On 31 March 2026, extortion activity and press coverage converged on Mercor: Lapsus$ claimed a large data theft (on the order of ~4 TB in public summaries), while Mercor confirmed to reporters a cybersecurity incident associated with the broader LiteLLM open-source supply-chain event (TeamPCP–linked malicious PyPI releases). Mercor stated it had contained and remediated promptly and engaged third-party forensics; it did not immediately validate every figure circulated on leak channels.
Why it is tracked
Where contractor resumes, interviews, and internal systems are involved, the risk model blends traditional PII with IP and trust in the AI supply chain. We document the incident as a structured 2026 record with primary sources.
Full entry: Mercor 2026 on BreachHistory.
Sources: TechCrunch, Tech Startups