Reporting describes an unsecured MongoDB deployment associated with the identity-verification provider IDMerit exposing on the order of three billion records — including around a billion know-your-customer entries and more than 200 million US records — during a window in November 2025.
There is no intrusion in this file. There is no actor, no vector worth naming and no dwell time. A database was reachable, and then it was not.
Exposure Is Not A Lesser Category
Incidents like this are consistently treated as embarrassments rather than breaches, because the narrative lacks an antagonist. That instinct is wrong on the only measure that matters to an affected person: whether their data was available to people who should not have had it.
It also produces a genuine evidential problem. Where an intrusion leaves traces that can bound what was taken, an open database usually offers only access logs that were never designed for the question — so the honest answer to "was it accessed" is frequently that nobody can say.
KYC Is The Wrong Data To Consolidate
Know-your-customer records exist because regulators require firms to establish identity, which means they are the highest-assurance identity data in commercial hands: documents, images and verification outcomes, collected under obligation.
Regulation drove the collection and drove the consolidation into specialist providers, on entirely reasonable efficiency grounds. The aggregate is a target of a kind the rules never contemplated, and the people described in it were never parties to the arrangement.
Compiled from public reporting, listed below. Record counts are as reported by the researchers who identified the exposure. Whether the data was accessed by anyone else is not established. Corrections: corrections@forensicpost.com.
- List of recent data breaches in 2026Bright Defense