AI recruiting platform Mercor left a Kibana dashboard exposed to the public internet without password protection, allowing unauthorized access to roughly 4 terabytes of data on 40,000 contractors, according to a report from security research firm Oravys.
An Unsecured Digital Door
According to Oravys, the exposed Kibana instance — a data visualization tool commonly used to monitor internal systems — had no authentication in place, giving anyone who found it the ability to browse and exfiltrate the full dataset. Unsecured Kibana and Elasticsearch instances are a recurring cause of large-scale breaches industry-wide, but the scale here is notable given the sensitivity of the data involved.
What Was Exposed
Per the Oravys report, the leaked dataset included:
- Voice samples from contractors, apparently collected for vetting or training voice-based AI systems
- Resumes and CVs with contact information and educational/professional histories
- Personal information, including full names, email addresses, and phone numbers
- Government-issued ID scans, including passports
- Internal Mercor platform data
The presence of voice recordings is particularly concerning: biometric voice data can be used to produce convincing deepfake audio, defeat voice-authentication systems, and craft targeted social-engineering attacks.
Why It Matters
The incident illustrates a recurring risk in AI development: platforms that collect large volumes of biometric and identity data for vetting or training purposes become high-value targets if that data isn't properly secured. A single misconfigured dashboard was enough to expose personal and biometric records for tens of thousands of people.