88 Breaches at ID Verification Services: 2.15 Billion Records

26.08.2026 4 min 6

More and more sites now ask you to prove who you are by uploading a passport photo or a live selfie. A new tally shows how badly that is going. Counting only identity-verification breaches, researchers found 88 separate incidents since 2011, exposing 2.15 billion confirmed records, with attackers and sellers claiming another 4.54 billion on top. The uncomfortable part: you can reset a password, but you cannot reset your face or your passport, and those are exactly what these services collect.

What the numbers show

The timeline, compiled by researchers at Mysterium VPN and reported by Security Affairs, is not about ordinary logins. In 41 of the 88 incidents, nearly half, what leaked was the source material itself: ID scans, verification selfies, fingerprints and full biometric templates. And the problem is accelerating: 37 of the breaches, about 42 percent, happened between January 2024 and August 2026, exactly as mandatory identity and age checks spread across the web.

  • 88 breaches at identity-verification providers since 2011.
  • 2.15 billion confirmed records exposed, plus 4.54 billion more claimed by attackers.
  • 41 of 88 incidents leaked actual documents and biometrics, not just email and password pairs.
  • 42 percent of the incidents landed in the last year and a half, as verification mandates grew.

The middlemen you never chose

When an app asks for your ID, it usually hands the job to a third-party verifier you have never heard of and never agreed to trust. The same names keep showing up in the breach timeline: AU10TIX, IDMerit, Sumsub, Persona and inVOID among them. One of them left an administrative login exposed for months; another left roughly a billion records sitting in an open database. Each of these companies sits behind dozens of popular apps, so a single lapse can spill the documents of users who never even knew the vendor existed.

Why this is worse than a leaked password

A stolen password is an inconvenience: you change it and move on. A leaked passport scan and a verification selfie are permanent. The same face and the same document are reused across every service that ever asks you to verify, so one breach can feed identity fraud, account takeovers and deepfake attacks for years. As the researchers put it, the wall you are forced to hand your ID to is exactly as breachable as everything else on the internet.

What it means for age verification

This is the strongest argument against turning the open web into an ID checkpoint. Laws that require you to prove your age push every user through these verification choke points, and every choke point is a honeypot of faces and documents. If you want to see how fast that requirement is spreading, we keep a running list of countries that ban or gate social media for minors. The more places demand your ID, the more copies of it end up in databases you cannot audit.

Important: you cannot un-leak a face. Before uploading a passport or a selfie, ask whether the service truly needs it, prefer options that estimate age without storing documents, and keep an eye on breach notifications for any verifier you have used. The real fix here is policy, not a setting you can toggle.
Can I just avoid these checks?
Sometimes. Where a service offers privacy-preserving age estimation that does not store your document, prefer it. But where verification is mandatory, you often have no choice but to hand over an ID, which is exactly why the systemic risk matters.
Does a VPN protect me from this?
Not from this specific risk. A VPN hides your IP and encrypts your connection, but once you upload your passport to a verification company, a VPN cannot protect that company's database. It helps with tracking and access, not with a vendor that gets breached after you hand over your documents.
My ID may already be in one of these leaks. What now?
Assume it is reusable against you. Enable two-factor authentication on important accounts, be extra sceptical of calls or messages that quote your real details, and watch bank and government accounts for fraud. Unlike a password, you cannot rotate the document, so vigilance is the defence.
Are privacy-preserving checks safe?
Safer, if they genuinely estimate age or validity without keeping the raw scan and selfie. The danger in this report is retention: services that store the source documents become the honeypots. Methods that verify and immediately discard shrink the target.

age verificationdata breachidentity verificationAU10TIXSumsubPersonaIDMeritbiometricsprivacy

Read also