Massive Global Data Leak Exposes Over One Billion Records

A massive unsecured database belonging to identity verification provider IDMerit has exposed more than three billion records, with an estimated one billion containing sensitive personal information.

The database was discovered by cybersecurity researchers at Cybernews, who identified an open MongoDB instance exceeding one terabyte in size. The researchers reported the exposure and worked to have the database secured.

What Was Exposed?

The unsecured database reportedly contained extensive personal data, including:

  • Full names
  • Addresses and postal codes
  • Dates of birth
  • National identification numbers
  • Phone numbers
  • Email addresses
  • Gender
  • Telco metadata
  • Social profile annotations
  • Breach status indicators

While more than three billion records were stored in the database, researchers clarified that this does not mean three billion individuals were affected. Multiple entries were linked to the same individuals.

Cybernews estimates that roughly one billion records contained sensitive personal data, while the remainder consisted largely of system logs and related metadata.

Global Impact Across 26 Countries

The exposure was international in scope, affecting individuals across 26 countries.

The highest concentrations of exposed records reportedly included:

  • United States: 203+ million records
  • Mexico: 124 million
  • Philippines: 72 million
  • Germany: 61 million
  • Italy & France: Approximately 53 million each

The scale and geographic spread significantly increase the potential for downstream abuse.

Who Is IDMerit?

IDMerit is a California-based digital identity verification and fraud prevention company founded in 2014.

The firm provides API-driven solutions for:

  • KYC (Know Your Customer)
  • AML (Anti-Money Laundering)
  • Digital identity verification

Despite its relatively small size — reportedly 25–50 employees and approximately $2.9 million in annual revenue — IDMerit serves a global customer base.

Why This Breach Is Concerning

According to researchers, exposures of this scale create serious secondary risks, including:

  • Account takeovers
  • Targeted phishing campaigns
  • Credit fraud
  • SIM swap attacks
  • Long-term identity and privacy harm

The incident also highlights a broader industry issue:

Identity verification vendors are becoming critical infrastructure.

When third-party identity platforms suffer security failures, they can become centralized points of catastrophic exposure for multiple organizations at once.

The Bigger Picture

As more businesses rely on external vendors for identity verification and fraud prevention, third-party data security becomes a shared responsibility.

Incidents like this underscore:

  • The risk of unsecured cloud databases
  • The importance of vendor risk assessments
  • The potential impact of concentrated identity datasets
  • The long-term consequences of exposed personal information

At this time, no official statement detailing user notification processes or regulatory consequences has been widely reported.

about happier IT

We’re a Canadian-owned Managed IT Services provider supporting growing businesses across Alberta, British Columbia, and Ontario. From day-to-day tech support to long-term strategy, we help organizations stay productive, protected, and future-ready.

GET YOUR
FREE CONSULTATION
Start optimizing your IT infrastructure today!