AI Briefing
KO

4TB of Voice Samples Leaked from 40,000 AI Contractors at Mercor

·2026.04.27 18:57

Key point

A data breach at AI training data company Mercor exposed 4TB of data including voice recordings and ID information from 40,000 contractors.

Details

The hacking group Lapsus$ stole approximately 4TB of data from Mercor, an AI training data collection company. The breach includes voice samples from over 40,000 contractors recorded for AI model training, along with their government-issued IDs (passports, driver's licenses, etc.), posing a serious security threat.

The leaked voice data consists of high-quality recordings averaging 2 to 5 minutes in length. Given that today's technology can achieve sophisticated voice cloning from just 15 seconds of sample audio, this data represents an asset that attackers can use immediately in real-world attacks. When combined with ID information in particular, the following attack scenarios could become reality:

  • Bypassing bank authentication: Passing identity verification procedures based on voice biometrics
  • Corporate vishing (voice phishing): Impersonating employees to request payroll account changes or money transfers
  • Deepfake video call scams: Advanced fraud combining IDs and cloned voices
  • Insurance and family impersonation scams: Filing insurance claims or impersonating people in emergencies using cloned voices

Experts recommend that, since voice data cannot be changed like a password, people should minimize public exposure of their voice, set up verbal codewords with financial institutions, and replace existing voice-based authentication methods.

This summary was generated automatically by AI. Check the original for the author's claims and context. Copyright belongs to the original author.

Our guide explains how the AI works. Report summary errors, attribution issues, or removal requests via Contact.