background image blur
background image

An ID Check Breach Timeline: 2011–2026

Image of author
By Tech Writer and VPN Researcher Gintarė Mažonaitė
clock icon
Last updated: 26 August, 2026
A hacker in a hoodie using his laptop next to many monitors

Key Takeaways

  • We documented 88 incidents since 2011 in which data collected specifically to verify identity or age was breached, exposed, or put up for sale — affecting at least 2.15 billion records on a confirmed or researcher-verified basis, with attacker- and seller-claimed figures adding a further 4.54 billion.
  • 42% of all incidents (37 of 88) date from January 2024 to August 2026, the period in which mandatory identity verification spread fastest. The rate is accelerating alongside the mandates.
  • In 41 of the 88 incidents, what leaked included the actual documents: ID scans, verification selfies, fingerprints, biometric templates. Unlike a password, none of that can be changed.
  • Every major identity-verification vendor from the current era — AU10TIX, IDMerit, Sumsub, Persona, inVOID — has appeared in this timeline. The companies the internet now relies on to hold everyone's identity documents safely haven't demonstrated they can do it.
An infographic showing breach timeline by year

Every year, more of the internet demands that you prove who you are before you may use it: KYC checks to open an account, a driver’s license to join a dating app, a passport scan to check into a hotel, a face scan to read an adult site in the UK, a government ID to appeal a Discord ban. 

Every one of those checks creates a copy of the most permanent data you have. This timeline compiles what happened to those copies.

We found 88 publicly documented incidents since 2011 in which data collected specifically to verify identity or age – government ID scans, verification selfies, biometric templates, KYC files, national ID registries – was breached, exposed, or put up for sale. 

On figures with a confirmed or researcher-verified basis, at least 2.15 billion identity-verification records have been affected; attacker- and seller-claimed figures add a further 4.54 billion on top. In 41 of the 88 incidents, the leaked material included the documents themselves: the scans, the selfies, the fingerprints – data that, unlike a password, can never be rotated.

The timeline is accelerating exactly as verification mandates spread: 37 of the 88 incidents (42%) date from January 2024 through August 2026, the era of the UK Online Safety Act, US state age-verification laws, and mandatory KYC nearly everywhere. 

The incidents of this era make the argument by themselves: the Tea app’s verification selfies scraped onto 4chan; 70,000 government IDs from Discord users’ age appeals leaked through a support vendor; the identity-verification vendors themselves (AU10TIX, IDMerit, Sumsub, Persona, inVOID) turning up with exposed credentials, open databases, or breached support systems. Nobody had compiled this record in one place. Now it is one dataset, one row per incident, with sources.

The Numbers

MeasureValue
Documented incidents, 2011 – Aug 202688 (2 further candidates rejected in fact-checking)
Incidents in 2024 – Aug 202637 (42% of all) – 2025 alone: 15; 2026 to date: 10
Records affected – confirmed/researcher-verified basis2.15 billion
Records affected – attacker/seller-claimed basis (on top)4.54 billion
Incidents where ID documents/selfies/biometrics/KYC files leaked41 of 88
Age-verification-specific incidents12 – from Omiai’s 1.7M documents (2021) to Discord, Persona and beyond (2025–26)
Confirmed breaches/exposures/vendor incidents58 / 24 / 6
Government or national-ID-system incidents20+ (OPM to France ANTS)

2011–2016: The Warning Shots

The pattern was set before anyone said “KYC” in public: South Korea’s Nate/Cyworld breach put 35 million resident registration numbers in criminal hands (2011); the US Office of Personnel Management lost 21.5 million background-investigation dossiers and 5.6 million fingerprint sets (2015); Turkey’s civil-registry extract of ~49 million circulated freely (dumped 2016); the Philippines’ COMELEC voter database, with passport numbers, was published outright (2016). 

Each was treated as an anomaly. Collectively they demonstrated the base fact that identity registries concentrate exactly on the data that can't be reissued.

2017–2021: KYC Goes Mainstream, and Leaks With It

As exchanges and fintechs institutionalized identity checks, the checks themselves became the loot: Binance extortion dumps of KYC selfies (2019), BioStar 2’s 27.8 million biometric access records sitting in an open Elasticsearch (2019), India’s BuyUcoin, Upstox and MobiKwik KYC troves (2021), Argentina’s RENAPER national registry offered for sale (2021, government disputes scale). 

The Ecuador (Novaestrat) and Brazil mega-aggregations showed the broker side of the same machine.

2022–2024: Governments Lose the Master Files

Optus and Latitude turned Australian ID-check mandates into millions of exposed licence and passport numbers and forced national reform. Thailand, Indonesia, Bangladesh, the Philippines police, Paraguay and El Salvador each lost citizen-scale registries – El Salvador’s dump included 5.1 million facial photos. India’s ICMR/Aadhaar-linked listing claimed 815 million

The US saw its background-check industry breached at scale (National Public Data, 272 million verified records).

By the end of 2024, the question was no longer whether national identity stores leak, but which one is next.

2025–2026: The Age Verification Era

Then the laws arrived that made showing ID a condition of ordinary internet use – and the incidents followed within months. The Tea app’s women-only verification selfies were scraped from an open bucket and sorted into sleazy rating threads on 4chan (July 2025).

Discord users who appealed age decisions had ~70,000 government IDs leak through a third-party support vendor (October 2025) – while Discord rolled age checks out globally anyway. 

Japan’s Omiai had already shown the shape of it in 2021: 1.7 million age-verification document images. And the verification industry itself joined the timeline: AU10TIX (verifier for TikTok, Uber, X) left admin credentials exposed for over a year; IDMerit was reported with ~1 billion identity records reachable in an open database (disputed by the company, flagged as claimed); Sumsub disclosed an 18-month-undetected support-system intrusion; Persona, Discord and Roblox’s age-verification vendor, exposed its own frontend configuration; France’s ANTS (the agency that issues French IDs) was breached with 11.7 million people confirmed affected. 

The pattern of this era is specific: the wall you are forced to hand your ID to is exactly as breachable as everything else on the internet.

An infographic showing the scatter of breach records

The Timeline

DateIncidentWhat leakedPeopleClassAV
2011-07SK Communications (Nate/Cyworld) breach – national IDsID numbers35 Mbreach✔️
2011-11Nexon Korea (MapleStory) breach – real-name-era national IDsID numbers13 Mbreach✔️
2015-06OPM background-investigation breachSSNs, biometrics, KYC files22 Mbreach
2016-04Turkey MERNIS national-ID database leakID numbers50 Mbreach
2016-04Philippines COMELEC 'Comeleak' voter breachbiometrics, passports, ID numbers55 Mbreach
2016-04Qatar National Bank data dumpID numbers, passports100 Kbreach
2016-06World-Check risk database leak (2016)ID numbers2.2 Mexposure
2017-10Malaysia telco 46.2M subscriber leak (MyKad)ID numbers46 Mbreach
2018-01Aadhaar / UIDAI 'Rs 500' database access (Tribune)ID numbers1.2 B *exposure
2018-04TrueMove H ID-card scan exposureID scans, ID numbers, DL46 Kexposure
2018-11Marriott / Starwood passport exposurepassports5.3 Mbreach
2019-02SenseNets facial-recognition database exposurebiometrics, ID numbers2.6 Mexposure
2019-05First American Financial document exposureID scans, DL, SSNs885 Mexposure
2019-06Perceptics / CBP traveler-image breachbiometrics, selfies184 Kbreach
2019-06Desjardins insider data breachID numbers, SSNs9.7 Mbreach
2019-07Bulgaria National Revenue Agency hackID numbers5.0 Mbreach
2019-08Binance KYC photo leak/extortionKYC files, ID scans, selfies10 K *breach
2019-08BioStar 2 / Suprema biometric exposurebiometrics27.8 Mexposure
2019-09Ecuador Novaestrat data leakID numbers21 Mexposure
2020-01PussyCash / ImLive cam-network model verification files exposureID scans, KYC files, SSNs, selfies875 Kexposure✔️
2020-01SextPanther model identity-document exposureID scans, DL, SSNs, KYC files11 Kexposure✔️
2020-02Digitex Futures KYC leakKYC files, passports, DL8 K *breach
2020-03Antheus Tecnologia fingerprint exposurebiometrics76 Kexposure
2020-11Liquid exchange breach (KYC documents potentially accessed)none confirmed (at risk: KYC files, ID scans, selfies)n/avendor
2021-01BuyUcoin crypto-exchange KYC leakKYC files, ID numbers325 Kbreach
2021-01Brazil 223M CPF 'megavazamento'ID numbers, biometrics223 Mbreach
2021-02CityBee user database leak (national ID codes)ID numbers110 Kbreach
2021-03MobiKwik alleged KYC breachKYC files, ID scans, ID numbers3.5 M *breach
2021-04Upstox KYC document breachKYC files, ID scans, ID numbers111 Kbreach
2021-05Omiai age-verification document breachID scans, DL1.7 Mbreach✔️
2021-07Estonia ID-photo theft from state databaseID scans286 Kbreach
2021-08T-Mobile 2021 breach (SSN/ID numbers)SSNs, DL, ID numbers77 Mbreach
2021-09OnlyFans ex-employee retained access to creator KYC datanone confirmed (at risk: KYC files, ID scans, selfies)n/avendor✔️
2021-09Thailand 106M international-visitor database exposurepassports, ID numbers106 Mexposure
2021-10Argentina RENAPER national registry breachID numbers, ID scans, selfies45 M *breach
2022-07Shanghai National Police database leakID numbers1 B *breach
2022-09Optus data breachpassports, DL, ID numbers9.5 Mbreach
2022-10Medibank ransomware breachpassports, ID numbers9.7 Mbreach
2022-12BetMGM patron database breachssn (hashed), ID numbers1.6 M *breach✔️
2023-03Thailand 9near '55 million Thais' claimID numbers55 M *breach
2023-03Latitude Financial data breachDL, passports, ID scans14 Mbreach
2023-04RentoMojo KYC breachKYC files, ID scans, ID numbers2.2 Mbreach
2023-04Philippines PNP / NBI applicant records leakID scans, biometrics, ID numbers1.3 Mexposure
2023-05Worldcoin Orb operator credential theftnone confirmed (at risk: biometrics)n/avendor
2023-06CoWIN vaccine portal data on TelegramID numbers, passportsn/abreach
2023-06MOVEit DMV cluster (Louisiana OMV / Oregon DMV)DL, ID numbers, SSNs9.8 Mbreach
2023-07Indonesia Immigration 34M passport leak (Bjorka)passports, ID numbers35 M *breach
2023-07Bangladesh government website citizen-registry leakID numbers50 Mexposure
2023-10ICMR / '815 million Indians' Aadhaar-passport listingID numbers, passports815 M *breach
2023-11Strendus casino KYC/ID-number exposureID numbersn/aexposure✔️
2023-11Indonesia KPU voter-roll breach (204M)ID numbers204 M *breach
2024-03Pakistan NADRA digital-ID data theftID numbers, biometrics2.7 Mbreach
2024-04El Salvador citizen headshots + ID dumpselfies, ID numbers, biometrics5.1 Mbreach
2024-04World-Check theft claim (GhostR, 2024)ID numbers, passports5.3 M *breach
2024-05Outabox / ClubsNSW biometric and licence-scan breachbiometrics, DL, ID numbers1.1 Mbreach✔️
2024-06AU10TIX exposed admin credentials (ID verification for TikTo…ID scans, DL, selfiesn/aexposure
2024-06Nigeria NIN/BVN resale via AnyVerify and othersID numbersn/aexposure
2024-07Fractal ID KYC breach (web3 identity provider)ID scans, selfies, KYC files5 Kbreach
2024-08National Public Data (Jerico Pictures) breachSSNs, ID numbers272 Mbreach
2024-09MC2 Data background-check exposureSSNs106 Mexposure
2024-10Transak KYC data breachKYC files, ID scans, selfies93 Kbreach
2024-12Signzy security incident (ID-verification vendor)None confirmed (at risk: KYC files)n/avendor
2024-12Byte Federal (Bitcoin ATM) breachID scans, SSNs, ID numbers58 Kbreach
2025-02DISA Global Solutions breachSSNs, DL, ID numbers3.3 Mbreach
2025-03M.A.D Mobile dating apps image leak (incl. verification phot…selfies1.5 M *exposure
2025-04Morocco CNSS social-security breachID numbers2.0 M *breach
2025-05Coinbase insider-bribery KYC breachID scans, KYC files, SSNs, ID numbers69 Kbreach
2025-05LexisNexis Risk Solutions breach (GitHub-linked)SSNs, DL, ID numbers364 Kbreach
2025-06Paraguay 7.4M citizen records leakID numbers7.4 M *breach
2025-07Bitcoin Depot customer breach (driver's licence numbers)DL, ID numbers27 Kbreach
2025-07Tea app verification selfies and ID breachselfies, ID scans, DL72 Kbreach
2025-08TeaOnHer driver's license/selfie exposureDL, selfiesn/aexposure
2025-08Italian hotels guest ID-scan theftID scans, passports91 Kbreach
2025-08Miljodata ransomware (Swedish personal IDs)ID numbers1.5 Mbreach
2025-09Prosper Marketplace breachSSNs, ID numbers18 M *breach
2025-09Vietnam National Credit Information Center (CIC) breachID numbers, ID scans160 M *breach
2025-10Discord third-party support breach (age-appeal government IDs)ID scans, selfies70 Kbreach✔️
2025-11Checkout.com legacy-storage KYC breachKYC files, ID scansn/abreach
2026-02Sumsub support-environment breach (18 months undetected)n/an/avendor
2026-02IDMerit open database (~1B identity records)ID numbers1 B *exposure
2026-02Persona age-verification frontend/code exposuren/an/avendor✔️
2026-02Odido (Dutch telco) extortion breachpassports, DL, ID numbers6.1 Mbreach
2026-03Addi (Colombian fintech) extortion breachID numbers35 Mbreach
2026-04France ANTS national ID agency breachn/a12 Mbreach
2026-05Tabiq / Reqrea hotel check-in ID exposurepassports, DL, selfies, ID scans1.0 Mexposure
2026-05UK Visa Portal passport/selfie exposurepassports, selfies, ID scans100 Kexposure
2026-06inVOID (Bureau) India KYC database key exposureKYC files, ID numbers, biometric data16 Mexposure
2026-06Cannabis Club Systems (Spain) photo-ID exposurepassports, DL, ID scans985 Kexposure✔️
  • * = record figure is attacker- or seller-claimed.  
  • AV = age-verification-related. 
  • “vendor” = capability exposure with no confirmed personal-data leak. 

What This Record Shows

The timeline makes something visible that individual breach reports obscure: this isn't a series of unrelated failures. It's one failure mode, repeated across 88 incidents, fifteen years, and every type of organization that has ever decided to collect this category of data.

What varies is the victim. Sometimes, it's a startup with inadequate security. Sometimes, it's a national government that built a country-scale identity registry and watched it walk out the door. Sometimes, it's a verification vendor that became the single point of failure for a dozen companies that outsourced their compliance obligations to them. 

The mechanism stays constant: concentrated, irreplaceable, maximum-sensitivity data in a place that eventually gets breached.

The policy context matters here. The incidents in this timeline aren't a bug in the age-verification system. They're the predictable output. Every law that makes identity checks mandatory, every platform that adds an ID gate, and every verification vendor that builds a centralized database creates a new target. 


Share on
Facebook share Twitter share Reddit share Linkedin share

Be part of the resistance, quietly.

Get Mysterium VPN Arrow icon
awareness campaign banner img
Image of author
Gintarė Mažonaitė
Tech Writer and VPN Researcher

Gintarė is a cybersecurity writer at Mysterium VPN, where she explores online privacy, VPN technology, and the latest digital threats in editorial pieces. With hands-on experience researching and writing about data protection and digital freedom, Gintarė makes complex security topics accessible and actionable.

Read our editorial policy here.

Read more by this author
© Copyright 2026 UAB "MN Intelligence"