Hackers Claim to Have Stolen 4TB of Data from an OpenAI, Google, and Meta Partner

26.08.2026 3 minutes Author: Newsman

San Francisco-based AI company Mercor, which works with OpenAI, Google, Meta, and Microsoft, has allegedly suffered a major breach. The attackers claim to have stolen 4TB of the company’s databases and source code and put the data up for sale.

Information about the alleged Mercor data breach appeared on underground hacking forums. The US startup specializes in recruiting AI professionals and is currently valued at $10 billion. Its major clients reportedly include OpenAI, Google, Meta, and Microsoft.

In a post published on a well-known cybercrime forum, the attackers claimed to have stolen 4TB of Mercor databases and source code. The materials have allegedly been put up for sale.

The research team analyzed the samples attached to the listing. According to the researchers, the disclosed materials appear extensive and well-structured. They include:

  • user activity logs;
  • prompts submitted to the system by users;
  • information about users and their roles within the system.

If the breach is confirmed, cybercriminals may have obtained sensitive information about Mercor users, recruitment processes, and communications with candidates.

Prompts and activity logs could expose private conversations, internal workflows, recruitment activity, and information entered by users into the platform.

System role data could help attackers determine which areas specific users are responsible for and what levels of access they have.

Information about candidates and users could also be combined with data from other breaches. This increases the risk of identity theft, impersonation, phishing attacks, and highly personalized social engineering.

Mercor Had Previously Suffered a Cybersecurity Incident

The attackers’ latest claim emerged only a few months after Mercor disclosed that it had been affected by a supply chain attack involving the open-source LiteLLM library.

In March 2026, attackers published compromised versions of LiteLLM designed to steal credentials from systems on which they were installed.

According to available information, the LAPSUS$ hacking group claimed responsibility for the incident. The attackers also attempted to auction the stolen information on the dark web.

The incident may have exposed approximately 4TB of contractor data, including Social Security numbers, government-issued identification documents, payment information, facial biometric data, voice recordings, and footage from AI-powered video interviews.

Mercor said its security team detected the suspicious activity and immediately took steps to stop the unauthorized access.

The company later brought in experts from Mandiant and Latacora, other industry partners, and law enforcement agencies to assist with the investigation. Despite these efforts, Meta reportedly suspended all work with Mercor “indefinitely” following the incident.

On June 25th, Mercor published an update announcing that the investigation had concluded. According to the company, sensitive information was compromised for only a very limited portion of the nearly five million experts registered on its platform. Mercor also said it had found no evidence that the data had been exploited by malicious actors.

Mercor said customer information was affected only to a very limited extent because many clients operate through their own platforms rather than the company’s system. The company also stated that no employee data had been compromised.

The new listing on a cybercrime marketplace claims that the attackers possess 4TB of Mercor databases and source code. The previous incident was also linked to the alleged theft of approximately 4TB of information, although that data primarily concerned contractors. The matching volume is notable, but it remains unclear whether the two incidents are connected.

Subscribe
Notify of
0 Коментарі
Oldest
Newest Most Voted
Found an error?
If you find an error, take a screenshot and send it to the bot.