Hackers claim massive 4TB haul from AI firm serving OpenAI, Google, and Meta
Multiple terabytes of data, including source code, were allegedly stolen.

Image by Cybernews
- Hackers claim they are selling 4TB of Mercor databases and source code on a cybercrime forum.
- Cybernews researchers found samples containing user logs, prompts, and system roles.
- The alleged data could expose hiring activity, private conversations, and access levels.
- Mercor previously disclosed a LiteLLM supply chain attack; it is unclear whether the incidents are connected.
Key Takeaways by nexos.ai, reviewed by Cybernews staff.
San Francisco AI company Mercor, whose clients include OpenAI, Google, Meta, and Microsoft, has allegedly been hacked, with attackers claiming to be selling 4TB of stolen company data and source code.
Mercor, a US AI recruiting company, has appeared on underground hacker marketplaces. Headquartered in San Francisco, the AI startup is currently valued at $10 billion. Mercor's major clients include the world's leading AI companies, such as OpenAI, Google, Meta, and Microsoft.
In a post on a well-known cybercrime forum, attackers are alleging that 4TB of database and source code has been exfiltrated and is now for sale.
The Cybernews research team has investigated the data samples provided with the initial listing. The data samples look comprehensive. The data exposed in the data samples include:
- User logs
- Prompts
- Users in the system and their roles
The alleged breach could put sensitive information about Mercor's users, hiring processes, and interactions with candidates in the hands of cybercriminals.
Prompts and logs can expose private conversations, operational workflows, hiring activity, and information users enter into the platform.
User roles can indicate to attackers who holds particular responsibilities or levels of access. Information about candidates and users could potentially be combined with other stolen datasets to facilitate identity theft, impersonation, phishing, and highly personalized social engineering.
Stay updated with our latest stories and follow us on social media
Be the first to discover new stories, ideas, and updates from our team.
Mercor has been hit by a cyber incident before
The latest allegation comes just months after Mercor disclosed it had been affected by a supply chain attack involving the LiteLLM open-source library.
In March 2026, attackers published compromised versions of LiteLLM designed to steal credentials from systems that installed them.
The LAPSUS$ hacking group has reportedly claimed responsibility for the incident and attempted to auction the stolen information on the dark web.
Reportedly, the incident exposed approximately 4TB of contractor data, including Social Security numbers, government identification documents, payment information, facial biometric data, voice recordings, and AI video interview footage.
Mercor said its security team detected the activity and immediately took steps to contain unauthorized access.
The company later worked with Google's Mandiant, Latacora, other industry partners, and law enforcement as part of a forensic investigation. Despite this, Meta reportedly “indefinitely” paused all work with Mercor after a breach.
On June 25th, Mercor published an update stating that the investigation had concluded. According to Mercor, only a very limited subset of its nearly 5 million experts had sensitive information affected. The company said there was no evidence that the information had been exploited in the wild.
Mercor also said customer information was affected only to a very limited extent because many of its customers operate on their own platforms rather than Mercor's. The company said no employee data was affected.
The current marketplace listing claims that attackers possess 4TB of Mercor databases and source code, while the earlier incident was also associated with allegations involving approximately 4TB of contractor data.
The matching size is notable, but it remains unknown whether the incidents are connected. Cybernews has reached out to Mercor for a comment. We will update this article once we receive a response.