4TB of voice samples from 40,000 AI contractors leaked from Mercor
Key point
The Mercor leak exposed voice and ID data of more than 40,000 contractors.
Details
A large-scale leak occurred at Mercor, bundling together voice samples and government-issued IDs of roughly 40,000 AI contractors.
The leaked archive is reported to be about 4TB in size, and is described as having been posted by Lapsus$ on a leak site on April 4, 2026.
Each contractor's recordings average 2 to 5 minutes of clean audio, far exceeding the roughly 15-second benchmark required by commercial voice-cloning services. The core issue is that voice clones and real identities were exposed together, meaning they could be used directly in actual impersonation attacks.
Possible abuses cited include:
- Bypassing bank voice authentication
- Vishing targeting workplaces
- Deepfake video calls
- Insurance claim fraud
- Emergency calls impersonating family members
Proposed countermeasures include deleting public voice traces, setting up codewords for family and financial use, re-enrolling voiceprints, disabling bank voice authentication, and running forensic examinations of suspicious voices. Forensics look at codec mismatches, breathing patterns, microphone jitter, formant trajectories, room acoustic consistency, and anomalies in prosody and speech rate.
Within 10 days of the posting, 5 lawsuits were filed by contractors, claiming that when their voiceprints were collected, they were not adequately informed that these constitute permanent biometric identifiers.
This summary was generated automatically by AI. Check the original for the author's claims and context. Copyright belongs to the original author.
Our guide explains how the AI works. Report summary errors, attribution issues, or removal requests via Contact.