10 ms·
4TB of voice samples just stolen from 40k AI contractors at Mercor
- terobyte 5mo agoOpen Source now?
- kumarski 5mo agoI was floating near some ex agency and GS15 folks yesterday in Houston, they explained to me that the Israeli cybersecurity apparatus has had everyone's voicemails for the last 20 years because they inserted themselves into the supply chain of voicemails somehow or another. Kind of nuts all the ways audio data can be used now.
- trollbridge 5mo agoA few Israeli companies supply the software used to record phone calls when you call customer service.
- dfordp11 5mo ago[dead]
- kleiba2 5mo agoIf you had a company, why not just tell all customers that their data is save but don't waste any money on security at all: in case of a breach, just write an apology email to your clients, promise a full investigation, and move on. Obviously, you don't have to face any legal consequences, so why worry? Sorry for the rant... but I just find this lack of liability frustrating.
- popcorncowboy 5mo agoI like this. I'm genuinely curious whether you could create a Delve [0] for security. Companies could pay for the "security review and package and dashboard" virtue signal, put an impressively secure looking logo on their site and effectively whitewash needing to do anything else. I suspect a sufficiently expensive law firm could draft the requisite legals to shield the principals SecCo from the eventual unveiling, but not before SecCo could make hundreds of millions and the rest of the industry could save hundreds of millions on their shit-as-fuck security practices anyway. Call the spade a spade. 0 - https://techcrunch.com/2026/03/22/delve-accused-of-misleading-customers-with-fake-compliance/ https://techcrunch.com/2026/03/22/delve-accused-of-misleadin...
- GS_Projects 5mo agoMercor had a SOC 2, an MSA, all the right clauses. Voices still leaked. The apology email writes itself. Why is voice and biometric stuff still server-side at all in 2026? Whisper.cpp runs on a phone. WebGPU works. Half these "we keep your voice secure" pipelines could run in the browser today. The real reason isn't capability. It's cost. Centralised compute is cheaper to run, but that math only holds if you don't price in the periodic breach. Which nobody does until it's their own employees on the leak list.
- GypsyKing716 5mo agoIts weird how 404 looks a lot like Claude Code CSS output itself. Is it just me? AI generated and submitted Ycombinator story?
- GorbachevyChase 5mo agoI was really hoping this was a leak of Warhammer 40K voice samples, but alas. My dreams of an imperial AI voice assistant go unrealized.
- zhouquanxi 5mo ago[dead]
- Oravys 5mo agoAuthor here. Wrote this after watching Lapsus$ post the Mercor archive on their leak site earlier this month. The thing that struck me is the combination: voice samples paired with ID document scans. Most breaches leak one or the other. This one ships a deepfake-ready kit. Tried to keep the writeup practical: what an attacker can actually do with this combo (banking voiceprint bypass, Arup-style video calls, insurance fraud), and a 5-step checklist for the contractors who were in the dump. Happy to discuss the forensic detection side. AudioSeal watermarks, AASIST anti-spoofing, and how the detection landscape changes once voice biometrics start leaking at scale.
- Zetaphor 5mo ago> Self-audit your public audio footprint. Search YouTube, podcast directories, and old Zoom recording This is suggestion #1 on your list of remediation steps for victims, but you didn't provide any information on how anyone would actually do that. How exactly would I search the internet for copies of my voice? Please don't tell me the solution is giving an embedding of my voice to another third party.
- Oravys 5mo agoGreat question. There's no "reverse voice search" yet the way there is for images — that's genuinely a tool the world needs. In the meantime, the most useful thing is searching your name across YouTube and podcast platforms to map out what's already public. And for Mercor contractors specifically, the California AG breach notice gives you a solid legal basis to request full deletion. Worth doing today.
- sillysaurusx 5mo agoNote, this comment and your other one (https://news.ycombinator.com/item?id=47931838 https://news.ycombinator.com/item?id=47931838) were autokilled by HN, because it (rightly) detected that you're using AI to write your comments. I vouched this one to unkill it before I realized it was AI and supposed to be dead. I unvouched it, but your comment's still alive. So now I'm leaving a note saying mea culpa, and to suggest not using AI in your comments unless you want to be autokilled.
- eqvinox 5mo agoThe only data that cannot be stolen or leaked is data that doesn't exist. Hard lesson for both users and companies. Germans (because of course) have a word for this: "Datensparsamkeit". Being frugal with your data.
- dhosek 5mo agoOr you could put it in a box with no connection to the internet. Introducing… The Hooli Box!
- dnnddidiej 5mo agoDo Germans have lots of words or just a lack of spaces?
- wlesieutre 5mo agoI miss the pre-LLM days when you could make a decent argument that having any unnecessary data was just a liability. Now all anybody thinks is “more data for the AI!”
- CincinnatiMan 5mo agoWere you not around for the Big Data heyday a decade ago?
- varispeed 5mo agoUntil thumb drives became large enough to fit most datasets it stopped becoming Big Data. Just normal data.
- ffsm8 5mo agoWe have thumb drives that can store petabytes of data? Or did you mean the "big data" crowd which thought 500GB was noteworthy? I don't think anyone took those serious, neither in 2010s nor now. That was always "small" data
- jacquesm 5mo agoYou could have seen this coming a mile away. So far I have gotten away with never uploading my ID and/or interacting with one of those companies (though one idiot working for some VC thought it was ok to sign a document on my behalf by uploading my signature!!, never mind a bit of fraud) but it is getting harder and harder. Banks and in some cases even governments forcing you to send data to these operators is a very bad idea. But hey, who ever got hurt by some security theater? I've had to open a bank account for a company here a few years ago and that was right on the bubble of this happening and they still had an option to come by in person with the proper documentation, which I did, now it is all outsourced. These companies are the fattest targets and they're run by incompetents. You should assume that anything you give them will eventually be part of some hack.
- Schlagbohrer 5mo agoTell us more about that fraud story! Was the person your attorney or accountant? Or just some "smart" person who decided to wisely save time by doing fraud?
- jacquesm 5mo agoIt was a fund administrator. I still find it unbelievable that they would so casually do this. And yes, they thought they were very smart... and helpful too...
- hiccuphippo 5mo agoWhy is the ID a hidden secret that can be used for anything regarding security in the first place?
- jacquesm 5mo agoBecause historically that's how it worked, but officials just looked at the document and verified that it was the real thing. Then photocopiers came along and it became normalized to take copies of the documents. Then digital copies happened and that changed things completely when coupled with networking technology. What the officials in charge don't seem to understand is that by making digital copies in networked environments the IDs themselves lost their value completely, after all if the digital copy serves any purpose at all as a stand-in for the original then they have become that original.
- josefritzishere 5mo agoThis kind of event is the best argument against needless data hoarding. But it would help if the law better provided for some kind of consequences for negligence.
- deleted 5mo ago[deleted]
- z0ltan 5mo ago[dead]
- algoth1 5mo ago[dead]
- VladVladikoff 5mo agoMan that’s pretty shitty that Mercor tricked 40k contractors, and then did a poor job of securing their data. There should be stronger consequences for stuff like this.
- throwa356262 5mo agoWhat happens now is that a lot of clueless CTO that didn't know about this company now know it's name. So the outcome of this mess is probably more business for Mercor I mean, just look at what happened to Crowdstrike....
- yunyu 5mo agoMercor has around 5 customers that make up 95% of its revenue. Anybody who needs to know about them already does.
- interludead 5mo agoAt minimum, collecting voiceprints should come with much stricter consent, retention and security requirements than ordinary "training data"
- Havoc 5mo agoI love how the check if your affected involves giving a voice sample to whatever the fuck that website is
- 2ndorderthought 5mo agoIt's like those have been owned websites. Where you type in your name email and they grab your IP location and anything else to sell it off.
- throw0101c 5mo ago"My voice is my passport. Verify Me." :)
- deleted 5mo ago[deleted]
- java-man 5mo agoHSBC did that. I could never understand that - the exact phrase was in the movie!
- NitpickLawyer 5mo agoSomeone probably did it for an internal demo, as a joke. Then people pushed it upwards, until someone clueless approved it.
- deltoidmaximus 5mo agoFidelity seemed to sign you up for this when you called them on the phone almost automatically. Ridiculous since it was defeated easily in a hacker movie from the 1990s using a tape recorder.
- brewdad 5mo agoMuch cleaner than keeping a finger on you to bypass the print reader.
- amarcheschi 5mo agoI've been doing similar things on a different platform because as a uni student the pay is kinda nice, but I limit myself to task without voice/video and just input from mouse/keyboard to do reinforcement learning/data tagging. No way I'm trusting these companies or the companies they contract the work with
- KnuthIsGod 5mo ago[dead]
- embedding-shape 5mo agoI wonder how many of the current text-to-speech ML models have large parts of leaked or "stolen" data in their training data? Almost none of the TTS releases seem to talk about exactly where they get their training data from, for some reason. I also wonder if we'll see an explosion in SOTA TTS in ~6 months from now.
- hirako2000 5mo agoIt's already there. And keeps moving. Even have a nice UI on top. https://voicebox.sh/ https://voicebox.sh/
- jubilanti 5mo agoNot really, Mozilla Common Voice (the ImageNet of speech) is larger than this. Their English database has 3814 hours, 1.6 million sentences, from 100k speakers. https://commonvoice.mozilla.org/en/languages https://commonvoice.mozilla.org/en/languages
- nmacias 5mo agoGOOG-411 was "competing" with a strong company (1-800-FREE411) by serving no ads in a category worth ~$3.5B at the time. It was inexplicable at the time, but they did this to get voice samples, way back when. For reasons like that, I expect that this category of training is baked — but I don't have current domain knowledge fwiw.
- interludead 5mo agoYep, the silence around provenance is probably the most suspicious part
- john_strinlai 5mo ago>Set up a verbal codeword with family and finance contacts. Pick a phrase that has never been spoken on a recording and never typed in chat. Brief the people who handle money on your behalf. If a call ever asks for a transfer, the codeword is mandatory. good luck with this. most finance people deal with hundreds to thousands of clients. they obviously cant remember everyones code word. commonly used finance systems arent setup to securely store these codewords. they dont have processes or policies in place to implement or adhere to any sort of codeword verification. >Rotate where voiceprints are still in use. [...] Do that now, ideally from a new recording in a different acoustic environment than the leaked sample. would this even have an effect? i have never heard of "rotating" a voice print. isnt the whole point of a voice print that you cant really change it? if simply switching your environment completely changes your voice print, that would make voice prints utterly useless to begin with.
- iterateoften 5mo agoYeah seems like nonsense advise. Have a code word that was never recorded? I don’t see how that would tote y anything. Like the point of these systems is they can say stuff you never said convincingly
- MarsIronPI 5mo agoThe idea is that the attacker doesn't know the codeword. If the attacker finds out about the codeword then the attacker could indeed fake it. Hence why you shouldn't say/write it in recordings or chat messages.
- wongarsu 5mo agoSomeone who has hundreds or thousands of clients presumably couldn't remember every client's voice either, so no meaningful security is lost. They are approximately as secure or insecure as before
- john_strinlai 5mo ago>presumably couldn't remember every client's voice either, so no meaningful security is lost there are automated systems for this already. my bank, isp, etc. use them when you call in to skip the traditional verification steps. this fact is also highlighted in the article. the problem is that there isnt typically a system in place for setting up or validating code words, so the advice given is not practical to implement.
- barrenko 5mo agoIt more looks like the purpose of such company was to steal such data.
- 52-6F-62 5mo agoLook at their privacy policies. It absolutely is. They are harvesting video, voice, and much more.
- oefrha 5mo ago> If you were a Mercor contractor and you believe your voice may already be in circulation, ORAVYS will analyze the first three suspect samples free of charge. Awesome, if you're a victim of an AI company having your voice, you can help yourself by sending another AI company your voice! > Audio is never used to train commercial models without explicit consent I'm sure Mercor has explicit consent as well, legal teams are reasonably good at legally covering their asses with license terms.
- 1vuio0pswjnm7 5mo ago[dead]
- Oravys 5mo agoHi oefrha. I totally understand your point of view. The only thing is: we give you an opportunity to recognize how unique your voice actually is. We only analyze the audio file to show you how much uniqueness a voice carries. Audio is never used for training without explicit consent and is purged on a defined retention schedule. That is very important to us and also to let people know what their voice has to offer them for their growth and self awareness. Big difference wiTh what Mercor did.
- a012 5mo agoReminds me of my experience when trying to remove my Airbnb account, they require my ID card scans of both sides. I said fuck it and never touch this company again
- zelphirkalt 5mo agoQuickly, extract some more money from this customer and hold their data hostage!
- sidewndr46 5mo agoThis reminds me of those identity theft settlements, where you need to prove your identity to claim the reward
- Henchman21 5mo ago
- globalnode 5mo agonot to be conspiratorial but stolen? or given away...
- ethagnawl 5mo agoSo, they should all just rotate their voices ... right? I jest but the majority of the "normal" people I know are happy to hand over biometrics because _it's easier_. We need to start branding biometrics as "forever passwords" or something to help people understand just what they're handing over when they validate access to their checking account or enter Disney World or whatever else.
- MattGaiser 5mo agoOne of the problems is that "forever passwords" is a term used positively when I worked in banking, as it was a password that the customer could not forget and would not need support using. So I could easily see a lot of people viewing this as a positive.
- ethagnawl 5mo agoThat's a really good point. It lays bare some of my biases when it comes to thinking about and communicating with "normal people" about this sort of thing.
- MattGaiser 5mo agoPeople having a bad memory is it enormous cost to institutions, which is why biometrics is so appealing in the first place. Them being forever passwords is the value prop. The risk scene has changed, but that was essentially always the pitch.
- gowld 5mo agoBiometrics are fine. My dog has an ID chip in injected under his skin.
- MattGaiser 5mo agoYour dog has nothing worth stealing and is not responsible for anything.
- deleted 5mo ago[deleted]
- eolgun 5mo agoThe biometric pairing is what makes this particularly bad. A leaked password is recoverable. A leaked voiceprint combined with ID scans is permanent, you can not rotate your voice. The deeper problem is that most of these companies collected this data because they could, not because they needed it for the core service. 'Datensparsamkeit' is the right frame: the voice samples were a liability sitting on a server waiting for exactly this.
- Oravys 5mo ago[dead]
- immanuwell 5mo agothey literally handed over their voice, their face, and their government id to train ai models for peanuts - and now lapsus is sitting on 4tb of 'you' that you can never change like a password
- kristopherleads 5mo agoI'm at the point where I might start professionally using a voice changer. I mean what in the world, my guy?
- sharadov 5mo agoMercor is the most scummy company out there, run by a bunch of sleazeball 20 somethings who are getting a lot of press as the youngest billionaires in the making. Can't wait for them to crash and burn.
- giannicmptr1000 5mo ago[flagged]
- tracker1 5mo agoI'm pretty sure Google and Apple already have some decent examples of a LOT of people's voices in concert with other data collation. Google Voice IIRC was bought for audio sampling voicemail in the first place. Not sure if Apple has done similar, but would be more surprised if they didn't... Let alone the voice search options for both.
- hedora 5mo agoIsn’t this going to immediately become daily news? Half the time I call a company they say “we are recording your voice for security / authentication purposes”. The companies that do that have all the information on me that they require for me to set up an account, so their data breaches will be just like this one, but 1000x larger. Can we just fast forward through the part where this works for ID theft, past the firefox age verification plugin that uses these datasets, and even through the part where people in the plugin dataset are digital outcasts (this voice has been used too many times. Want to try another?) At the end of this dark predictable tunnel, maybe there will be a ban on biometrics for important stuff, a repeal of the age verification laws, and actual privacy legislation with teeth.
- AntiUSAbah 5mo agoI'm curious: if i create an online sample from my voice, might this make it a lot harder for an AI model to identify me if every trainingdata contains my particular voice sample?
- AtNightWeCode 5mo agoWhere I live there was a common scam to manipulate voice recordings from phone calls. I was very careful back then with phone calls when I ran my own business. Like 15 years ago. Kinda crazy that any service would use voice recognition today as stated.
- mugivarra69 5mo ago[dead]
- squirrelon 5mo ago40k people are not under thread, I am getting AI contractor job offers every month on UpWork, I am glad I haven't accepted more than one as it is just not worth to do.
- meric_ 5mo agoIs this post not just an ad for a vibe coded site / product? It adds no new info on the mercor breach and advertises something which I presume has even worse safety practices
- ChrisMarshallNY 5mo ago> What does an attacker actually do with thirty seconds of someone's clean read voice plus a scan of their driver's license? I could think of quite a few things. I know that my bank and brokerage use voice ID.
- throwaway67743 5mo agoI saw the red flags immediately when I stumbled across them a year ago maybe. I'm really not surprised.
- yesman_x 5mo agoIf this is real, the bigger issue might not even be the leak itself. It could be that we are quietly moving into a world where voice plus ID is enough to fully impersonate someone, and most systems are still not built for that reality.
- flockonus 5mo ago> How to check if your voice is being misused I love that the answer here is basically.. - you don't - But maybe mitigate at unreasonable personal costs. How about services simply stop taking public information as proof of identity?
- gyanchawdhary 5mo agoim the founder of a company that runs deepfake phishing simulations for enterprises, so biased on this one .. but the operational thing the piece misses is that this is the first widely circulated dump where voice, govt ID and selfie all came from the same onboarding session i.e. most enterprise call center auth still treats those as 3 independent factors .. The scarier piece is that an attacker pulls a contractor from the dump, finds their employer on linkedin, then calls that companys IT helpdesk for a password reset with the cloned voice. Fwiw we put up a free realtime face swap demo a while back at https://www.callstrike.ai/deepfake-security-training https://www.callstrike.ai/deepfake-security-training .. worth a look if you want to actually feel how trivial this has gotten.
- Oravys 5mo agoGreat point about the helpdesk vector. The LinkedIn-to-IT-reset path is a brilliant illustration of how social engineering chains work. And you're right that audio is the frontier video deepfake detection has gotten really good, lots of great tools out there. Audio is the next wave, and the teams building solutions for real-world call quality are going to unlock a massive market. Exciting space to be in.
- interludead 5mo agoThis is exactly why "voice as authentication" feels like a dead end to me
- Oravys 5mo agoIt feels like a dead end because it's being used wrong. "Is this John's voice?" is the wrong question. "Does this call look like how John normally calls?" is way more interesting. Same device, same time of day, same way of starting a sentence. That whole pattern is much harder to fake than a voice alone. The authentication isn't dead, it just needs to grow up from a single check into a full picture.
- glicvdfhsdf 5mo ago[dead]
- deferredgrant 5mo ago[flagged]
- miohtama 5mo agoNow open Chinese models can catch up