Skip to content

Mercor Breached, Biometric Face and Voice Data on Every Registered User Offered for Sale

Breach Report United States flagUnited States AI / Talent Marketplace Data for Sale Confirmed

Mercor Breached, Biometric Face and Voice Data on Every Registered User Offered for Sale

A seller posting as Resolute, claiming to have acted alongside a group using the Lapsus$ name, is advertising data from a complete compromise of Mercor, the US platform that recruits domain experts to produce training data for AI laboratories. The data includes high-definition facial videos, voice recordings, biometric identifiers, and full personal data for every registered user, across a 211GB database also holding AI training material, plus 939GB of source code and cloud storage buckets. Sample files, bucket trees, and source trees are linked from the post. The sale is one-time, via escrow. The breach has been confirmed.

Database211GB
Code & buckets939GB
CountryUnited States flagUnited States
ActorResolute

Post details

TargetMercor
CountryUnited States flagUnited States
SectorAI / Talent marketplace
ListingOne-time sale, escrow, offers
Volume211GB DB / 939GB code
DataBiometric, PII, source, buckets
Observed
AttributionResolute, Lapsus$ claimed

!What was taken

  • HD facial videos
  • Voice recordings
  • Biometric identifiers
  • Full personal data
  • Every registered user
  • AI training data
  • Platform source code
  • Cloud storage buckets
  • Bucket & source trees

Screenshot

Potential impact

Biometric data cannot be reissued. A breached password is replaced in minutes; a person's face and voice are permanent, and both were taken, at high definition, for every user on the platform. Paired with full identity data, that is the raw material for synthetic impersonation against a population of named professionals who work with AI laboratories, several of whom will hold access their employers would rather protect. The source code and cloud buckets extend the problem past the data itself, since either may contain credentials permitting continued access after remediation.

iStatus

Confirmed

The breach has been confirmed. Three sample archives are linked from the post, which Dark Web Informer is not reproducing along with the contact routes. The Lapsus$ attribution remains unconfirmed, as the name has been reused widely since the original group's members were arrested, and the precise scope of the biometric holdings has not been independently established. Affected users should treat their face and voice data as permanently exposed.

Want everything on this breach? Paid subscribers get the full claim details and more. Check out the threat feed, then after subscribing, search there for this alert. View pricing →

DARK WEB INFORMER - THREAT INTELLIGENCE

Latest