4TB of voice samples just stolen from 40k AI contractors at Mercor
1–10 of 250 posts
Re: 4TB of voice samples just stolen from 40k AI contractors at Mercor
#2Author here. Wrote this after watching Lapsus$ post the Mercor archive on their leak site earlier this month. The thing that struck me is the combination: voice samples paired with ID document scans. Most breaches leak one or the other. This one ships a deepfake-ready kit. Tried to keep the writeup practical: what an attacker can actually do with this combo (banking voiceprint bypass, Arup-style video calls, insurance fraud), and a 5-step checklist for the contractors who were in the dump.
Happy to discuss the forensic detection side. AudioSeal
watermarks, AASIST anti-spoofing, and how the detection landscape changes
once voice biometrics start leaking at scale.Re: 4TB of voice samples just stolen from 40k AI contractors at Mercor
#3The only data that cannot be stolen or leaked is data that doesn't exist. Hard lesson for both users and companies.
Germans (because of course) have a word for this: "Datensparsamkeit". Being frugal with your data.
Re: 4TB of voice samples just stolen from 40k AI contractors at Mercor
#4You could have seen this coming a mile away. So far I have gotten away with never uploading my ID and/or interacting with one of those companies (though one idiot working for some VC thought it was ok to sign a document on my behalf by uploading my signature!!, never mind a bit of fraud) but it is getting harder and harder. Banks and in some cases even governments forcing you to send data to these operators is a very bad idea. But hey, who ever got hurt by some security theater?
I've had to open a bank account for a company here a few years ago and that was right on the bubble of this happening and they still had an option to come by in person with the proper documentation, which I did, now it is all outsourced.
These companies are the fattest targets and they're run by incompetents. You should assume that anything you give them will eventually be part of some hack.
Re: 4TB of voice samples just stolen from 40k AI contractors at Mercor
#5This kind of event is the best argument against needless data hoarding. But it would help if the law better provided for some kind of consequences for negligence.
Re: 4TB of voice samples just stolen from 40k AI contractors at Mercor
#6[deleted]
Re: 4TB of voice samples just stolen from 40k AI contractors at Mercor
#7[deleted]
[dead]
Re: 4TB of voice samples just stolen from 40k AI contractors at Mercor
#8[dead]
Re: 4TB of voice samples just stolen from 40k AI contractors at Mercor
#9The only data that cannot be stolen or leaked is data that doesn't exist. Hard lesson for both users and companies. Germans (because of course) have a word for this: "Datensparsamkeit". Being frugal with your data.
I miss the pre-LLM days when you could make a decent argument that having any unnecessary data was just a liability. Now all anybody thinks is “more data for the AI!”
Re: 4TB of voice samples just stolen from 40k AI contractors at Mercor
#10Man that’s pretty shitty that Mercor tricked 40k contractors, and then did a poor job of securing their data. There should be stronger consequences for stuff like this.