Meta Outsourcer Exposed in Massive Credential Leak

Research from Suzu Labs reveals over 100 compromised credentials at Sama, the firm reviewing sensitive smart glasses footage.

Evidence of security lapses at a major data annotation firm has raised new questions about the privacy of users wearing AI-powered eyewear. Research released by Suzu Labs indicates that Sama, an outsourcing company used by Meta to review video captured by its smart glasses, has suffered a significant exposure of corporate credentials.

The findings come shortly after reports that human annotators in Kenya were tasked with reviewing footage from the glasses, which at times included intimate moments recorded in private settings. Suzu Labs, using dark web intelligence tools, identified 118 credential entries tied to the company’s corporate domain circulating on underground forums and Telegram channels.

The dataset included dozens of unique email addresses and plaintext passwords. Security analysts noted that 88% of the analyzed passwords failed to meet basic complexity requirements, with many being shorter than eight characters or consisting entirely of digits.
The exposure is particularly concerning given the nature of the data handled by the firm.

Information-stealer malware, designed to siphon login tokens and passwords from infected devices, was the source for the majority of the leaked data. If an employee's workstation used to access internal annotation platforms is compromised, the entire pipeline of user footage could be at risk.

Industry experts emphasize that third-party risk management is a critical component of data security. When companies outsource the processing of sensitive biometric or visual data, the security posture of the vendor becomes a direct extension of the primary company's risk profile.

Meta has previously stated that it uses contractors to improve its AI services and that data is filtered to protect privacy, including the blurring of faces. However, the current leak suggests that the human element of this supply chain may remain a vulnerable link.

Security professionals recommend that organizations handling sensitive consumer data implement multi-factor authentication and rigorous endpoint monitoring to prevent credential stuffing and malware-based breaches.

About the Author

Jesse Jacobs is assistant editor of SecurityToday.com.

Featured

New Products

  • PE80 Series

    PE80 Series by SARGENT / ED4000/PED5000 Series by Corbin Russwin

    ASSA ABLOY, a global leader in access solutions, has announced the launch of two next generation exit devices from long-standing leaders in the premium exit device market: the PE80 Series by SARGENT and the PED4000/PED5000 Series by Corbin Russwin. These new exit devices boast industry-first features that are specifically designed to provide enhanced safety, security and convenience, setting new standards for exit solutions. The SARGENT PE80 and Corbin Russwin PED4000/PED5000 Series exit devices are engineered to meet the ever-evolving needs of modern buildings. Featuring the high strength, security and durability that ASSA ABLOY is known for, the new exit devices deliver several innovative, industry-first features in addition to elegant design finishes for every opening.

  • Compact IP Video Intercom

    Viking’s X-205 Series of intercoms provide HD IP video and two-way voice communication - all wrapped up in an attractive compact chassis.

  • Camden CV-7600 High Security Card Readers

    Camden CV-7600 High Security Card Readers

    Camden Door Controls has relaunched its CV-7600 card readers in response to growing market demand for a more secure alternative to standard proximity credentials that can be easily cloned. CV-7600 readers support MIFARE DESFire EV1 & EV2 encryption technology credentials, making them virtually clone-proof and highly secure.