Hackers claim they have stolen and are selling 4TB of databases and source code from AI recruiting company Mercor. The alleged Mercor data breach has not been independently confirmed, and the company had not publicly commented on the new claim at the time of reporting.
Mercor works with major AI companies, including OpenAI, Google, Meta and Microsoft. The attackers posted the alleged data on a cybercrime forum and claimed it contains extensive company information.
Cybernews researchers reviewed samples attached to the listing. The samples reportedly included user logs, prompts and records showing system users and their roles.
Alleged files could expose sensitive activity
If genuine, the alleged Mercor data breach could reveal information about users, hiring activity and internal platform operations.
Prompts and user logs can contain private conversations, business workflows and information entered by candidates or customers. User-role data may also show who holds administrative access or other responsibilities within a system.
Attackers could combine that information with other leaked datasets to carry out phishing, impersonation and targeted social-engineering attacks.
The forum post claims that the stolen material includes both databases and source code. However, researchers and affected companies need more evidence before they can confirm the scope, source or authenticity of the alleged files.
Mercor previously disclosed a supply-chain incident
The latest claim follows a separate security incident that Mercor disclosed earlier in 2026.
In March, compromised versions of the LiteLLM open-source library reportedly targeted credentials on systems that installed them. Mercor later said attackers had accessed a limited subset of sensitive contractor information.
The earlier incident reportedly involved highly sensitive data, including government identification documents, payment information, biometric data, voice recordings and AI video interview footage.
Mercor said its security team detected the activity, contained unauthorised access and worked with outside security partners and law enforcement during the investigation.
Connection between incidents remains unclear
The new listing also refers to 4TB of alleged stolen data. Earlier reporting linked a similar volume of contractor data to the LiteLLM supply-chain incident.
That matching figure is notable, but it does not prove that the two events are connected. The alleged Mercor data breach could involve previously stolen material, a new intrusion, exaggerated claims or a mixture of datasets.
Until Mercor or an independent investigation verifies the listing, the claim should remain unconfirmed.
Users should stay alert for targeted scams
People who have used Mercor’s platform should remain cautious, particularly if they receive unexpected job offers, account alerts or requests for documents.
A leak involving prompts, logs or user roles can give criminals useful context for convincing scams. Users should avoid sharing credentials or identity documents through unsolicited messages and should verify job-related communications through official channels.


0 responses to “Hackers Claim 4TB Mercor Data Breach Haul”