Is Mercor Legit? A Look at the AI Hiring Startup's Track Record
Mercor is a real company, not a scam. It's a San Francisco startup that pays experts to help train AI models for clients including OpenAI and Anthropic, and it's backed by hundreds of millions of dollars from venture firms like Benchmark and General Catalyst. The question worth asking isn't whether Mercor exists. It's what happened to a data breach that hit millions of its contractors in 2026, and why a chunk of its workforce saw their pay cut with little warning months earlier.
In short: Mercor is a legitimate, venture-backed AI talent marketplace founded in 2023, now valued at roughly $10 billion. It pays contractors real money for real work, and Trustpilot reviews back that up. But a March 2026 supply-chain attack exposed Social Security numbers and ID documents for a subset of its nearly 5 million registered experts, and a November pay-cut dispute left thousands of contractors angry. If you're applying or already working through Mercor, both incidents are worth understanding before you hand over sensitive documents.
What Is Mercor?
Is Mercor a Real Company?
Yes. Mercor.io Corporation, trading as Mercor, was founded in 2023 by Brendan Foody, Adarsh Hiremath, and Surya Midha, three Bay Area high school friends who met on their school's debate team and later received Thiel Fellowships to skip college and build the company full time. It's headquartered at 181 Fremont in San Francisco. By October 2025, a $350 million Series C round led by Felicis Ventures, with participation from Benchmark and General Catalyst, valued the company at $10 billion, up fivefold from its previous round eight months earlier. Reports in July 2026 indicate Mercor was in talks to raise another $500 million at a $20 billion valuation. This is real, institutional money, not the kind of funding trail you'd expect from a shell operation.
Mercor's actual business is matching expert contractors, engineers, lawyers, doctors, scientists, and other professionals, with AI labs that need humans to evaluate and generate training data for their models. It manages roughly 30,000 active contractors at any given time out of a registered pool approaching 5 million experts, according to the company's own disclosures.
How Does Mercor Make Money?
Mercor doesn't charge contractors anything. It earns its revenue from the AI labs and enterprises on the other side of the marketplace, taking a margin between what a client pays for a given project and what the contractor is paid to do the work. As one review of the platform put it, "the hourly rate you see is typically what you receive, Mercor takes its margin from the client side." On top of contractor placement, Mercor also sells enterprise products built on that same data pipeline, including AI agent evaluation and what it calls "human data" services sold directly to companies building or testing models. By September 2025, the company had reportedly reached $500 million in annualized revenue.
What Contractors and Users Are Reporting
Mercor holds roughly a 4-star rating on Trustpilot across more than 500 reviews, and the pattern in that feedback is fairly consistent. On the positive side, reviewers repeatedly cite reliable weekly payments (contracts pay out every Wednesday via Stripe or Wise, with a 7-day hold on your first payout), responsive support for technical issues, and access to well-paying project work that's hard to find elsewhere. Reported rates range from around $45 an hour on average up to $70 to $200 an hour for specialized software and AI/ML engineering roles.
The negative reviews cluster around a different set of issues. Several Trustpilot reviewers describe the recruitment process, an unsolicited LinkedIn message leading to a roughly 20-minute AI-conducted video interview, as feeling more like a data-collection exercise than a real hiring funnel, since interviews are reused across projects and Mercor doesn't publish how many applicants who complete one actually get placed. Others report abrupt offboarding from projects with little explanation, and the "feast or famine" nature of project-based freelance work, where a role can end without notice once a client's budget or scope changes.
The November Pay-Cut Dispute
In November, Mercor abruptly ended a large content-review project, reportedly involving thousands of contractors moderating video content for Meta's Instagram and Facebook platforms. Workers on that project were earning $21 an hour. Within days, Mercor offered many of them a new role on a similar project, but at $16 an hour, a roughly 24% pay cut. Mercor's public response framed the change as an effort toward "greater earning stability and consistent access to work," and the company pointed out that its job postings describe the work as temporary and project-based, calling contractor characterizations of the situation "inaccurate." Some affected workers said the abrupt shift felt less like normal project turnover and more like a unilateral pay cut on people who needed the income. Neither account is inherently false: freelance, project-based work is genuinely volatile by design, but the size and speed of this particular repricing is what drove the coverage.
The March 2026 Data Breach
This is the most serious mark against Mercor, and it's worth reading carefully if you've submitted personal documents through the platform. In March 2026, attackers linked to a group called TeamPCP published malicious versions of LiteLLM, an open-source AI infrastructure tool, to the Python Package Index (PyPI) on March 27. Any system that installed the compromised package, including Mercor's, had credentials exfiltrated as a result.
Mercor has confirmed the incident directly. According to the company's own security update, the attack led to roughly 4 terabytes of stolen data: about 211 GB of candidate records including resumes, contact details, and Social Security numbers; around 3 TB of video and identity-verification data, including interview recordings and government ID documents; and about 939 GB of source code and internal systems data. Mercor says only a limited subset of its nearly 5 million registered experts had sensitive information exposed, and states it has found no evidence the stolen data has been used fraudulently so far. The company brought in Google's Mandiant and the security firm Latacora to investigate, rotated credentials across its cloud and GitHub systems, and began notifying affected users directly on June 25 and 26, offering complimentary identity-protection monitoring through TransUnion.
The breach has already produced legal consequences. On April 21, 2026, the law firms Hausfeld LLP and Hall Attorneys filed a proposed class action against Mercor in the U.S. District Court for the Northern District of California on behalf of affected candidates and contractors, and Mercor has reportedly faced additional contractor lawsuits since. If you applied to or worked through Mercor and haven't checked whether you were notified, it's worth confirming directly with the company rather than assuming you weren't affected.
Applying Through Mercor: What the SSN Request Means
A specific concern shows up in job-seeker forums like Glassdoor and Fishbowl: applicants who go through Mercor's AI interview get a hiring email shortly after, followed by onboarding paperwork that includes a W-9 form requesting a Social Security number. On its own, this isn't a red flag. A W-9 is the standard IRS form any legitimate US company uses to pay an independent contractor, and Mercor does hire people this way. The real precaution is making sure the request is actually coming from Mercor, through your account on mercor.com, rather than a lookalike domain or a message sent outside the platform. Given that Mercor has already had one incident where contractor documents were exposed, treat any unexpected onboarding email as worth double-checking the sender domain on, even when the underlying request is standard practice.
FAQ
Is Mercor a scam?
No. Mercor is a registered company, incorporated as Mercor.io Corporation, with over $492 million raised from venture investors and a real client base that reportedly includes OpenAI and Anthropic. It pays contractors on a set weekly schedule, and Trustpilot reviews consistently confirm payments arrive as promised.
Can I trust Mercor with my Social Security number?
Mercor is a legitimate business that legally needs a W-9 to pay US contractors, so being asked isn't itself suspicious. What matters is verifying you're submitting it through your genuine Mercor account and not a phishing message impersonating the company, especially since Mercor's own March 2026 breach already exposed some contractors' SSNs and ID documents once.
How do I apply to work through Mercor?
Applicants create an account, submit a resume, and complete a roughly 20-minute AI-conducted video interview for a specific role. Mercor reuses that interview and profile across its talent pool, matching approved applicants to projects as they become available, rather than requiring a new interview for every opportunity.
Was I affected by the Mercor data breach?
Mercor says it directly notified affected experts by email on June 25 and 26, 2026, and offered free TransUnion identity monitoring to those whose data was exposed. If you applied or worked through Mercor before March 2026 and are unsure whether you were included, contact Mercor's support directly to confirm rather than assuming you were not affected.
If you're weighing whether to apply to Mercor, or you've already gotten an unexpected hiring email tied to it, the company itself checks out. What deserves your attention is the fine print: confirm any onboarding request actually comes from mercor.com before you send tax documents, and if you get a message that only claims to be from Mercor, run the sender's domain through ScamInfo's validator before you respond. If something about a Mercor-related interaction still doesn't add up, file a report with ScamInfo so we can track the pattern.
Editor notes:
[INTERNAL LINK NEEDED: a job-scam / recruiter-phishing article, if one exists or gets written, would fit well in the "Applying Through Mercor" section]
No secondary keywords, outlinks, or ScamInfo scan URL were provided in the outline, so none were forced in.
Sources used: Wikipedia (Mercor), TechCrunch and CNBC (Series C funding), Forbes (July 2026 $20B talks), Trustpilot (mercor.io / mercor.com reviews), RemoWork's 2026 Mercor review, AOL/Fortune coverage of the November pay-cut dispute, Mercor's own blog post on the March 2026 security incident, and reporting on the Hausfeld/Hall Attorneys class action.