborated or if Lapsus$ independently accessed the stolen data. Mercor is working with third-party forensics experts to assess the full impact. ### Broader Implications The breach highlights critical vulnerabilities in AI infrastructure, particularly the risks of relying on open-source tools like LiteLLM a project maintained by a Y Combinator-backed startup. The incident reveals how a single compromise can cascade across industries, exposing sensitive data in AI training pipelines. The involvement of TeamPCP, linked to state-sponsored operations, suggests potential motives beyond financial gain, including intelligence gathering on AI methodologies and contractor networks. Mercor’s rapid growth valued at $10 billion after a $350 million Series C in October 2025 makes it a prime target, but the attack’s ripple effects extend to the broader tech ecosystem. The ambiguity around the threat actors’ roles further complicates mitigation efforts.
INCIDENT DETAILS -
TYPE
Supply Chain Attack
MOTIVATION
ExtortionIntelligence gathering on AI methodologies and contractor networks
IMPACT
Slack communicationsTicketing systemAI training pipelinesOperational Impact: Exposure of proprietary AI training data and client information
DATA BREACH
Contractor data (professional credentials, payment details)Proprietary AI training dataClient informationInternal communicationsOperational recordsSensitivity Of Data: HighSlack communicationsTicketing system recordsVideos of AI-contractor interactions

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for Mercor ?
?
What was Mercor's A.I Rankiteo Cyber Score in August 2026 ?
?
What was Mercor's A.I Rankiteo Cyber Score in July 2026 ?
?
What was Mercor's A.I Rankiteo Cyber Score in June 2026 ?
?
What was Mercor's A.I Rankiteo Cyber Score in May 2026 ?
?
What was Mercor's A.I Rankiteo Cyber Score in April 2026 ?
?
What was Mercor's A.I Rankiteo Cyber Score in March 2026 ?
?
What was Mercor's A.I Rankiteo Cyber Score in February 2026 ?
?
What was Mercor's A.I Rankiteo Cyber Score in January 2026 ?
?
What was Mercor's A.I Rankiteo Cyber Score in December 2025 ?
?
What was Mercor's A.I Rankiteo Cyber Score in November 2025 ?
?
What was Mercor's A.I Rankiteo Cyber Score in October 2025 ?
?
What is the average per-incident point impact on Mercor's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with Mercor ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view Mercor's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?