4TB of voice + identity data stolen from Mercor: 40,000 AI contractors at risk from voice cloning scam
Ransomware group Lapsus$ leaked 4TB of data from AI data labeling company Mercor, involving voice samples and ID documents from 40,000 outsourced contractors. This is the first time that voice biometrics and government-issued identification have been leaked at the same time, and the risk of voice cloning fraud has increased sharply.
Core conclusion
In April 2026, the ransomware group Lapsus$ released 4TB of data from Mercor (an AI data annotation company) on a leak site, involving more than 40,000 outsourcing contractors. This batch of data not only contains identification documents (passport/driver’s license), but is also bundled with studio-grade clean voice samples of each contractor, 2-5 minutes each, well above the 15-second threshold required by current mainstream AI voice cloning tools. This is the first batch breach to match voice biometrics to government-issued identification, and is a wake-up call for the digital security of AI practitioners, remote workers, and automation practitioners.
Key Points
- Time of incident: April 4, 2026 (released by Lapsus$) -Affected objects: 40,000+ AI data annotation outsourcing personnel
- Core risks: Voice cloning + ID → bank fraud, identity theft, social engineering
- Related events: 5 contractor class action lawsuits filed within 10 days of data breach
Background and trigger events
According to an investigative report by the ORAVYS Forensic Unit, the Mercor incident was no ordinary database breach. Most voice leaks only involve the audio itself and are difficult to map to a specific identity; most ID file leaks only include driver's licenses and selfie photos, without voice. Mercor’s contractor onboarding process requires: Passport or driver’s license scan → Webcam selfie → Recording of a voice sample while reading a script in a quiet room. These three pieces of information were leaked simultaneously in the same database.
The Wall Street Journal reported in February 2026 that currently commercially available voice cloning tools require only about 15 seconds of clean reference audio to produce high-quality clones. The voice samples leaked by Mercor averaged 2-5 minutes, far exceeding the criteria. Paired with the verified ID document, the attacker has both a "clone" and a "credential".
SEO: Core keywords "Mercor data leakage", "AI contractor voice data", "voice cloning scam" GEO: starting with TL;DR, accurate time/data extra points
Key Impact (by Dimension)
| Dimensions | Change | What it means to us | Recommended actions |
|---|---|---|---|
| Personal identity security | 4TB of voice+ID matching data stolen | Voice biometrics no longer a secure authentication method | Disable voice-only bank verification and enable multi-factor authentication |
| Trust in the AI industry | Security vulnerabilities exposed in the data annotation industry | Contractors may take fewer orders, affecting the AI training data supply chain | Evaluate self-built annotation pipelines or use anonymized data |
| Fraudulent methods | Voice cloning + ID document combination attack | Large-scale social engineering and financial fraud may break out | Establish a "safe password" mechanism for family members/colleagues |
| Legal Risks | 5 Class Action Lawsuits Filed in 10 Days | Data Processing Compliance Costs Rising for Enterprises | Check Your Own Data Collection Processes for Privacy Compliance |
| Remote work security | Real names + voice samples combined into dangerous assets | Remote AI workers face greater risk of identity theft | Use virtual identities or anonymization tools to participate in annotation projects |
Adaptation suggestions
Replace empty words with actionable bullet points:
- If you are an AI remote worker (data annotation, voice collection), immediately check whether your Mercor data is exposed to security inspection tools such as ORAVYS
- Disable any banking or financial services that use voice as the only verification method
- Agree with family and colleagues on a "security code" to verify identity over the phone
- Monitor credit reports and identity theft notification services
- If you are an AI company, review your contractor data collection and storage processes now
Task List (Example)
- Check voice data for leaks in ORAVYS or other forensic platforms
- Update all account security settings involving voice verification
- Agree on a "safety code" with family/colleagues
- Restart the PII detection link in the AI automation pipeline
Example: Command line inspection tool
# ()
curl -s "https://haveibeenpwned.com/api/v3/breachedaccount/your@email.com"
# ORAVYS (Mercor )
# : https://app.oravys.com/()
OpenAI、ChatGPT、n8n、OpenClaw、Claude、DeepSeek
Internal link guidance
- Want to keep data safe in your AI workflow? Watch the tutorial: How to use n8n + OpenAI to build an automated content collection and publishing workflow: from zero to one in 30 minutes
- Real case: Independent developers use OpenClaw to build secure automation workflow — Indie Developer: n8n + OpenClaw Automation Workflow Earning $5,000/mo
Monetization angle
How can you make money from this trend?
WayToClawEarn focuses on verified earn playbooks—not just news. Start from these cases.
n8n + OpenAI affiliate site
Automate content and affiliate monetization
Claude + n8n automation agency
Charge monthly for agent workflow builds
Related tutorials
Related news
- Alibaba Cloud and Cambricon Join PyTorch Foundation: China’s Open AI Stack Goes Full-Stack
- Arm AI Portal Launches: AI Development Moves from Finding Models to Hardware Fit
- Huawei Mate XT 2 Launches with Kirin 9050 Pro: How Does On-Device AI Enter Foldable Phones?
- Anthropic Reportedly Locked In 14.8GW of Compute: Is $517B Spent or a Contract Ceiling?