Mercor.io Corporation Data Breach Notification

Mercor has notified certain individuals that their personal information may have been exposed after an unauthorized actor tampered with a widely used code scanning tool from LiteLLM. According to the letter, the attacker inserted malware into certain versions of that tool, and because Mercor used it, the malware allowed the intruder to access some of Mercor’s systems between March 24 and March 30, 2026. Mercor says it detected and blocked the activity, then worked with outside security experts to investigate — a process that took several months before the company could confirm exactly what data was taken.

The notice is written to a specific individual described as an expert who worked with Mercor, rather than to the public at large, and the copy of the letter available to us does not include an aggregate figure for how many people were affected overall.

What information was exposed?
  • The letter states that Mercor completed a review of the downloaded data and identified specific categories of personal information affected, but the section of the notice listing those categories was left blank in the version filed with regulators, so we cannot confirm exactly which data types were involved for this notice.
  • Mercor’s decision to offer 24 months of credit monitoring and identity restoration services suggests the company considered the exposed information sensitive enough to warrant those protections.

Mercor is offering 24 months of complimentary credit monitoring and identity restoration services through TransUnion’s Cyberscout division. To activate, visit https://bfs.cyberscout.com/activate and enter the unique activation code included in your individual copy of the letter. You must enroll by October 1, 2026 — after that date, the code will no longer work.

What should you do now?
  • Enroll in the free TransUnion credit monitoring and identity restoration services before the October 1, 2026 deadline, since this protection expires if you don’t sign up in time.
  • Review your credit card and bank statements regularly for any charges or accounts you don’t recognize.
  • Request your free annual credit reports from all three bureaus at annualcreditreport.com or by calling 1-877-322-8228, and check them for accounts opened in your name.
  • Consider placing a fraud alert or a security freeze with Equifax, Experian, and TransUnion, especially since the exact data exposed hasn’t been confirmed in this notice — a freeze is free and prevents new accounts from being opened in your name without your authorization.
  • Given the uncertainty about what specific data was taken, consider signing up for a service like Aura or LifeLock, which can alert you if your information appears elsewhere, such as on the dark web or in new credit applications.
  • If you notice suspicious activity, contact your local police and file a report — this can help support any identity theft claims later.

If you have questions, Mercor can be reached at 1-844-507-8047, available 8 a.m. to 8 p.m. ET Monday through Friday, excluding major U.S. holidays.

Leave a Comment