Back to Blog

The AI Job Interview Is the Product: What the Mercor Breach Proved About Who Owns Your Face

A $10 billion AI recruiting company collected 40,000 people's faces, voices, and passport scans through job interviews. Then a poisoned Python package sat on PyPI for 40 minutes, and all of it ended up on a ransomware leak site. Here is how the AI interview funnel actually works, who profits from feeding it, and what to check before you sit down in front of a bot.

AI interview, job scams, recruitment fraud, data harvesting, biometric data, deepfake, Mercor, data breach, AI training data
A voice cloning tool needs 15 seconds of clean audio. One AI job interview records 120 to 300 seconds, paired with a passport scan of the same person.

Forty Minutes on PyPI

On 27 March 2026, someone with stolen credentials published two new versions of LiteLLM, an open-source library that sits between applications and AI models. LiteLLM is downloaded roughly 95 million times a month. Versions 1.82.7 and 1.82.8 were poisoned, and they were live for about 40 minutes before anyone pulled them.

That was long enough.

One of the companies that pulled the bad version was Mercor, an AI talent platform valued at $10 billion, serving OpenAI, Anthropic, Meta and Microsoft. Attackers had access to Mercor systems from 24 to 30 March 2026, in the company's own words: "the malware enabled the unauthorized actor to access some of our systems." On 4 April, the extortion group Lapsus$ listed Mercor on its leak site and started auctioning what it took.

What it took was roughly 4 terabytes. Around 3TB of that was contractor voice recordings and AI video interview footage. Sitting alongside it: government-issued ID scans, passports and driver's licences, for more than 40,000 people. A 211GB database of candidate records with Social Security numbers and full personal information. W-9 tax forms (U.S. relevant). Banking details. Background check materials. Screenshots taken from contractors' own computers by monitoring software. And 939GB of Mercor's source code.

Mercor notified affected people on 25 and 26 June 2026. That's three months after the intrusion window closed, what the heck!

Every one of those 40,000 people handed that material over voluntarily, because they thought they were applying for a job.

87 daysof silence27 MarPoisoned LiteLLMversions sit on PyPIfor 40 minutes24–30 MarAttackers insideMercor systems for sixdays4 AprLapsus$ lists Mercoron its leak site21 AprFirst class actionfiled, N.D. Cal.25–26 JunThe 40,000 people arefinally told
The breach timeline. The 87-day gap is marked, not drawn to scale: at any readable scale the March events collide.

Why the Pairing Is the Problem

Off-the-shelf voice cloning tools need roughly fifteen seconds of clean reference audio to produce a convincing result. The recordings in this breach average two to five minutes per person, captured in quiet rooms on decent microphones, because that is what an interview is. That is eight to twenty times the material a cloning tool actually needs.

Now add the passport scan of the same person, in the same record, already matched.

A voice sample on its own is a nuisance. A stolen passport on its own is a nuisance. A verified government ID pre-linked to studio-quality audio of that person speaking naturally for several minutes, replicated 40,000 times and sold as a single dataset, is something else. It is an off-the-shelf kit for defeating voice-based identity verification at banks, for calling a helpdesk as someone real, and for producing video of a real person with a real documented identity saying things they never said.

The interview footage makes it worse, not better. Candidates in these sessions are asked to explain their expertise on camera, at length, in their own words. That is not just biometric data. It is a behavioural sample of how a specific person thinks and speaks under mild pressure, which is precisely what makes an impersonation survive a phone call.

Nobody at Mercor built the dataset to do this. That is the point. The collection was legal, the consent screen was clicked, the company was real and funded and paying people. The exposure happened anyway, through a dependency nobody in the hiring funnel had ever heard of.

What a voice cloning tool needs15 secondsWhat one AI job interview records120 to 300 seconds, studio quality8 to 20 times more than the tool needsPaired, in the same record, with a passport scan of the sameperson. Replicated 40,000 times and sold as one dataset.
What a cloning tool needs against what one interview records. The passport scan in the same record is what turns a voice sample into an identity.

The Litigation

At least seven proposed class actions have been filed. The lead case is Ananthula, et al. v. Mercor.io Corporation, et al., No. 3:26-cv-03362, filed 21 April 2026 in the U.S. District Court for the Northern District of California. The claims include negligence, failure to implement reasonable data security measures, and violations of the Fair Credit Reporting Act.

The complaints go further than the breach itself. Plaintiffs allege that Mercor monitored contractors' computers and shared that data with clients, that recorded candidate interviews were used to train AI models, and that client models were trained on materials potentially owned by third parties.

Mercor's public documentation says the opposite. Its talent docs state plainly: "Your interview data will not be employed to train AI models; instead, we procure additional training data separately as required." The same page says twice that the company does not sell interview data.

Those allegations are unproven and Mercor disputes them, telling reporters it "strongly disputes the speculative claims" and would present facts "at the appropriate time and place." What is not in dispute is that a company's own contractors, under oath, are asserting something the company's own help pages deny. Meta paused its work with Mercor and opened its own investigation.

You do not have to pick a side in that fight to draw the practical lesson. If the people inside the pipeline cannot agree on what happens to the recording, you certainly cannot know from the outside before you press record.


How You End Up in the Funnel

The Mercor breach is the consequence. The funnel is the cause, and it has three layers. Only the bottom one is funded and real.

Layer one: the bait. A LinkedIn ad appears for a remote creative or technical role at an eye-catching rate. Video editor at $72 an hour. Copywriter starting at $45 an hour. Content creator, animator, social media manager, $50 to $80 an hour. The company posting it is a small outfit you have never heard of. Crossing Hurdles, a Gurugram-registered firm that spent its first years describing itself as an HR consultancy and now describes itself as an "AI contributor network," is the most-reported example. AskEthos, freelinkedin.com, Pesto Tech and Intch show up in the same complaint clusters.

Layer two: the extraction. You apply, and instead of a conversation with a person you are routed into a 20 to 30 minute AI video interview. At Mercor it is a one-way recorded session with an AI-generated transcript. At Micro1 it is an AI interviewer called Zara asking adaptive technical questions, while a second system called Ava tracks your gaze, your tab switches, and your browser activity in the background. Government ID is required. If you pass, you go into a "Certified" talent pool.

Layer three: the client. The frontier AI labs and Fortune 100 companies that buy the resulting expert labour and, more to the point, the resulting data.

Micro1 is not small either. It raised a $35 million Series A led by 01 Advisors in September 2025 at a $500 million valuation, and hit $300 million in annualised revenue by April 2026, up from $125 million at the end of 2025. It screens over 1,000 candidates per role. Mercor has run more than 100,000 interviews in under two years and has close to five million users. Neither company publishes a placement rate.

LAYER 1The baitLinkedIn ads for creative andtechnical roles at $50 to $80an hour, posted by small firmsyou have never heard of.LAYER 2The extractionA 20 to 30 minute AI videointerview. Your face, yourvoice, your government ID.LAYER 3The clientFrontier AI labs and Fortune100 companies buying theexpert labour, and the data.THE REFERRAL BOUNTY$250 to $15,000 perreferral, plus 20% ofeverything theysubsequently earn.Open to anyone.
The three layers, and the referral bounty that pays layer one to keep feeding layer two whether or not anyone is ever hired.

The Bounty That Explains Everything

Here is the piece that reframes the whole thing, and almost nobody writing about this has picked it up.

Mercor runs a public referral programme. Bounties run from $250 to $15,000 per referral, plus 20 percent of everything your referral subsequently earns, ongoing, until you hit an earnings cap. And critically: you do not need to work for Mercor to participate. Anyone can sign up, take a referral link, and start pushing people into the funnel.

That single fact dissolves the question everyone keeps asking. People spend a lot of energy debating whether Crossing Hurdles is "a scam." The more useful question is what the economics reward. A layer-one operator does not need to be a criminal enterprise. It needs a LinkedIn ad budget, a plausible logo, and a referral link. The bounty structure pays for volume into the top of the funnel, and it pays whether or not the person on the other end ever gets a day of work.

That is why the complaint pattern is so consistent across otherwise unrelated companies. Reddit, Glassdoor and Trustpilot reviewers for Crossing Hurdles and AskEthos independently report the same sequence: an attractive posting, a fast push toward an AI interview, then indefinite "Review" status, unanswered emails, and the same job ad still running on LinkedIn weeks later. One reviewer of Crossing Hurdles: "I can't find anyone who actually got a job through this company." An AskEthos reviewer described the platform as "using long AI interviews to train their AI models for free using experts who think they are interviewing for paid work," and noted that several colleagues did the same interview and none were paid.

Both companies also have genuinely positive reviews describing real paid work and prompt payment. Crossing Hurdles carries a 4.6 Glassdoor rating. This is not a case of an obviously fake operation. It is a case where the same process produces paid work for some people and a permanent database entry for everyone else, and you cannot tell in advance which one you are.

There is also a documented asymmetry in how these roles get described. Job postings aimed at candidates for AI training work are vague about what the company actually does. The same companies' internal job listings describe the business openly as training "models that predict how well someone will perform on a job." The information exists. It is just not in the ad you clicked.


The Numbers Nobody Puts in the Job Ad

The candidate-side data on AI interviews is worse than most people assume.

  • 51 percent of candidates who completed an AI interview were ghosted entirely or are still waiting to hear back. Not rejected. Never answered.
  • 70 percent were never told upfront that AI would be evaluating them. Another 21 percent only found out once the interview had already started.
  • 38 percent of candidates have already withdrawn from a hiring process because it involved an AI interview, and a further 12 percent say they would.
  • 53 percent of job seekers were ghosted by an employer at some point in the past year, a three-year high.

Put those together and the transaction becomes visible. Roughly seven in ten people are not told a machine is assessing them until it already is, and roughly half of those who complete the process never hear another word. The recording, the face scan, the ID and the transcript stay exactly where they are.

51%of people who complete an AIinterview are ghostedentirely, or are stillwaiting70%were never told upfront thatAI would be assessing them38%have already walked out of ahiring process because itinvolved an AI interview
Candidate-side outcomes. Sources: Fortune (May 2026) on AI interview withdrawal, and 2026 candidate-experience reporting on ghosting and disclosure.

This Is Not Legal Everywhere

The most useful thing you can know about the AI interview is that in a lot of jurisdictions, significant parts of it are already regulated or outright banned. Vendors do not lead with this.

European Union. Article 5(1)(f) of the AI Act has prohibited AI systems that infer emotions of a person in workplace and education contexts since 2 February 2025, with narrow exceptions for medical or safety purposes. The European Commission's guidelines state explicitly that use during recruitment or a probationary period is covered. The prohibition applies to any employer or vendor operating in the EU regardless of where it is headquartered. Penalties reach €35 million or 7 percent of global turnover. Systems that track gaze, expression or affect during a recruitment interview sit directly in the path of this rule. Separately, EU privacy regulators warned in July 2026 that fully automated hiring rejections may already breach Article 22 of the GDPR, which gives you the right not to be subject to a decision based solely on automated processing. GDPR enforcement in the employment sector already stands at 193 fines worth €360.9 million.

United States. The precedent that matters is Deyerler v. HireVue. In a decision issued 26 February 2024, an Illinois court largely denied HireVue's motion to dismiss a claim under the Biometric Information Privacy Act, and specifically rejected the argument that facial scans are not biometric identifiers merely because they are not used to identify a specific individual. That reasoning removes the standard defence used by AI interview vendors. HireVue has since agreed a $3.75 million settlement with a claim deadline of 13 October 2026. On top of BIPA: New York City's Local Law 144 requires an annual independent bias audit of automated employment decision tools, a public summary of the results, and at least ten business days' notice to candidates before the tool is used, enforced by the Department of Consumer and Worker Protection at $500 to $1,500 per violation. Illinois has a separate AI Video Interview Act. Colorado's SB 26-189, which replaced the earlier SB 24-205 framework in May 2026, takes effect in January 2027 and requires disclosure plus a human review pathway.

South Africa. POPIA introduced "biometrics" into South African law as a defined category and has been fully enforceable since July 2021. Processing biometric information requires a lawful basis, and recruiters are expected to obtain explicit consent and be transparent about use. Penalties reach R10 million or ten years' imprisonment.

UAE and Saudi Arabia. The UAE's PDPL treats biometric data as sensitive personal data and makes consent the default legal basis for processing. Saudi Arabia's PDPL, in force since 14 September 2023 with a further year of transition, applies across sectors and, in some cases, extraterritorially.

India. Relevant because a good share of layer-one operators are registered there. India's Digital Personal Data Protection framework governs consent and purpose limitation for personal data processing, and a recruiter collecting biometric material for a stated hiring purpose does not get to silently repurpose it.

None of this means a given company is breaking the law. It means there is a real, enforceable question you are entitled to ask before you press record, and a vendor that cannot answer it in writing is telling you something.


The Global Picture

The AI interview funnel does not exist in isolation. It sits on top of a job scam problem that is growing everywhere at once.

  • United States: job scam losses went from $90 million in 2020 to $501 million in 2024. Q4 2025 alone produced $150.4 million in losses from 25,002 reports, with a median individual loss of $2,000. The FTC estimates fewer than 10 percent of fraud victims ever report to a federal agency, so the real figure is a multiple of that.
  • United Kingdom: Action Fraud reports rose from 2,094 in 2022 to 4,876 in 2024, with an average reported loss of £4,707 and more than £17 million lost in 2025. 43 percent of UK Gen Z job seekers say they nearly fell for a job scam, and 31 percent say they actually did.
  • Europe: Romania accounts for nearly a fifth of reported scams, followed by Spain at 12 percent and the UK at 8 percent. Roughly one in three recruiters across the UK and Germany has had their own identity stolen and used to approach candidates.
  • Australia: AU$24.4 million lost to job and employment scams in 2025, with reports up 102.4 percent year on year, and a further AU$4 million lost in the first three months of 2026 alone. Reports from Australians aged 24 and under jumped from 377 to 877, up 132 percent. Reports rose disproportionately among First Nations people (76.3 percent), people with disability (114 percent) and culturally and linguistically diverse communities (51.4 percent). The AFP and the National Anti-Scam Centre have stood up a dedicated Job Scam Fusion Cell. Most telling of all: 65 percent of Australian professionals have decided not to apply for a role they wanted because they could not be confident it was real.
  • Middle East: legitimate recruiters in the UAE routinely use WhatsApp for hiring conversations, which is completely normal there and which makes WhatsApp-based recruitment fraud far harder to filter out than it is elsewhere. Familiarity is the attack surface.
  • Africa: this is where the bottom of the pipeline is most visible. Kenyan data workers annotating AI training material have been reported earning under $2 an hour against more than $20 for US counterparts, with Sama, an OpenAI contractor, paying $1.32 to $2 an hour. Outlier, Mindrift, Remotasks, Prolific and Appen all recruit across Kenya, Nigeria, Ghana, South Africa and Egypt. Across five major annotation platforms, workers spend 26.8 percent of their time unpaid, on tests, applications, training and hunting for the next task. A Data Labellers Association has formed in Kenya specifically because no grievance channel existed.

The US Department of Labor has had an open investigation into Scale AI's compliance with the Fair Labor Standards Act since at least August 2024, and Scale and its Outlier platform have faced multiple worker lawsuits alleging below-minimum-wage pay and contractor misclassification.


What to Check Before You Sit Down in Front of a Bot

You do not need to boycott AI interviews. Some of this work is real and pays. You need to know what you are trading and get it in writing.

Ask, in writing, what happens to the recording. Specifically: is the video, audio and transcript used to train any model, is it shared with or sold to third parties, how long is it retained, and how do you request deletion. A legitimate operator can answer this in one email. Save the reply.

Find out who the actual employer is before the interview, not after. If the recruiter cannot name the end client, there may not be one. "We'll match you to opportunities" is a database, not a job.

Check whether they are asking for government ID before there is an offer. Identity verification at the point of contract is normal. Passport scans at the point of application, before any human has spoken to you, is a collection step dressed as a compliance step.

Look for the disclosure the law may already require. In New York City you are owed at least ten business days' notice before an automated employment decision tool is used on you, and a published bias audit summary. In the EU, emotion inference during recruitment is prohibited outright. If you are being asked to submit to gaze tracking or affect analysis in a covered jurisdiction with no disclosure at all, that is not a grey area.

Search the company name plus "reviews" and "Reddit" before you apply, not after. Every one of the layer-one operators in this article had a visible complaint trail months before most applicants found it. Run the domain through RiskScope as well. It takes thirty seconds.

Treat "you are in our talent pool now" as the realistic outcome. Paid work is the bonus, not the baseline. Decide whether the trade is worth it on those terms, because those are the terms.

Be much more careful with anything that arrives unsolicited. A high-rate creative role you did not apply for, from a company you have never heard of, that wants you on camera within 48 hours, is the exact shape of the pattern described above.


If You Already Did One

If you interviewed with or worked through Mercor, check whether you are affected. Eligibility extends to people who applied for or performed work through the platform, participated in interviews or onboarding, or otherwise provided personal or financial information. Notification emails went out on 25 and 26 June 2026, but a notification is not the only way to be in scope.

Assume the voice is out. If your bank uses voiceprint matching as an authentication factor, switch it off and move to something else. A voiceprint you cannot change, paired with a passport scan of the same person, is the single most dangerous combination in that leaked dataset.

Warn the people a caller would impersonate you to. Agree a verification phrase with family and with anyone at work who could be asked to move money or reset access on your say-so. This is the same defence that works against family emergency voice cloning, and it works here for the same reason.

Freeze your credit and monitor for identity misuse, given the Social Security numbers, tax forms and banking details in scope.

Exercise your deletion rights where you have them. Under GDPR, POPIA, the UAE and Saudi PDPLs and comparable frameworks, you can request access to and erasure of personal data held about you. Organisations subject to GDPR generally have 30 days to respond. Ask other AI interview platforms you have used the same question, not just the one that got breached.

Report it.


The Uncomfortable Version

The instinct most people have about AI interviews is that somewhere behind the bot there is a con artist. That instinct is looking for the wrong threat.

There was no con artist at Mercor. There was a real company with real revenue, real clients among the biggest names in AI, a referral programme, a privacy page, and a consent checkbox. It collected exactly what it said it collected, from people who agreed. And then a package it depended on was poisoned for 40 minutes, and 40,000 people's faces, voices and passports went up for auction.

The lesson is not that AI recruiters are scams. It is that the AI interview concentrates the most irreplaceable data you own, your face, your voice and your identity documents, into one linked record, held by a company whose actual business is data infrastructure, protected by a software supply chain none of those 40,000 people ever agreed to trust. You can change a password. You cannot change your voice.

Sixty-five percent of Australian professionals now skip roles they actually want because they cannot tell what is real. That number is the real cost of this pattern, and it is not being paid by the platforms.


Before you hand your face, voice and ID to a recruiter you have not verified, run their domain through RiskScope. It is free and it takes less time than the interview will.


Related Reading


Sources: PYMNTS: AI Startup Mercor Faces Lawsuit Over Data Breach, All About Cookies: Mercor AI Data Breach, Hausfeld: Mercor Data Breach, Breacher.ai: What the Mercor Breach Changes for Deepfake Defense, Mercor talent documentation: AI Interview, Mercor Referral Policy and FAQs, TechCrunch: Micro1 raises funds at $500M valuation, Future of Privacy Forum: Red Lines under the EU AI Act, Epstein Becker Green: Deyerler v. HireVue, Deloitte: NYC Local Law 144 and Algorithmic Bias, Fortune: Nearly 4 in 10 job candidates have bailed on a hiring round that required an AI interview, FTC: Job Scams, National Anti-Scam Centre: Job Scam Fusion Cell, Australian Federal Police: Unicorn job scams, Euronews: As job scams rise in Europe, AlgorithmWatch: The AI Revolution Comes With the Exploitation of Gig Workers, SOMO: Big Tech sets unfair terms and conditions for AI data workers globally, TechCrunch: Scale AI is being investigated by the US Department of Labor, Michalsons: Biometrics laws around the world

Check Any Website Yourself

RiskScope is free. No signup required. Enter any domain and get an instant risk assessment.

Related Articles