> ## Content Index
> Fetch the complete content index at: https://darkwebinformer.com/llms.txt
> Use this file to discover other available public pages before exploring further.

# Mercor Breached, Biometric Face and Voice Data on Every Registered User Offered for Sale
- URL: https://darkwebinformer.com/mercor-breached-biometric-face-and-voice-data-on-every-registered-user-offered-for-sale/
- Published: 2026-07-29T19:31:14.000Z
- Updated: 2026-07-29T19:31:14.000Z
- Author: Dark Web Informer
- Tags: Data Breaches

Breach Report ![United States flag](https://flagcdn.com/w40/us.png)United States AI / Talent Marketplace Data for Sale Confirmed 

## Mercor Breached, Biometric Face and Voice Data on Every Registered User Offered for Sale

A seller posting as **Resolute**, claiming to have acted alongside a group using the **Lapsus$** name, is advertising data from a complete compromise of **Mercor**, the US platform that recruits domain experts to produce training data for AI laboratories. The data includes **high-definition facial videos, voice recordings, biometric identifiers, and full personal data for every registered user**, across a **211GB database** also holding AI training material, plus **939GB of source code and cloud storage buckets**. Sample files, bucket trees, and source trees are linked from the post. The sale is one-time, via escrow. The breach has been **confirmed**.

Severity CRITICAL 

Database211GB

Code & buckets939GB

Country![United States flag](https://flagcdn.com/w40/us.png)United States

ActorResolute

### ▣Post details

TargetMercor

Country![United States flag](https://flagcdn.com/w40/us.png)United States

SectorAI / Talent marketplace

ListingOne-time sale, escrow, offers

Volume211GB DB / 939GB code

DataBiometric, PII, source, buckets

ObservedJul 29, 2026

AttributionResolute, Lapsus$ claimed

### !What was taken

- HD facial videos
- Voice recordings
- Biometric identifiers
- Full personal data
- Every registered user
- AI training data
- Platform source code
- Cloud storage buckets
- Bucket & source trees

### ◱Screenshot

[ ![Mercor AI talent platform database breach sale listing screenshot, July 2026](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/07/23579862349876124987621345987612498712.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/07/23579862349876124987621345987612498712.png) 

### ⚠Potential impact

**Biometric data cannot be reissued.** A breached password is replaced in minutes; a person's face and voice are permanent, and both were taken, at high definition, for every user on the platform. Paired with full identity data, that is the raw material for **synthetic impersonation** against a population of named professionals who work with AI laboratories, several of whom will hold access their employers would rather protect. The **source code and cloud buckets** extend the problem past the data itself, since either may contain credentials permitting continued access after remediation.

### iStatus

Confirmed 

The breach has been **confirmed**. Three sample archives are linked from the post, which Dark Web Informer is not reproducing along with the contact routes. The **Lapsus$ attribution remains unconfirmed**, as the name has been reused widely since the original group's members were arrested, and the precise scope of the biometric holdings has not been independently established. Affected users should treat their face and voice data as permanently exposed.

Want everything on this breach? **Paid subscribers** get the full claim details and more. Check out the [threat feed](https://darkwebinformer.com/threat-feed/), then after subscribing, search there for this alert. [View pricing →](https://darkwebinformer.com/pricing) 

[DARK WEB INFORMER](https://darkwebinformer.com/) \- THREAT INTELLIGENCE