ZeroHour
Security Affairspublished ()ingested @securityaffairs

88 ID Verification Breaches Show the Cost of Collecting Identity Data

highData breachimportance 68
AI summary · glm-5.3-flash

A report catalogs 88 ID-verification breaches since 2011 exposing at least 2.15 billion records, with 41 incidents leaking irreplaceable biometric data and documents.

A Mysterium VPN report compiles 88 documented breaches since 2011 involving identity and age-verification data, with confirmed exposure of 2.15 billion records and claimed totals of 4.54 billion. In 41 of 88 incidents, ID scans, verification selfies, fingerprints, and biometric templates leaked, data that cannot be changed after exposure. Notable cases include the Tea app's exposed selfies, Discord's ~70,000 government IDs, vendor failures at AU10TIX, Sumsub, and Persona, and national registry breaches in Argentina (45 million records) and France (11.7 million people).

  • 88 incidents since 2011 exposed at least 2.15 billion confirmed records, with claimed totals of 4.54 billion.
  • 41 of 88 incidents leaked source documents such as ID scans, selfies, fingerprints, and biometric templates.
  • 42% of the incidents (37) occurred between January 2024 and August 2026 as mandatory age checks spread.
  • Vendors AU10TIX, Sumsub, and Persona all suffered incidents affecting users of TikTok, Uber, X, Discord, and Roblox.
  • Government registries were also hit, including Argentina's 45-million-record leak and France's ANTS breach affecting 11.7 million people.
Full article693 words · extracted from securityaffairs.com · click to collapse

88 ID-verification breaches exposed billions of records, highlighting the growing risks of collecting sensitive identity and biometric data.

A new report from Mysterium VPN compiles 88 documented incidents since 2011 where data collected specifically to verify someone’s identity or age got breached, exposed, or sold. The confirmed and researcher-verified total sits at 2.15 billion records, with attacker and seller claims piling another 4.54 billion on top of that.

The most uncomfortable number in the whole dataset isn’t the total record count, it’s how much of it can’t be fixed after the fact. In 41 of the 88 incidents, what actually leaked included the source documents themselves: ID scans, verification selfies, fingerprints, full biometric templates. A password gets reset in thirty seconds. A face doesn’t.

The timing makes the report especially concerning. Of the 88 incidents, 37, or 42%, happened between January 2024 and August 2026, when mandatory identity and age checks were spreading quickly around the world. The message is simple: the systems that collect your ID can be breached just like any other online service.

“The pattern of this era is specific: the wall you are forced to hand your ID to is exactly as breachable as everything else on the internet.” reads the report.

Some recent cases are particularly worrying. The Tea app, created as a women-only safety platform, exposed verification selfies through an open storage bucket, and the images later appeared on 4chan. Discord users who challenged age-verification decisions also had around 70,000 government IDs exposed through a third-party support provider, even as Discord continued expanding age checks.

What makes this particularly damning is who’s actually running the verification layer for the internet’s biggest platforms. AU10TIX, which verifies identity for TikTok, Uber, and X, left admin credentials exposed for over a year. Sumsub disclosed a support-system intrusion that went undetected for 18 months. Persona, which handles age verification for Discord and Roblox, exposed its own frontend configuration.

“In 41 of the 88 incidents, what leaked included the actual documents: ID scans, verification selfies, fingerprints, biometric templates. Unlike a password, none of that can be changed.” states the report. “Every major identity-verification vendor from the current era — AU10TIX, IDMerit, Sumsub, Persona, inVOID — has appeared in this timeline. The companies the internet now relies on to hold everyone’s identity documents safely haven’t demonstrated they can do it.”

Governments haven’t fared any better with their own centralized registries. Argentina’s national identity system leaked 45 million records including ID scans and selfies. France’s ANTS, the agency that literally issues French identity documents, confirmed 11.7 million people affected in a 2026 breach. India’s Aadhaar system, Thailand’s visitor database, the Philippines’ voter rolls, Brazil’s tax registry, the pattern repeats at country scale roughly as often as it does at startup scale.

The report isn’t blaming one company or one mistake. Its main point is that the growing use of ID and age checks is creating more opportunities for sensitive data to be exposed.

Every new law that requires ID checks, every platform that adds age verification, and every company that stores identity data creates another valuable target. Putting permanent and highly sensitive information into systems with different levels of security creates a risk that’s hard to ignore.

This doesn’t mean ID and age verification have no value. They can serve legitimate purposes. But companies deciding whether to build or outsource these systems should study this history carefully. Relying on a “reputable” third-party provider clearly isn’t enough.

“The timeline makes something visible that individual breach reports obscure: this isn’t a series of unrelated failures. It’s one failure mode, repeated across 88 incidents, fifteen years, and every type of organization that has ever decided to collect this category of data.” concludes the report. “What varies is the victim. Sometimes, it’s a startup with inadequate security. Sometimes, it’s a national government that built a country-scale identity registry and watched it walk out the door. Sometimes, it’s a verification vendor that became the single point of failure for a dozen companies that outsourced their compliance obligations to them. “

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, ID Verification Breaches)



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/197855/reports/88-id-verification-breaches-show-the-cost-of-collecting-identity-data.html