Massive Global Data Leak Exposes Over One Billion Records
A massive unsecured database belonging to identity verification provider IDMerit has exposed more than three billion records, with an estimated one billion containing sensitive personal information.
The database was discovered by cybersecurity researchers at Cybernews, who identified an open MongoDB instance exceeding one terabyte in size. The researchers reported the exposure and worked to have the database secured.
What Was Exposed?
The unsecured database reportedly contained extensive personal data, including:
- Full names
- Addresses and postal codes
- Dates of birth
- National identification numbers
- Phone numbers
- Email addresses
- Gender
- Telco metadata
- Social profile annotations
- Breach status indicators
While more than three billion records were stored in the database, researchers clarified that this does not mean three billion individuals were affected. Multiple entries were linked to the same individuals.
Cybernews estimates that roughly one billion records contained sensitive personal data, while the remainder consisted largely of system logs and related metadata.
Global Impact Across 26 Countries
The exposure was international in scope, affecting individuals across 26 countries.
The highest concentrations of exposed records reportedly included:
- United States: 203+ million records
- Mexico: 124 million
- Philippines: 72 million
- Germany: 61 million
- Italy & France: Approximately 53 million each
The scale and geographic spread significantly increase the potential for downstream abuse.
Who Is IDMerit?
IDMerit is a California-based digital identity verification and fraud prevention company founded in 2014.
The firm provides API-driven solutions for:
- KYC (Know Your Customer)
- AML (Anti-Money Laundering)
- Digital identity verification
Despite its relatively small size — reportedly 25–50 employees and approximately $2.9 million in annual revenue — IDMerit serves a global customer base.
Why This Breach Is Concerning
According to researchers, exposures of this scale create serious secondary risks, including:
- Account takeovers
- Targeted phishing campaigns
- Credit fraud
- SIM swap attacks
- Long-term identity and privacy harm
The incident also highlights a broader industry issue:
Identity verification vendors are becoming critical infrastructure.
When third-party identity platforms suffer security failures, they can become centralized points of catastrophic exposure for multiple organizations at once.
The Bigger Picture
As more businesses rely on external vendors for identity verification and fraud prevention, third-party data security becomes a shared responsibility.
Incidents like this underscore:
- The risk of unsecured cloud databases
- The importance of vendor risk assessments
- The potential impact of concentrated identity datasets
- The long-term consequences of exposed personal information
At this time, no official statement detailing user notification processes or regulatory consequences has been widely reported.



