- Blog >
- Data and Research >
- An ID Check Breach Timeline: 2011–2026
An ID Check Breach Timeline: 2011–2026
Key Takeaways
- We documented 88 incidents since 2011 in which data collected specifically to verify identity or age was breached, exposed, or put up for sale — affecting at least 2.15 billion records on a confirmed or researcher-verified basis, with attacker- and seller-claimed figures adding a further 4.54 billion.
- 42% of all incidents (37 of 88) date from January 2024 to August 2026, the period in which mandatory identity verification spread fastest. The rate is accelerating alongside the mandates.
- In 41 of the 88 incidents, what leaked included the actual documents: ID scans, verification selfies, fingerprints, biometric templates. Unlike a password, none of that can be changed.
- Every major identity-verification vendor from the current era — AU10TIX, IDMerit, Sumsub, Persona, inVOID — has appeared in this timeline. The companies the internet now relies on to hold everyone's identity documents safely haven't demonstrated they can do it.
Every year, more of the internet demands that you prove who you are before you may use it: KYC checks to open an account, a driver’s license to join a dating app, a passport scan to check into a hotel, a face scan to read an adult site in the UK, a government ID to appeal a Discord ban.
Every one of those checks creates a copy of the most permanent data you have. This timeline compiles what happened to those copies.
We found 88 publicly documented incidents since 2011 in which data collected specifically to verify identity or age – government ID scans, verification selfies, biometric templates, KYC files, national ID registries – was breached, exposed, or put up for sale.
On figures with a confirmed or researcher-verified basis, at least 2.15 billion identity-verification records have been affected; attacker- and seller-claimed figures add a further 4.54 billion on top. In 41 of the 88 incidents, the leaked material included the documents themselves: the scans, the selfies, the fingerprints – data that, unlike a password, can never be rotated.
The timeline is accelerating exactly as verification mandates spread: 37 of the 88 incidents (42%) date from January 2024 through August 2026, the era of the UK Online Safety Act, US state age-verification laws, and mandatory KYC nearly everywhere.
The incidents of this era make the argument by themselves: the Tea app’s verification selfies scraped onto 4chan; 70,000 government IDs from Discord users’ age appeals leaked through a support vendor; the identity-verification vendors themselves (AU10TIX, IDMerit, Sumsub, Persona, inVOID) turning up with exposed credentials, open databases, or breached support systems. Nobody had compiled this record in one place. Now it is one dataset, one row per incident, with sources.
The Numbers
| Measure | Value |
| Documented incidents, 2011 – Aug 2026 | 88 (2 further candidates rejected in fact-checking) |
| Incidents in 2024 – Aug 2026 | 37 (42% of all) – 2025 alone: 15; 2026 to date: 10 |
| Records affected – confirmed/researcher-verified basis | 2.15 billion |
| Records affected – attacker/seller-claimed basis (on top) | 4.54 billion |
| Incidents where ID documents/selfies/biometrics/KYC files leaked | 41 of 88 |
| Age-verification-specific incidents | 12 – from Omiai’s 1.7M documents (2021) to Discord, Persona and beyond (2025–26) |
| Confirmed breaches/exposures/vendor incidents | 58 / 24 / 6 |
| Government or national-ID-system incidents | 20+ (OPM to France ANTS) |
2011–2016: The Warning Shots
The pattern was set before anyone said “KYC” in public: South Korea’s Nate/Cyworld breach put 35 million resident registration numbers in criminal hands (2011); the US Office of Personnel Management lost 21.5 million background-investigation dossiers and 5.6 million fingerprint sets (2015); Turkey’s civil-registry extract of ~49 million circulated freely (dumped 2016); the Philippines’ COMELEC voter database, with passport numbers, was published outright (2016).
Each was treated as an anomaly. Collectively they demonstrated the base fact that identity registries concentrate exactly on the data that can't be reissued.
2017–2021: KYC Goes Mainstream, and Leaks With It
As exchanges and fintechs institutionalized identity checks, the checks themselves became the loot: Binance extortion dumps of KYC selfies (2019), BioStar 2’s 27.8 million biometric access records sitting in an open Elasticsearch (2019), India’s BuyUcoin, Upstox and MobiKwik KYC troves (2021), Argentina’s RENAPER national registry offered for sale (2021, government disputes scale).
The Ecuador (Novaestrat) and Brazil mega-aggregations showed the broker side of the same machine.
2022–2024: Governments Lose the Master Files
Optus and Latitude turned Australian ID-check mandates into millions of exposed licence and passport numbers and forced national reform. Thailand, Indonesia, Bangladesh, the Philippines police, Paraguay and El Salvador each lost citizen-scale registries – El Salvador’s dump included 5.1 million facial photos. India’s ICMR/Aadhaar-linked listing claimed 815 million.
The US saw its background-check industry breached at scale (National Public Data, 272 million verified records).
By the end of 2024, the question was no longer whether national identity stores leak, but which one is next.
2025–2026: The Age Verification Era
Then the laws arrived that made showing ID a condition of ordinary internet use – and the incidents followed within months. The Tea app’s women-only verification selfies were scraped from an open bucket and sorted into sleazy rating threads on 4chan (July 2025).
Discord users who appealed age decisions had ~70,000 government IDs leak through a third-party support vendor (October 2025) – while Discord rolled age checks out globally anyway.
Japan’s Omiai had already shown the shape of it in 2021: 1.7 million age-verification document images. And the verification industry itself joined the timeline: AU10TIX (verifier for TikTok, Uber, X) left admin credentials exposed for over a year; IDMerit was reported with ~1 billion identity records reachable in an open database (disputed by the company, flagged as claimed); Sumsub disclosed an 18-month-undetected support-system intrusion; Persona, Discord and Roblox’s age-verification vendor, exposed its own frontend configuration; France’s ANTS (the agency that issues French IDs) was breached with 11.7 million people confirmed affected.
The pattern of this era is specific: the wall you are forced to hand your ID to is exactly as breachable as everything else on the internet.
The Timeline
| Date | Incident | What leaked | People | Class | AV |
| 2011-07 | SK Communications (Nate/Cyworld) breach – national IDs | ID numbers | 35 M | breach | ✔️ |
| 2011-11 | Nexon Korea (MapleStory) breach – real-name-era national IDs | ID numbers | 13 M | breach | ✔️ |
| 2015-06 | OPM background-investigation breach | SSNs, biometrics, KYC files | 22 M | breach | |
| 2016-04 | Turkey MERNIS national-ID database leak | ID numbers | 50 M | breach | |
| 2016-04 | Philippines COMELEC 'Comeleak' voter breach | biometrics, passports, ID numbers | 55 M | breach | |
| 2016-04 | Qatar National Bank data dump | ID numbers, passports | 100 K | breach | |
| 2016-06 | World-Check risk database leak (2016) | ID numbers | 2.2 M | exposure | |
| 2017-10 | Malaysia telco 46.2M subscriber leak (MyKad) | ID numbers | 46 M | breach | |
| 2018-01 | Aadhaar / UIDAI 'Rs 500' database access (Tribune) | ID numbers | 1.2 B * | exposure | |
| 2018-04 | TrueMove H ID-card scan exposure | ID scans, ID numbers, DL | 46 K | exposure | |
| 2018-11 | Marriott / Starwood passport exposure | passports | 5.3 M | breach | |
| 2019-02 | SenseNets facial-recognition database exposure | biometrics, ID numbers | 2.6 M | exposure | |
| 2019-05 | First American Financial document exposure | ID scans, DL, SSNs | 885 M | exposure | |
| 2019-06 | Perceptics / CBP traveler-image breach | biometrics, selfies | 184 K | breach | |
| 2019-06 | Desjardins insider data breach | ID numbers, SSNs | 9.7 M | breach | |
| 2019-07 | Bulgaria National Revenue Agency hack | ID numbers | 5.0 M | breach | |
| 2019-08 | Binance KYC photo leak/extortion | KYC files, ID scans, selfies | 10 K * | breach | |
| 2019-08 | BioStar 2 / Suprema biometric exposure | biometrics | 27.8 M | exposure | |
| 2019-09 | Ecuador Novaestrat data leak | ID numbers | 21 M | exposure | |
| 2020-01 | PussyCash / ImLive cam-network model verification files exposure | ID scans, KYC files, SSNs, selfies | 875 K | exposure | ✔️ |
| 2020-01 | SextPanther model identity-document exposure | ID scans, DL, SSNs, KYC files | 11 K | exposure | ✔️ |
| 2020-02 | Digitex Futures KYC leak | KYC files, passports, DL | 8 K * | breach | |
| 2020-03 | Antheus Tecnologia fingerprint exposure | biometrics | 76 K | exposure | |
| 2020-11 | Liquid exchange breach (KYC documents potentially accessed) | none confirmed (at risk: KYC files, ID scans, selfies) | n/a | vendor | |
| 2021-01 | BuyUcoin crypto-exchange KYC leak | KYC files, ID numbers | 325 K | breach | |
| 2021-01 | Brazil 223M CPF 'megavazamento' | ID numbers, biometrics | 223 M | breach | |
| 2021-02 | CityBee user database leak (national ID codes) | ID numbers | 110 K | breach | |
| 2021-03 | MobiKwik alleged KYC breach | KYC files, ID scans, ID numbers | 3.5 M * | breach | |
| 2021-04 | Upstox KYC document breach | KYC files, ID scans, ID numbers | 111 K | breach | |
| 2021-05 | Omiai age-verification document breach | ID scans, DL | 1.7 M | breach | ✔️ |
| 2021-07 | Estonia ID-photo theft from state database | ID scans | 286 K | breach | |
| 2021-08 | T-Mobile 2021 breach (SSN/ID numbers) | SSNs, DL, ID numbers | 77 M | breach | |
| 2021-09 | OnlyFans ex-employee retained access to creator KYC data | none confirmed (at risk: KYC files, ID scans, selfies) | n/a | vendor | ✔️ |
| 2021-09 | Thailand 106M international-visitor database exposure | passports, ID numbers | 106 M | exposure | |
| 2021-10 | Argentina RENAPER national registry breach | ID numbers, ID scans, selfies | 45 M * | breach | |
| 2022-07 | Shanghai National Police database leak | ID numbers | 1 B * | breach | |
| 2022-09 | Optus data breach | passports, DL, ID numbers | 9.5 M | breach | |
| 2022-10 | Medibank ransomware breach | passports, ID numbers | 9.7 M | breach | |
| 2022-12 | BetMGM patron database breach | ssn (hashed), ID numbers | 1.6 M * | breach | ✔️ |
| 2023-03 | Thailand 9near '55 million Thais' claim | ID numbers | 55 M * | breach | |
| 2023-03 | Latitude Financial data breach | DL, passports, ID scans | 14 M | breach | |
| 2023-04 | RentoMojo KYC breach | KYC files, ID scans, ID numbers | 2.2 M | breach | |
| 2023-04 | Philippines PNP / NBI applicant records leak | ID scans, biometrics, ID numbers | 1.3 M | exposure | |
| 2023-05 | Worldcoin Orb operator credential theft | none confirmed (at risk: biometrics) | n/a | vendor | |
| 2023-06 | CoWIN vaccine portal data on Telegram | ID numbers, passports | n/a | breach | |
| 2023-06 | MOVEit DMV cluster (Louisiana OMV / Oregon DMV) | DL, ID numbers, SSNs | 9.8 M | breach | |
| 2023-07 | Indonesia Immigration 34M passport leak (Bjorka) | passports, ID numbers | 35 M * | breach | |
| 2023-07 | Bangladesh government website citizen-registry leak | ID numbers | 50 M | exposure | |
| 2023-10 | ICMR / '815 million Indians' Aadhaar-passport listing | ID numbers, passports | 815 M * | breach | |
| 2023-11 | Strendus casino KYC/ID-number exposure | ID numbers | n/a | exposure | ✔️ |
| 2023-11 | Indonesia KPU voter-roll breach (204M) | ID numbers | 204 M * | breach | |
| 2024-03 | Pakistan NADRA digital-ID data theft | ID numbers, biometrics | 2.7 M | breach | |
| 2024-04 | El Salvador citizen headshots + ID dump | selfies, ID numbers, biometrics | 5.1 M | breach | |
| 2024-04 | World-Check theft claim (GhostR, 2024) | ID numbers, passports | 5.3 M * | breach | |
| 2024-05 | Outabox / ClubsNSW biometric and licence-scan breach | biometrics, DL, ID numbers | 1.1 M | breach | ✔️ |
| 2024-06 | AU10TIX exposed admin credentials (ID verification for TikTo… | ID scans, DL, selfies | n/a | exposure | |
| 2024-06 | Nigeria NIN/BVN resale via AnyVerify and others | ID numbers | n/a | exposure | |
| 2024-07 | Fractal ID KYC breach (web3 identity provider) | ID scans, selfies, KYC files | 5 K | breach | |
| 2024-08 | National Public Data (Jerico Pictures) breach | SSNs, ID numbers | 272 M | breach | |
| 2024-09 | MC2 Data background-check exposure | SSNs | 106 M | exposure | |
| 2024-10 | Transak KYC data breach | KYC files, ID scans, selfies | 93 K | breach | |
| 2024-12 | Signzy security incident (ID-verification vendor) | None confirmed (at risk: KYC files) | n/a | vendor | |
| 2024-12 | Byte Federal (Bitcoin ATM) breach | ID scans, SSNs, ID numbers | 58 K | breach | |
| 2025-02 | DISA Global Solutions breach | SSNs, DL, ID numbers | 3.3 M | breach | |
| 2025-03 | M.A.D Mobile dating apps image leak (incl. verification phot… | selfies | 1.5 M * | exposure | |
| 2025-04 | Morocco CNSS social-security breach | ID numbers | 2.0 M * | breach | |
| 2025-05 | Coinbase insider-bribery KYC breach | ID scans, KYC files, SSNs, ID numbers | 69 K | breach | |
| 2025-05 | LexisNexis Risk Solutions breach (GitHub-linked) | SSNs, DL, ID numbers | 364 K | breach | |
| 2025-06 | Paraguay 7.4M citizen records leak | ID numbers | 7.4 M * | breach | |
| 2025-07 | Bitcoin Depot customer breach (driver's licence numbers) | DL, ID numbers | 27 K | breach | |
| 2025-07 | Tea app verification selfies and ID breach | selfies, ID scans, DL | 72 K | breach | |
| 2025-08 | TeaOnHer driver's license/selfie exposure | DL, selfies | n/a | exposure | |
| 2025-08 | Italian hotels guest ID-scan theft | ID scans, passports | 91 K | breach | |
| 2025-08 | Miljodata ransomware (Swedish personal IDs) | ID numbers | 1.5 M | breach | |
| 2025-09 | Prosper Marketplace breach | SSNs, ID numbers | 18 M * | breach | |
| 2025-09 | Vietnam National Credit Information Center (CIC) breach | ID numbers, ID scans | 160 M * | breach | |
| 2025-10 | Discord third-party support breach (age-appeal government IDs) | ID scans, selfies | 70 K | breach | ✔️ |
| 2025-11 | Checkout.com legacy-storage KYC breach | KYC files, ID scans | n/a | breach | |
| 2026-02 | Sumsub support-environment breach (18 months undetected) | n/a | n/a | vendor | |
| 2026-02 | IDMerit open database (~1B identity records) | ID numbers | 1 B * | exposure | |
| 2026-02 | Persona age-verification frontend/code exposure | n/a | n/a | vendor | ✔️ |
| 2026-02 | Odido (Dutch telco) extortion breach | passports, DL, ID numbers | 6.1 M | breach | |
| 2026-03 | Addi (Colombian fintech) extortion breach | ID numbers | 35 M | breach | |
| 2026-04 | France ANTS national ID agency breach | n/a | 12 M | breach | |
| 2026-05 | Tabiq / Reqrea hotel check-in ID exposure | passports, DL, selfies, ID scans | 1.0 M | exposure | |
| 2026-05 | UK Visa Portal passport/selfie exposure | passports, selfies, ID scans | 100 K | exposure | |
| 2026-06 | inVOID (Bureau) India KYC database key exposure | KYC files, ID numbers, biometric data | 16 M | exposure | |
| 2026-06 | Cannabis Club Systems (Spain) photo-ID exposure | passports, DL, ID scans | 985 K | exposure | ✔️ |
- * = record figure is attacker- or seller-claimed.
- AV = age-verification-related.
- “vendor” = capability exposure with no confirmed personal-data leak.
What This Record Shows
The timeline makes something visible that individual breach reports obscure: this isn't a series of unrelated failures. It's one failure mode, repeated across 88 incidents, fifteen years, and every type of organization that has ever decided to collect this category of data.
What varies is the victim. Sometimes, it's a startup with inadequate security. Sometimes, it's a national government that built a country-scale identity registry and watched it walk out the door. Sometimes, it's a verification vendor that became the single point of failure for a dozen companies that outsourced their compliance obligations to them.
The mechanism stays constant: concentrated, irreplaceable, maximum-sensitivity data in a place that eventually gets breached.
The policy context matters here. The incidents in this timeline aren't a bug in the age-verification system. They're the predictable output. Every law that makes identity checks mandatory, every platform that adds an ID gate, and every verification vendor that builds a centralized database creates a new target.
Be part of the resistance, quietly.
Get Mysterium VPN

Gintarė is a cybersecurity writer at Mysterium VPN, where she explores online privacy, VPN technology, and the latest digital threats in editorial pieces. With hands-on experience researching and writing about data protection and digital freedom, Gintarė makes complex security topics accessible and actionable.
