Your Face Is Not a Password: 88 Identity Breaches and 2.15 Billion Exposed Records

0
281

Somewhere in the last few years, the internet decided it needed to know who you actually are. Not your email address. Not your handle. Your real identity, in the form of government IDs, selfies, and biometric data, collected by companies whose entire pitch is that they can be trusted with the one set of data you can never change.

That pitch took a beating this week. Mysterium VPN published a timeline that should worry anyone who has ever uploaded a driver's license or stared into a liveness-check camera: 88 documented breaches of identity-verification systems since 2011, and a confirmed 2.15 billion exposed records. The unconfirmed claims from attackers and data sellers pile another 4.54 billion on top. This is not a niche security story. It is a story about the architectural decisions every platform on the internet is making right now.

The Report That Counted Every Identity Breach

Mysterium's report compiles incidents where data collected specifically to verify someone's identity or age got breached, exposed, or sold. The scope is staggering: confirmed and researcher-verified totals sit at 2.15 billion records, with attacker and seller claims adding 4.54 billion more. The most uncomfortable number in the dataset is not the record count, though. It is how much of it cannot be fixed after the fact.

In 41 of the 88 incidents, what actually leaked included the source documents themselves: ID scans, verification selfies, fingerprints, and full biometric templates. A password gets reset in thirty seconds. A face does not. Once that material is out, it stays out, and it can be used against its owner for the rest of their life.

The 41 Breaches That Can't Be Undone

That distinction between ordinary breaches and identity breaches is the whole story. Leaked passwords are a transient problem; you rotate them and move on. Leaked government ID scans paired with liveness-check selfies are a permanent liability. Security researchers point to the obvious follow-ons: synthetic identity fraud, credential stuffing built on reused document data, and social engineering pretexts strong enough to defeat secondary authentication for the victim's entire lifetime.

The report makes the point bluntly: every major identity-verification vendor of the current era, AU10TIX, IDMerit, Sumsub, Persona, inVOID, has appeared in this timeline. The companies the internet now relies on to hold everyone's identity documents safely have not demonstrated they can do it. This is not one bad actor. It is a systemic pattern.

The Supply Chain Problem: One Vendor, Dozens of Platforms

Here is where the story stops being abstract. AU10TIX, an Israel-based company that verifies identity for TikTok, Uber, and X, exposed administrative credentials online for more than a year. Investigators at 404 Media, working with researcher Mossab Hussein, found the credentials opened a logging platform containing links to personal data: names, dates of birth, nationalities, ID numbers, document images, and driver's licenses. The exposure has been tied to an infostealer infection. AU10TIX's client list also reportedly includes Coinbase, LinkedIn, Airbnb, Fiverr, Payoneer, and Saxo Bank. One vendor, dozens of platforms, one exposed set of credentials.

It is not an isolated case. Sumsub disclosed a support-system intrusion that went undetected for 18 months. Persona, which handles age verification for Discord and Roblox, exposed its own frontend configuration. Discord users who challenged age-verification decisions had around 70,000 government IDs exposed through a third-party support provider, not even through Discord's primary infrastructure. The attack surface extends to every subcontractor in the verification workflow.

The Tea App Shows What Happens When ID Photos Leak

The consequences stop being abstract fast. Tea, a women-only dating and safety platform that had climbed to 1.7 million users and the top of the App Store, left a Firebase database exposed. The result: roughly 72,000 images leaked, including 13,000 verification selfies and about 59,000 profile pictures. Those selfies ended up on 4chan. Trolls built games ranking the women's appearances. Maps appeared online that allegedly tracked where users lived. 404 Media reviewed the evidence. The app was supposed to be a safe space built on identity verification. The verification data is exactly what got weaponized.

That is the trap. The more platforms lean on identity collection to prove safety, the more valuable the resulting data becomes to people whose entire hobby is destroying that safety. The wall you are forced to hand your ID to is exactly as breachable as everything else on the internet.

Governments Are Building Bigger Honeypots

Governments have not fared any better with their own centralized registries. Argentina's national identity system leaked 45 million records, including ID scans and selfies. France's ANTS, the agency that literally issues French identity documents, confirmed 11.7 million people affected in a 2026 breach. India's Aadhaar system, Thailand's visitor database, the Philippines' voter rolls, Brazil's tax registry. The pattern repeats at country scale roughly as often as it does at startup scale.

This matters because a breach of a national ID database is not just a privacy incident. It is an intelligence windfall that enables cross-border identity fraud for decades. Nation-state actors and organized criminal groups know it. Centralized biometric registries, however well-intentioned, are single points of failure with national-scale consequences.

What This Means: Regulation Is Creating the Exposure

The timing makes this report especially damning. Of the 88 incidents, 37, or 42 percent, happened between January 2024 and August 2026, precisely as mandatory identity and age checks were spreading around the world. Regulatory pressure is outrunning technical safeguards. When governments mandate identity checks, platforms rush to bolt on third-party verification without adequate due diligence on the vendor's security posture. The result is a supply chain where one compromised vendor cascades across dozens of consumer platforms.

The report's conclusion is worth reading twice: this is not a series of unrelated failures. It is one failure mode, repeated across 88 incidents, fifteen years, and every type of organization that has ever decided to collect this category of data. What varies is the victim. Sometimes it is a startup with inadequate security. Sometimes it is a national government that built a country-scale identity registry and watched it walk out the door. Sometimes it is a verification vendor that became the single point of failure for a dozen companies that outsourced their compliance obligations to it.

What Comes Next: Verification Without Retention

There is a way out, and it does not require giving up age checks or KYC. It requires changing what gets stored. Tokenized verification flows can return a simple assertion, yes or no, without the vendor ever storing the document. Zero-knowledge proofs and decentralized identity standards can confirm age, residency, or identity status while the biometric scans and government IDs stay on the user's device. Data minimization means deleting source documents the moment verification completes, unless there is explicit, revocable consent to keep them.

Buyers of verification services need contract teeth: 72-hour breach notification, independent annual penetration tests, audit rights, and a full map of every subprocessor in the workflow. Policymakers need to pair identity mandates with security standards, not just requirements to collect more. Requiring age verification without requiring the provider to meet a defined security baseline is legislative malpractice.

The 88 incidents in this report are not a historical record. They are a leading indicator. The industry built on holding your face and your ID in a database is going to keep getting breached until it stops holding them in the first place. If you run a platform, or you are about to bolt on a verification vendor, do the due diligence. If you are a user, assume that anything you upload for verification is one misconfiguration away from the internet. The systems that collect your ID can be breached like any other online service. The only fix is to collect less.

— Allan Ali, Sylt.ing

Căutare
Categorii
Citeste mai mult
AI Tools & Software
PJM's Grid Is 6.8 Gigawatts Short and Data Centers Are Driving the Crisis
PJM's Grid Is 6.8 Gigawatts Short — and Data Centers Are Driving the Crisis On July 14,...
By Allan 2026-07-22 20:10:51 0 2K
AI News & Updates
The Real Cost of Building with AI Agents vs Traditional Coding: The Numbers That Actually Matter
The Real Cost of Building with AI Agents vs Traditional Coding: The Numbers That Actually Matter...
By Jessica 2026-07-07 17:04:06 0 529
AI News & Updates
The Tools Every AI Engineer Actually Needs in 2026
The Tools Every AI Engineer Actually Needs in 2026 NVIDIA GPUs Remain Non-Negotiable for...
By Jessica 2026-07-23 17:04:09 0 544
Generative AI & AI Art
From Brief to Shelf: How AI-Generated Label Design is Reshaping Food Product Launches
From Brief to Shelf: How AI-Generated Label Design is Reshaping Food Product Launches Walk down...
By Patty 2026-08-20 17:07:27 0 417
Generative AI & AI Art
Infusing AI Magic into Your Design Workflow
Embracing AI as Your Creative Companion Discovering Fresh Inspiration Daily Hey friend! Mornings...
By Patty 2026-07-09 12:31:13 0 737