Technical Analysis of the Mercor Data Breach Incident
Key point
Hacking group Lapsus$ leaked a massive amount of Mercor's operational data, and even after ransom payment, a serious security incident occurred in which data samples were publicly released.
Details
The hacking group Lapsus$ leaked a massive amount of Mercor's operational data. The scale of the leak is enormous, including a 211GB production database, 939GB of source code, 3TB of cloud storage, Slack exports, and Tailscale VPN data.
Despite reports that Mercor paid the ransom, Lapsus$ has released data samples and is attempting to sell the full dataset. This analysis was conducted based on two small sample files that were made public (a database schema and some Airtable export files), which represent only a tiny fraction of the entire leaked dataset.
The leaked data contains the following sensitive information:
- User and identity information: PII, financial identifiers, bank account information, Persona KYC session tokens
- AI and operational data: Apple Foundation Model outputs, project and AI task management information, desktop screenshot URLs
- Recruitment and work process: recruitment pipelines, interview and evaluation data, work tests and onboarding information
- Infrastructure and communications: system architecture, time tracking and productivity surveillance data, communication and outreach records
This incident is being assessed as an extremely serious security threat, as it goes beyond simple personal information leakage to expose the company's core assets, including AI training data and its overall infrastructure.
This summary was generated automatically by AI. Check the original for the author's claims and context. Copyright belongs to the original author.
Our guide explains how the AI works. Report summary errors, attribution issues, or removal requests via Contact.