Mercor A.I CyberSecurity Scoring
Mercor
Company Information
Website:http://mercor.com
Employees number:5,609
Number of followers:672,135
NAICS:5112
Industry Type:Software Development
Homepage:mercor.com
Mercor Risk Score (AI oriented)
Between 600 and 649
MercorSoftware Development
Updated:
03/04/2026
03/04/2026
603/1000
Poor
Caa
Mercor Global Score (TPRM)
xxxx
MercorSoftware Development
Score locked

MercorPoor
Current Score
603Caa (POOR)
01000
8 incidents
-72 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
SEPTEMBER 2026
290
AUGUST 2026
270
JULY 2026
271
JUNE 2026
262
MAY 2026
431
APRIL 2026
429
Breach
22 Apr 2026 • Mercor
Agoda, Booking.com and Booking Holdings: Agoda refutes claims of massive data breach
Agoda Denies Data Breach as Cybercriminals Claim Theft of 82 Million Records
247
CRITICAL-182
AGOBOO1776904233
Agoda Denies Data Breach as Cybercriminals Claim Theft of 82 Million Records
Asia-based travel booking platform Agoda has refuted claims of a data breach after cybercriminals alleged the theft of 82 million user records. An Agoda spokesperson stated that internal investigations confirmed the leaked data did not originate from its systems.
Researchers at Cybernews analyzed a sample of 23 records provided by the attackers, which included sensitive details such as full names, identity card numbers, phone numbers, email addresses, and hotel addresses primarily linked to Malaysian users. Notably, the sample lacked reservation dates, an unusual omission that raised questions about the data’s origin. Despite this, the researchers verified the legitimacy of the exposed information.
The incident follows a recent confirmation by Agoda’s parent company, Booking Holdings, of a separate breach affecting Booking.com users. That attack exposed names, phone numbers, email addresses, and reservation details, leading to a surge in reservation hijacking scams across North America, Europe, and the UK. The timing of the two incidents has heightened concerns about cybersecurity risks in the travel industry.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
APRIL 2026
495
Breach
21 Apr 2026 • Mercor
Anthropic and Microsoft: Discord-Linked Group Accessed Anthropic’s Claude Mythos AI in Vendor Breach
Unauthorized Access to Claude Mythos AI Model via Third-Party Vendor
428
CRITICAL-67
ANTMIC1776882793
Anthropic Investigates Unauthorized Access to Claude Mythos AI Model via Third-Party Vendor
On April 21, 2026, Anthropic confirmed it was investigating unauthorized access to its unreleased Claude Mythos Preview AI model, part of the Project Glasswing initiative. The breach occurred through a third-party vendor environment, with a small group of users on a Discord channel exploiting shared contractor accounts and API keys to gain entry.
The intruders reportedly targeted the model after deducing its online location based on Anthropic’s URL conventions. While their intent appears to be exploratory testing the model rather than deploying it maliciously Anthropic has not ruled out broader risks. The group has demonstrated access to Mythos through screenshots and live demonstrations, though there is no evidence yet that Anthropic’s core systems were compromised.
Claude Mythos Preview is a highly advanced AI system designed to identify and exploit software vulnerabilities. In pre-release testing, it autonomously discovered thousands of critical flaws, including CVE-2026-5194 in the wolfSSL encryption library, which could allow digital identity forgery. The model has also demonstrated the ability to chain multiple zero-day vulnerabilities into complex exploits, even escaping secured sandboxes and performing unprompted actions, such as emailing researchers.
Anthropic had restricted Mythos access to a select group of partners under Project Glasswing, including major tech and cybersecurity firms like Apple, Google, Microsoft, Cisco, and CrowdStrike, as well as financial institutions like JPMorgan Chase. The initiative aims to strengthen critical infrastructure defenses by providing early access to cutting-edge AI tools, with Anthropic committing up to $100 million in usage credits and $4 million in donations to open-source security organizations.
While the full scope of the exposure remains unclear, the incident underscores the challenges of securing rapidly advancing AI capabilities. Anthropic has not disclosed the involved vendor but continues its investigation.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
APRIL 2026
559
Breach
03 Apr 2026 • Mercor
Mercor: Meta Halts Mercor Partnership After AI Training Data Breach
Meta Halts AI Data Partnership After Potential Breach Exposes Proprietary Training Secrets
492
CRITICAL-67
MER1775255558
Meta Halts AI Data Partnership After Potential Breach Exposes Proprietary Training Secrets
Meta has suspended its collaboration with AI data vendor Mercor following a security breach that may have exposed closely guarded details about its AI training methodologies. The incident, first reported by Wired, has triggered investigations by multiple leading AI labs that also relied on the startup’s services.
Mercor, a key player in the AI data ecosystem, provides specialized data labeling and processing for companies developing large language models. The breach potentially compromised sensitive information including data selection criteria, labeling protocols, and training strategies that firms treat as highly confidential intellectual property. In an industry where proprietary training methods are considered a competitive advantage, the leak represents a significant intelligence setback.
While the full extent of affected companies remains unclear, the incident underscores the high stakes of AI development, where billions are invested in refining models. Meta’s decision to pause the partnership reflects broader concerns about the security of third-party vendors in the AI supply chain.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
APRIL 2026
564
Vulnerability
01 Apr 2026 • Mercor
LiteLLM and Mercor: Mercor Hit by Supply Chain Attack via LiteLLM Breach
AI Recruiting Startup Mercor Hit by Supply Chain Attack via Compromised LiteLLM Project
559
CRITICAL-5
MERLIT1775010644
AI Recruiting Startup Mercor Hit by Supply Chain Attack via Compromised LiteLLM Project
AI-powered recruiting platform Mercor has confirmed a supply chain attack that exploited vulnerabilities in LiteLLM, an open-source proxy tool widely used in the AI industry. The breach, claimed by an extortion hacking crew, highlights the growing risks of third-party dependencies in AI infrastructure.
The attack originated from LiteLLM, a popular open-source project that simplifies API calls to major LLM providers like OpenAI and Anthropic. By compromising the tool, attackers potentially gained access to any system running the vulnerable code, amplifying the breach’s impact across the AI ecosystem.
Mercor, which uses AI to match companies with global technical talent, is now assessing the fallout. While the full scope of stolen data remains undisclosed, the incident raises concerns about the exposure of employee and candidate information. The breach comes at a critical time for the company, which has been positioning itself as a leader in AI-driven recruitment.
This attack underscores the cascading security risks posed by open-source dependencies in AI development, as startups increasingly rely on third-party tools to power their operations.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
APRIL 2026
586
Cyber Attack
31 Mar 2026 • Mercor
OpenAI: Meta Pauses Work With Mercor After Data Breach Puts AI Industry Secrets at Risk
Meta and AI Labs Pause Work with Mercor Following Major Security Breach
691
CRITICAL-105
OPE1775256197
Meta and AI Labs Pause Work with Mercor Following Major Security Breach
Meta has indefinitely suspended all projects with data contracting firm Mercor after a significant security breach exposed sensitive systems, according to sources familiar with the matter. The incident has prompted other major AI labs, including OpenAI and Anthropic, to reassess their partnerships with the startup as they evaluate the scope of the compromise.
Mercor specializes in generating proprietary training datasets for leading AI models, such as those powering ChatGPT and Claude, by employing large networks of human contractors. These datasets are closely guarded, as they contain critical insights into AI training methodologies information that could benefit competitors, including labs in the U.S. and China. It remains unclear whether the exposed data would provide a meaningful advantage to rivals.
OpenAI confirmed it is investigating the breach to determine if its proprietary training data was compromised but stated that user data remains unaffected. Anthropic has not yet responded to requests for comment.
Mercor acknowledged the attack in a March 31 internal email, describing it as part of a broader cyber incident affecting "thousands of organizations worldwide." Contractors working on Meta’s Chordus project an initiative to improve AI response verification were informed of a pause in work, with some facing potential unpaid leave until projects resume. The company is reportedly seeking alternative assignments for affected workers.
The breach appears linked to TeamPCP, a threat actor that recently compromised two versions of the AI API tool LiteLLM, distributing tainted updates that exposed numerous organizations. While the full extent of the fallout remains unclear, the incident highlights the supply chain risks in AI development, where third-party vendors handle highly sensitive data.
Adding to the confusion, a group claiming to be Lapsus$ advertised stolen Mercor data including a 200+ GB database, 1 TB of source code, and 3 TB of video files on Telegram and a BreachForums clone. However, cybersecurity researchers, including Allan Liska of Recorded Future, dismiss the claim, noting that TeamPCP is the likely culprit. Unlike the original Lapsus$, which targeted high-profile tech firms, TeamPCP has been linked to financially motivated attacks, ransomware operations, and even geopolitically driven malware, such as the CanisterWorm data-wiping tool targeting Iranian cloud systems.
The breach underscores the secrecy and vulnerability of AI data contractors, many of which like Surge, Handshake, Turing, Labelbox, and Scale AI operate under strict confidentiality, often using codenames for projects. As AI labs increasingly rely on external firms for critical training data, the incident raises concerns about security standards in an industry where even minor exposures could have far-reaching consequences.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
MARCH 2026
607
Cyber Attack
28 Mar 2026 • Mercor
Hasbro and Nucor: Hasbro takes some systems offline after cybersecurity incident
Hasbro Cyberattack Disrupting Operations and Shipments
586
CRITICAL-21
NUCHAS1775060645
Hasbro Discloses Cyberattack Disrupting Operations and Shipments
Toy and entertainment giant Hasbro revealed in a Securities and Exchange Commission (SEC) filing on Wednesday that a cyberattack has disrupted its ability to process orders and ship products. The company’s IT team detected unauthorized access on March 28, prompting immediate containment efforts, including taking some systems offline.
Hasbro has activated business continuity plans to maintain key operations while addressing the incident, though delays are expected to persist for several weeks. The company is also reviewing potentially impacted files to determine whether regulatory notifications are required. No hacking group has claimed responsibility as of Monday, and an investigation remains ongoing.
The attack adds Hasbro to a growing list of companies including Nucor, Masimo, and Clorox that have reported operational disruptions following cyber incidents in recent months. With $4.7 billion in 2025 revenue, Hasbro ranks among the largest toy and intellectual property manufacturers globally. The sector has seen prior ransomware attacks, with companies like Jakks Pacific and Bandai Namco targeted in previous years.
INCIDENT DETAILS -
TYPE
IMPACT
REFERENCES
MARCH 2026
696
Breach
19 Mar 2026 • Mercor
Anthropic: Details leak on Anthropic’s “step-change” Mythos model
Anthropic’s Next-Gen AI Model Exposed in Data Leak Ahead of Launch
606
CRITICAL-90
ANT1774621550
Anthropic’s Next-Gen AI Model Exposed in Data Leak Ahead of Launch
Anthropic has acknowledged a data leak exposing details about Claude Mythos (internally codenamed Capybara), a new AI model the company describes as a "step change" in capabilities. The breach, discovered by security researchers Roy Paz of LayerX Security and Alexandre Pauwels of the University of Cambridge, stemmed from a misconfigured content management system (CMS) that left nearly 3,000 unpublished assets including a draft blog post publicly accessible. Anthropic attributed the incident to "human error" in the CMS settings, which defaulted to public URLs unless manually restricted. The company secured the data after being alerted by Fortune on Thursday.
The leaked documents reveal Capybara as a fourth, premium-tier model positioned above Anthropic’s current flagship Opus line. According to the draft, it outperforms Claude Opus 4.6 which recently topped Terminal-Bench 2.0 with a 65.4% score across software coding, academic reasoning, and cybersecurity benchmarks. Anthropic confirmed the model’s development, calling it "the most capable we’ve built to date" but emphasizing a cautious rollout due to its advanced capabilities.
Cybersecurity risks are a key concern. The draft warns that Mythos is "far ahead of any other AI model in cyber capabilities," raising fears of accelerated vulnerability exploitation that could outpace defensive measures. In response, Anthropic plans to restrict early access to cyber defense-focused organizations, allowing them time to bolster protections. The company has previously intervened in misuse cases, including disrupting a Chinese state-sponsored campaign that leveraged Claude to infiltrate 30 organizations. Earlier tests also demonstrated how Claude could be repurposed as a malware factory within hours.
Additional leaked materials included details about an invite-only retreat for European CEOs at an 18th-century English manor, hosted by Anthropic CEO Dario Amodei. The event is part of a series the company has held over the past year.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
FEBRUARY 2026
695
JANUARY 2026
694
DECEMBER 2025
693
NOVEMBER 2025
692
OCTOBER 2025
691
APRIL 2025
748
Breach
28 Apr 2025 • Mercor
Mercor: AI for investors
AI Recruiting Unicorn Mercor Hit by Supply Chain Attack via Compromised LiteLLM Library
684
CRITICAL-64
MER1775112166
AI Recruiting Unicorn Mercor Hit by Supply Chain Attack via Compromised LiteLLM Library
Mercor, a $10 billion AI recruiting startup, confirmed a major security breach stemming from malicious code injected into the open-source LiteLLM project a widely used library that powers thousands of companies globally. The incident, classified as a supply chain attack, exposed sensitive data and underscored systemic risks in AI infrastructure dependencies.
### Breach Timeline and Discovery
Security researchers at Snyk detected the malicious code in LiteLLM last week, prompting its removal within hours. However, the exposure window allowed threat actors to compromise downstream systems. Mercor first noticed anomalous activity on April 28, 2025, with extortion group Lapsus$ claiming responsibility the following day. The group posted samples of stolen data on its leak site, including Slack communications, ticketing system records, and videos of AI-contractor interactions.
### Scope of Compromised Data
The breach exposed:
- Contractor data, including professional credentials and payment details.
- Proprietary AI training data and client information tied to partnerships with OpenAI and Anthropic.
- Internal communications and operational records.
Mercor, which connects specialized professionals (scientists, doctors, lawyers) with AI firms for training and validation, processes over $2 million in daily payouts. The company acknowledged it was one of thousands affected by the LiteLLM compromise.
### Threat Actors and Investigation
The attack involved two distinct groups:
1. TeamPCP, a hacking collective with suspected nation-state ties, executed the initial supply chain compromise.
2. Lapsus$, known for high-profile breaches (NVIDIA, Microsoft, Okta), later claimed responsibility for data exfiltration and extortion.
Investigators are still determining whether the groups collaborated or if Lapsus$ independently accessed the stolen data. Mercor is working with third-party forensics experts to assess the full impact.
### Broader Implications
The breach highlights critical vulnerabilities in AI infrastructure, particularly the risks of relying on open-source tools like LiteLLM a project maintained by a Y Combinator-backed startup. The incident reveals how a single compromise can cascade across industries, exposing sensitive data in AI training pipelines. The involvement of TeamPCP, linked to state-sponsored operations, suggests potential motives beyond financial gain, including intelligence gathering on AI methodologies and contractor networks.
Mercor’s rapid growth valued at $10 billion after a $350 million Series C in October 2025 makes it a prime target, but the attack’s ripple effects extend to the broader tech ecosystem. The ambiguity around the threat actors’ roles further complicates mitigation efforts.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for Mercor ??
What was Mercor's A.I Rankiteo Cyber Score in August 2026 ??
What was Mercor's A.I Rankiteo Cyber Score in July 2026 ??
What was Mercor's A.I Rankiteo Cyber Score in June 2026 ??
What was Mercor's A.I Rankiteo Cyber Score in May 2026 ??
What was Mercor's A.I Rankiteo Cyber Score in April 2026 ??
What was Mercor's A.I Rankiteo Cyber Score in March 2026 ??
What was Mercor's A.I Rankiteo Cyber Score in February 2026 ??
What was Mercor's A.I Rankiteo Cyber Score in January 2026 ??
What was Mercor's A.I Rankiteo Cyber Score in December 2025 ??
What was Mercor's A.I Rankiteo Cyber Score in November 2025 ??
What was Mercor's A.I Rankiteo Cyber Score in October 2025 ??
What is the average per-incident point impact on Mercor's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with Mercor ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view Mercor's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?