Desk live·
ForensicPost
Cloud/Exposure/File 26-0219

Three Billion Identity Records, and No Attacker Required

An unsecured database attributed to the identity-verification firm IDMerit reportedly exposed around three billion records, including a billion KYC entries. Nobody broke in, which is the part worth dwelling on.

Constructed geometry · not a chart of case data
TargetIDMerit
ActorExposure
S. Rosler9 min readConfidence: medium1 source reviewed

Reporting describes an unsecured MongoDB deployment associated with the identity-verification provider IDMerit exposing on the order of three billion records — including around a billion know-your-customer entries and more than 200 million US records — during a window in November 2025.

There is no intrusion in this file. There is no actor, no vector worth naming and no dwell time. A database was reachable, and then it was not.

Exposure Is Not A Lesser Category

Incidents like this are consistently treated as embarrassments rather than breaches, because the narrative lacks an antagonist. That instinct is wrong on the only measure that matters to an affected person: whether their data was available to people who should not have had it.

It also produces a genuine evidential problem. Where an intrusion leaves traces that can bound what was taken, an open database usually offers only access logs that were never designed for the question — so the honest answer to "was it accessed" is frequently that nobody can say.

KYC Is The Wrong Data To Consolidate

Know-your-customer records exist because regulators require firms to establish identity, which means they are the highest-assurance identity data in commercial hands: documents, images and verification outcomes, collected under obligation.

Regulation drove the collection and drove the consolidation into specialist providers, on entirely reasonable efficiency grounds. The aggregate is a target of a kind the rules never contemplated, and the people described in it were never parties to the arrangement.

How we reported this

Compiled from public reporting, listed below. Record counts are as reported by the researchers who identified the exposure. Whether the data was accessed by anyone else is not established. Corrections: corrections@forensicpost.com.

Sources
  1. List of recent data breaches in 2026Bright Defense
S. Rosler
Covers extortion groups and leak-site economics. Verifies our sample sets.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary