88 Breaches at ID Verification Services: 2.15 Billion Records
More and more sites now ask you to prove who you are by uploading a passport photo or a live selfie. A new tally shows how badly that is going. Counting only identity-verification breaches, researchers found 88 separate incidents since 2011, exposing 2.15 billion confirmed records, with attackers and sellers claiming another 4.54 billion on top. The uncomfortable part: you can reset a password, but you cannot reset your face or your passport, and those are exactly what these services collect.
What the numbers show
The timeline, compiled by researchers at Mysterium VPN and reported by Security Affairs, is not about ordinary logins. In 41 of the 88 incidents, nearly half, what leaked was the source material itself: ID scans, verification selfies, fingerprints and full biometric templates. And the problem is accelerating: 37 of the breaches, about 42 percent, happened between January 2024 and August 2026, exactly as mandatory identity and age checks spread across the web.
- 88 breaches at identity-verification providers since 2011.
- 2.15 billion confirmed records exposed, plus 4.54 billion more claimed by attackers.
- 41 of 88 incidents leaked actual documents and biometrics, not just email and password pairs.
- 42 percent of the incidents landed in the last year and a half, as verification mandates grew.
The middlemen you never chose
When an app asks for your ID, it usually hands the job to a third-party verifier you have never heard of and never agreed to trust. The same names keep showing up in the breach timeline: AU10TIX, IDMerit, Sumsub, Persona and inVOID among them. One of them left an administrative login exposed for months; another left roughly a billion records sitting in an open database. Each of these companies sits behind dozens of popular apps, so a single lapse can spill the documents of users who never even knew the vendor existed.
Why this is worse than a leaked password
A stolen password is an inconvenience: you change it and move on. A leaked passport scan and a verification selfie are permanent. The same face and the same document are reused across every service that ever asks you to verify, so one breach can feed identity fraud, account takeovers and deepfake attacks for years. As the researchers put it, the wall you are forced to hand your ID to is exactly as breachable as everything else on the internet.
What it means for age verification
This is the strongest argument against turning the open web into an ID checkpoint. Laws that require you to prove your age push every user through these verification choke points, and every choke point is a honeypot of faces and documents. If you want to see how fast that requirement is spreading, we keep a running list of countries that ban or gate social media for minors. The more places demand your ID, the more copies of it end up in databases you cannot audit.