Search TorNews

Find cybersecurity news, guides, and research articles

Popular searches:

Home » News » Data Breaches » Mercor Confirms Supply-Chain Breach as Hackers Claim 4TB of Source Code and User Data

Mercor Confirms Supply-Chain Breach as Hackers Claim 4TB of Source Code and User Data

By:
Last updated:September 15, 2026
Human Written
  • A dark web threat actor claims to have breached AI talent platform Mercor, advertising 4 terabytes of stolen data containing source code, candidate records, and internal files.

  • The advertised datasets allegedly contain 939 GB of source code, a 211 GB user database, 3 TB of video interview recordings, passport scans, Social Security numbers, and workspace messages.

  • Exposing internal source code and client files threatens corporate intellectual property, while stolen government identity documents and facial biometric data expose contractors to deepfake fraud and identity theft.

Hacker Claims 4TB of Mercor Data, Including Source Code and User Records

A bad actor on dark web forums claims to have hacked Mercor, a major talent platform for artificial intelligence work. The platform acts as an online marketplace for tech workers and connects skilled professionals with top technology companies. These experts perform specialized AI model training. They also handle domain evaluations and software development tasks.

The forum post advertises a massive data dump totaling roughly 4 terabytes of internal files. To support the claim, the seller uploaded multiple sample files containing proprietary platform records, identity documents, and operational data. However, independent cybersecurity research teams and forensic investigators have not publicly validated the complete scope or authenticity of the advertised datasets.

Detailed Breakdown of the Advertised Datasets and Exposed Materials

The cybercriminal provided a structured breakdown of the exfiltrated material across several distinct files. The listing claims to contain 939 gigabytes of internal platform source code, exposing proprietary application logic and algorithmic evaluation scripts. Furthermore, the seller offers a 211-gigabyte main user database that stores candidate profiles, contact information, and account details.

The largest single component of the breach consists of a 3-terabyte contractor dataset. It consists of recorded interviews in video format and assessments of the candidates. Also, it contains received and sent internal messages regarding employees in the organization.

In addition, the leaked data includes personal details, such as passport photos, driving licenses, and Social Security numbers acquired during identity verification processes.

Consequently, security analysts who reviewed the forum listing noted that the breach combines general user tracking with deep biometric and identity records. The seller also claims to possess proprietary artificial intelligence training artifacts, internal documentation, and file attachments extracted from connected workspace collaboration tools.

Therefore, the exposure threatens both corporate software intellectual property and individual applicant privacy across multiple geographic regions.

Strategic AI Supply Chain Risks and Intellectual Property Exposure

The exposure of proprietary platform source code and training artifacts presents severe operational risks for the artificial intelligence industry. Modern talent marketplaces rely on complex matching algorithms and automated evaluation models to score technical candidates.

When threat actors leak proprietary platform code, competing organizations or malicious groups can analyze the internal logic to reverse-engineer matching systems or bypass skill verification checks.

Furthermore, leaking internal workspace communications exposes private business arrangements between talent brokers and frontier AI development labs. Threat actors can inspect internal task files to identify specialized projects, proprietary dataset formats, and specific evaluation metrics used by client enterprises. Consequently, exposing these collaborative workspace materials creates significant commercial damage and disrupts sensitive technology development pipelines.

In addition, security researchers emphasize that centralizing sensitive training data creates a highly attractive target for global cybercriminals. One central platform might store thousands of developer resumes. It may also hold secret code evaluation rules. A single system breach then damages dozens of partner companies.

AI companies face similar risks when attackers exploit weaknesses in their wider supply chains. In a separate incident, hackers claimed 4TB of data theft from Mercor AI in a supply chain attack, showing how attacks on connected systems can expose large volumes of sensitive information.

Because of this, tech security groups urge vendors to act. Software companies must enforce strict zero-trust access controls. They need these rules across all secondary developer tools. Finally, they must secure all internal database environments.

Severe Identity Theft and Biometric Exploitation Hazards

The addition of government identity credentials, tax identification numbers, and video interview records exposes thousands of independent contractors to high identity fraud risks. Cyber thieves frequently acquire stolen passport copies, Social Security Numbers from the dark web to execute fraud application loans.

Also, such data enable synthetic identity theft and compromise of secondary financial accounts. By blending genuine government records with valid contact data, fraudsters undertake highly believable social engineering scams.

In addition, the release of 3 terabytes of high-definition video interview recordings brings forth a whole new set of obstacles to biometric privacy. Malicious actors can extract facial biometric features and clear voice samples from recorded video files. Subsequently, fraudsters can feed these stolen biometric samples into deepfake generation tools to bypass identity verification checks on external platforms.

Furthermore, experts in the security field raise alarm about the possibility of exploiting recorded interviews for phishing attacks on victims. Criminals can refer to some technologies, interview dates and feedback records to pose as recruiters or corporate software clients.

Affected contractors must stay vigilant and monitor personal credit reports continuously. Also, they should report unexpected identity verification alerts to relevant fraud monitoring agencies immediately.

Forensic Verification Status and Preventive Guidance

At this stage, the security research teams continue their work on the samples they posted to see if the dataset contains a new case of intrusion or if it is a collection of earlier incidents. But the presence of specific platform source code files and contractor interview samples indicates a genuine security incident. This means it requires immediate forensic investigation.

Meanwhile, specialists who registered at the talent platform should promptly take measures to protect their personal digital traces. Candidates need to change all their passwords for different accounts.

Also, they should activate two-factor authentication via special applications and freeze their accounts in all credit bureaus. In addition, those who uploaded their passport copies or tax documents need to pay more attention to their bank accounts for cases of credit applications without their knowledge.

This incident highlights the growing cybersecurity risks surrounding central HR technology platforms and AI workforce platforms. Organizations handling delicate identity records of employees must abide by stringent protocols concerning full-cycle data encryption. Also, they should have automatic audits of access to their databases.

Share this article

About the Author

Joahn G

Joahn G

Cyber Threat Journalist

Joahn is a cyber threat journalist dedicated to tracking the evolving landscape of digital risks. His reporting focuses on ransomware gangs, data breach incidents, and state-sponsored cyber operations. By analyzing threat actor motives and tactics, he provides timely intelligence that helps readers understand and anticipate the security challenges of tomorrow.

View all posts by Joahn G >
Comments (0)

No comments.