Mercor, the data labeling startup founded in 2023 by three 22-year-old high school debate teammates, has rocketed to a $1 billion annualized revenue run rate and $10 billion valuation in record time. CEO Brendan Foody, CTO Adarsh Hiremath, and board chairman Surya Midha became the world's youngest self-made billionaires in October 2025 after raising $350 million from top-tier VCs like Felicis, Benchmark, and General Catalyst. The company recruits 50,000 highly skilled contractors—PhDs, lawyers, scientists, and programmers—to generate training data for frontier AI labs including OpenAI and Anthropic.
But explosive growth has exposed serious operational vulnerabilities. In early 2026, Foody revealed to staff that an early-hire lead manager on Mercor's critical Anthropic account had embezzled company funds by funneling hundreds of thousands in fraudulent "bonus payments" to his brother and father disguised as expert contractors. The scheme went undetected until contractors were paid more than what was billed to Anthropic for multiple projects. While Mercor recovered the stolen funds and Anthropic remained unaware, the incident signals weak internal controls at a company managing proprietary training data for the world's most advanced AI systems.
The fraud case pales beside a more alarming security threat: multiple former employees told Forbes that suspected North Korean operatives infiltrated Mercor's platform using stolen credentials to bypass identity verification checks. These operatives, nicknamed "NKs" internally, were reportedly among the best contractors at code-writing tasks and worked extreme hours—80 hours weekly—producing "the cleanest code." Employees discovered them through onboarding videos showing multiple people in identical black headphones in drab office settings, a stark contrast to the home office setups typical of legitimate remote experts. The concern isn't just fraud; it's espionage—suspected North Koreans gained visibility into what proprietary training data frontier AI labs prioritize, information guarded as trade secrets.
Mercor's security woes compounded dramatically in April 2026 when the startup fell victim to a massive hack linked to open source project LiteLLM, affecting thousands of companies. Meta immediately paused its work with Mercor pending investigation, and OpenAI began evaluating whether its proprietary training data was exposed. At least six lawsuits from contractors allege the breach exposed Social Security numbers, full names, and customer data. The company now faces fierce competition from better-established rivals like Scale (valued at $7.3 billion), Invisible Technologies ($2+ billion), Surge, and Turing AI ($2.2 billion), all hungry for the same high-value contracts that power AI development.
Mercor's spokesperson insists the company has "industry leading fraud detection" with around-the-clock monitoring and IP-blocking, and claims most customers remain in "business-as-usual" mode. Yet the cascade of incidents—internal theft, suspected state-sponsored infiltration, third-party breaches, and legal exposure—reveals the acute risks facing ultra-young founders scaling infrastructure-critical businesses faster than governance and security can keep pace.
Gist is a free AI reader for your browser, iPhone, and Android. Get concise summaries and key takeaways from any article or podcast.
Get Gist — Free