Listen to this Post

A New Privacy Crisis Is Taking Shape
For years, people were told that identity verification would make the internet safer. Upload your passport. Take a selfie. Scan your ID. Prove your age. Confirm that you are really you.
The promise sounds reasonable.
The problem is what happens when the systems collecting that proof are compromised.
A new report from Mysterium VPN documents 88 incidents since 2011 involving data collected specifically for identity or age verification. According to the report, confirmed and researcher-verified incidents account for approximately 2.15 billion records, while another 4.54 billion records are attributed to claims made by attackers or data sellers.
Those numbers are enormous, but the raw number of records is not the most disturbing part.
The real danger is that some of the stolen information cannot simply be replaced.
Passwords Can Be Changed. Faces Cannot.
A compromised password can be reset.
A stolen API key can be revoked.
A leaked credit card can be replaced.
Your passport can eventually be reissued.
But what happens when criminals obtain a high-resolution scan of your face, your fingerprint information, your government identification document, or the biometric template created from your identity?
You cannot reset your face.
You cannot rotate your fingerprints.
You cannot permanently erase the fact that a government document containing your name, date of birth, photograph, address, and identification number existed in somebody else’s database.
That is what makes identity-verification breaches fundamentally different from many conventional data breaches.
41 Incidents Included the Actual Identity Evidence
According to the report, 41 of the 88 documented incidents involved the actual documents or biometric material used during verification.
That reportedly included ID scans, verification selfies, fingerprints, and biometric templates.
This distinction matters enormously.
A database containing an email address is problematic.
A database containing an email address, passport scan, selfie, government ID number, biometric information, and verification history is an entirely different category of risk.
The second database can potentially become a permanent identity dossier.
The Verification Boom Is Making the Problem Worse
The timing of the incidents is particularly concerning.
The report says that 37 of the 88 incidents, or roughly 42%, occurred between January 2024 and August 2026.
That period coincides with a rapid expansion of mandatory identity and age-verification requirements across online services.
Platforms increasingly want to know whether users are adults.
Financial companies need to verify customers.
Social networks are experimenting with age assurance.
Online marketplaces need stronger identity controls.
Governments are introducing new digital identity systems.
The result is a growing ecosystem where more organizations need to collect extremely sensitive information.
And every additional database becomes another potential target.
The Internet Is Building an Identity Data Supply Chain
The biggest mistake is thinking about identity verification as a single company problem.
It is actually a supply chain.
A user submits an ID to a platform.
The platform sends the information to a verification company.
The verification company processes the document.
A separate cloud provider may store the information.
A customer-support provider may gain access to the case.
Analytics tools may be embedded into the verification interface.
Employees may have administrative access.
Logs may contain sensitive metadata.
Backups may exist for months or years.
Each component creates another possible failure point.
The Third-Party Problem
Outsourcing identity verification can make sense operationally.
Building an advanced document-recognition and biometric verification system internally is expensive, complicated, and difficult to maintain.
So companies often turn to specialized providers.
But outsourcing does not eliminate the security problem.
It can concentrate it.
If one verification company serves dozens or hundreds of major platforms, compromising that provider could potentially expose information belonging to users of many different services simultaneously.
The third-party provider effectively becomes a single point of failure for identity.
AU10TIX Shows Why Reputation Is Not Enough
The report highlights AU10TIX, an identity-verification company reportedly used by major platforms including TikTok, Uber, and X.
According to the report, administrative credentials were exposed for more than a year.
The significance is bigger than one credential-management mistake.
When a provider handles identity information for major internet platforms, an administrative credential is not merely an internal IT secret.
It can potentially become a gateway into a much larger identity ecosystem.
That is why security assessments must examine not only whether a vendor is reputable, but also how its privileged accounts, secrets, storage systems, monitoring, and internal access controls actually work.
Sumsub and the Hidden Duration of Intrusions
The report also points to Sumsub, which disclosed an intrusion involving a support system that reportedly went undetected for 18 months.
Long dwell times are particularly dangerous in identity environments.
A short-lived intrusion may expose a limited amount of information.
An attacker who remains inside a system for months has opportunities to understand architecture, identify privileged accounts, locate databases, discover backups, monitor employees, and gradually extract valuable information.
Detection time therefore becomes part of the privacy equation.
Persona Adds Another Warning
Persona, another company involved in identity and age verification, is also mentioned in the report.
The issue highlighted was exposure of frontend configuration.
Configuration information does not automatically mean that an attacker has obtained a complete identity database.
However, exposed configuration can reveal valuable information about how an application works, what services it communicates with, and where security boundaries exist.
For attackers, seemingly harmless technical details can become pieces of a larger attack chain.
The Tea App Incident Shows the Human Cost
One of the more disturbing examples concerns Tea, a women-focused safety platform.
According to the report, verification selfies were exposed through an improperly secured storage bucket, and images later appeared on 4chan.
This illustrates an uncomfortable reality.
Security failures do not remain confined to databases.
Once identity material is stolen, it can be copied, redistributed, indexed, reposted, and weaponized.
The organization may eventually close the storage bucket.
But it cannot retrieve every copy of the leaked material from the internet.
Discord Users Also Faced Exposure
The report also references an incident involving Discord users who challenged age-verification decisions.
Around 70,000 government IDs were reportedly exposed through a third-party support provider.
This example is especially important because identity verification does not stop when the automated check finishes.
Users may open support tickets.
They may dispute an age determination.
They may upload additional documents.
They may communicate with customer-service personnel.
Suddenly, another system becomes part of the identity-verification architecture.
The attack surface expands again.
Government Databases Are Not Immune
It would be easy to conclude that private companies are the problem.
The evidence does not support such a simple conclusion.
Governments have experienced their own large-scale identity-data incidents.
The report cites
France’s ANTS, the agency responsible for issuing French identity documents, reportedly confirmed that 11.7 million people were affected by a 2026 breach.
Other examples mentioned include identity-related databases in India, Thailand, the Philippines, and Brazil.
The pattern crosses borders and organizational categories.
Centralization Creates Extraordinary Risk
Centralized identity databases have an obvious advantage.
They can make verification easier.
They can reduce duplication.
They can simplify government services.
They can improve fraud detection.
But centralization creates another property that cybersecurity professionals understand very well:
concentration of risk.
The more valuable the database becomes, the more attractive it becomes to attackers.
A database containing millions of ordinary records might already be valuable.
A database containing millions of verified identities can be extraordinarily valuable.
Every New Verification Law Changes the Threat Model
There is a broader policy issue hiding underneath this discussion.
When governments require platforms to verify
They are indirectly creating demand for identity databases.
A platform that previously needed an email address may suddenly need a government ID.
A service that previously relied on self-declared age may suddenly require biometric age estimation.
A company that never stored identity documents may now need to retain them for compliance or dispute resolution.
Every such requirement changes the
The Question Should Not Be “Can We Verify?”
The more important question is:
How little information do we need to verify?
There is a major difference between proving that somebody is over a certain age and storing a complete passport scan.
There is a difference between confirming identity and retaining the underlying document indefinitely.
There is a difference between calculating an age threshold locally and sending biometric information to a remote third party.
Good privacy architecture should therefore minimize the information that crosses the security boundary.
Age Verification Does Not Always Require Full Identity
Imagine a website simply needs to determine whether someone is over 18.
Does the website really need the
Does it need their home address?
Does it need a permanent copy of their passport?
Does it need to retain a selfie indefinitely?
In many situations, the answer should be no.
A better architecture may involve a trusted verifier returning a simple assertion such as:
Age requirement satisfied.
The website receives the result, not the entire identity document.
That concept is often described through privacy-preserving identity or selective disclosure.
Data Minimization Is Becoming a Security Strategy
Data minimization is sometimes presented as a privacy principle.
It is also a cybersecurity principle.
Every piece of information you do not collect is one less piece of information attackers can steal.
Every database column you do not store reduces potential exposure.
Every document you delete after verification reduces long-term risk.
Every unnecessary integration you remove reduces attack surface.
Privacy and security therefore converge around the same architectural question:
Why are we storing this information at all?
Deep Analysis
Start by Mapping the Identity Data Flow
Organizations should begin with a complete identity-data map.
grep -RniE "passport|government.?id|biometric|selfie|identity|age.?verification" \n/var/log /etc 2>/dev/null
This is not a complete discovery mechanism, but it illustrates the type of audit teams should perform.
The objective is to identify where identity-related information appears across systems, logs, applications, and configurations.
Search for Exposed Credentials
Privileged credentials are particularly dangerous in identity environments.
grep -RniE "AKIA[0-9A-Z]{16}|BEGIN .PRIVATE KEY|password=|api[_-]?key" \n/opt /srv /etc 2>/dev/null
Secrets should never be committed to source code or left inside frontend configuration.
Organizations should use dedicated secret-management systems and rotate credentials automatically.
Inspect Cloud Storage Permissions
Misconfigured object storage has repeatedly caused serious data exposures.
For AWS environments, security teams can begin with:
aws s3api list-buckets
Then review bucket policies and access controls:
aws s3api get-public-access-block \n--bucket YOUR_BUCKET_NAME
The objective is simple:
Identity documents should never accidentally become internet-readable objects.
Look for Publicly Accessible Objects
A basic security review should identify whether sensitive storage endpoints can be accessed anonymously.
curl -I https://example.com/identity/test-document.jpg
A production environment should never expose verification documents simply because someone knows or guesses the URL.
Search Application Logs
Identity information sometimes leaks through debugging.
grep -RniE "passport|national.?id|ssn|dob|biometric|selfie" \n/var/log 2>/dev/null
Applications should avoid logging sensitive documents, authentication tokens, full identification numbers, or biometric material.
Monitor Administrative Access
Identity providers should maintain detailed audit trails.
journalctl --since "24 hours ago" | \ngrep -Ei "sudo|admin|authentication|login|credential"
Security teams should investigate unusual administrative access, especially from unexpected locations, devices, or time periods.
Rotate Compromised Credentials Immediately
If a privileged identity-system credential is suspected of exposure, do not simply remove it from a repository.
Rotate it.
git log --all --oneline --decorate
Then revoke the compromised secret through the relevant identity or cloud platform.
Deleting the visible credential does not remove it from historical commits.
Test the Verification Boundary
Security teams should ask a difficult question:
What happens if the verification provider is compromised?
The application should still minimize the information that can be extracted.
A well-designed system should not blindly trust every response, endpoint, webhook, or frontend configuration supplied by a third party.
Treat Vendors as Extensions of Your Security Boundary
Vendor security should be continuously evaluated.
Organizations should examine:
Data retention periods
Encryption practices
Administrative access
Incident detection capabilities
Credential management
Employee access
Subprocessors
Backup retention
Deletion procedures
Breach notification requirements
Geographic data storage
API authentication
Logging and monitoring
Security testing
Privileged-access management
A vendor contract is not a security control.
Test What Happens After Deletion
One of the most overlooked questions is whether deleted identity information is actually deleted.
Organizations should know where copies exist.
Primary databases.
Backups.
Caches.
Logs.
Support tickets.
Analytics systems.
Data warehouses.
Disaster-recovery systems.
Third-party processors.
Deletion must be considered across the entire lifecycle.
Build for Breach Containment
No security architecture should assume that compromise will never happen.
Instead, identity systems should be designed around containment.
If one application is compromised, it should not automatically provide access to every identity database.
If one employee account is hijacked, it should not become a master key.
If one vendor is breached, the attacker should not automatically inherit access to unrelated systems.
Segmentation matters.
Biometrics Need Special Treatment
Biometric information deserves a separate security strategy.
Organizations should avoid storing raw biometric material whenever possible.
Where technically feasible, systems should use protected representations, hardware-backed mechanisms, strong encryption, strict access controls, and carefully designed retention policies.
The objective is not simply to encrypt biometric data.
It is to reduce the number of systems that ever possess it.
The Real Security Metric Is Not Records Collected
Organizations often celebrate the number of users they can verify.
That is the wrong metric from a security perspective.
A more useful measurement is:
How much sensitive information did we need to collect to achieve the verification objective?
Less data means less exposure.
Less retention means less long-term liability.
Less centralization means less catastrophic failure potential.
What Undercode Say:
Identity Verification Is Becoming an Attack Surface
The internet is entering an unusual phase where proving who you are can be almost as dangerous as hiding who you are.
The Verification Paradox
The paradox is simple.
We are collecting more information to make online services safer.
But collecting more information creates more valuable targets.
Permanent Data Creates Permanent Risk
Passwords are temporary secrets.
Biometrics are persistent identifiers.
That difference should fundamentally change how organizations protect them.
Third Parties Are Becoming Identity Gatekeepers
A company can outsource verification.
It cannot outsource responsibility.
If a vendor loses customer identities, the original platform still faces the consequences.
Reputation Is Not a Security Architecture
A famous vendor can suffer a breach.
A government can suffer a breach.
A startup can suffer a breach.
The important question is not who operates the system.
The important question is what happens when that system fails.
The Attackers Only Need One Weak Link
Identity ecosystems are complicated.
Attackers do not need to defeat every component.
They need to find one weak point.
An exposed credential.
A public storage bucket.
A vulnerable support system.
A compromised employee.
An overly permissive API.
An insecure integration.
One mistake can unlock an enormous amount of information.
Centralization Magnifies Consequences
A small local breach can become a national-scale privacy event when identity information is centralized.
The more successful a centralized system becomes, the more attractive it becomes to attackers.
That is an uncomfortable mathematical relationship.
Age Verification Needs a Privacy Reset
The industry should seriously question whether age verification requires identity collection at all.
If a platform only needs an age threshold, collecting a complete government identity document may represent unnecessary risk.
Selective Disclosure Could Change the Equation
Modern cryptographic approaches can allow users to prove certain attributes without revealing everything about themselves.
That could dramatically reduce the information stored by platforms.
The Best Data Breach Is the Data You Never Had
This is an old security principle that deserves renewed attention.
If an organization never collected a passport scan, attackers cannot steal its passport database.
If it never retained a selfie, there is no selfie archive to leak.
Retention Policies Matter
Verification should not automatically mean permanent storage.
Organizations should define exactly how long information needs to exist.
Then they should enforce that policy technically.
Compliance Can Create New Security Problems
Regulation may demand stronger verification.
But compliance programs must also consider the cybersecurity consequences of collecting more sensitive information.
A regulation can solve one problem while unintentionally expanding another.
Government Databases Need the Same Skepticism
Governments are not automatically safer custodians of identity information.
Large centralized registries can become extraordinarily attractive targets.
Identity Providers Are High-Value Targets
Verification companies effectively sit at the intersection of technology, regulation, finance, social platforms, and personal identity.
That makes them strategically valuable to attackers.
Support Systems Are Part of the Attack Surface
Organizations frequently protect production databases more carefully than customer-support systems.
That is dangerous.
A support ticket can contain the same passport or identity information as a production verification workflow.
Logs Can Become Shadow Databases
If applications log identity numbers, document names, verification responses, or tokens, attackers may find sensitive information outside the primary database.
Security Testing Must Follow the Data
Penetration testing should not stop at the public-facing website.
It should follow the entire identity journey.
Upload.
Processing.
Verification.
Storage.
Support.
Analytics.
Backups.
Deletion.
Vendor Chains Need Visibility
A platform may have one verification vendor that uses several additional subprocessors.
The security team needs to understand that entire chain.
Encryption Is Not Enough
Encryption protects data under certain conditions.
It does not solve compromised credentials.
It does not stop authorized insiders.
It does not prevent insecure applications from exposing decrypted information.
It does not fix poor retention policies.
Access Control Is Critical
Identity systems should operate under strict least-privilege principles.
Employees should receive only the access required for their role.
Administrative Credentials Deserve Special Protection
A compromised administrator account can be more dangerous than a vulnerable web endpoint.
Privileged identities should use strong authentication, hardware-backed credentials where possible, short-lived access, and detailed monitoring.
Breach Detection Must Be Fast
An intrusion lasting hours is bad.
An intrusion lasting months is potentially catastrophic.
Identity providers should prioritize rapid detection and response.
The Industry Needs Better Transparency
Users rarely know exactly where their identity documents go after clicking “Verify.”
That needs to change.
People should be told what is collected, why it is collected, who processes it, where it is stored, and when it will be deleted.
Users Need Real Choices
Privacy-preserving alternatives should become standard rather than exceptional.
A person should not have to surrender a permanent biometric identity merely to access an ordinary online service.
Security Should Be Measured Before Deployment
Companies should perform threat modeling before introducing mandatory verification.
The question should be:
What new information are we creating, and who will want it?
The Cost of Failure Is Asymmetric
The benefit of verification may be incremental.
The consequence of a massive identity breach can last decades.
That imbalance deserves serious consideration.
Identity Theft Could Become More Convincing
AI-powered fraud makes leaked identity material increasingly dangerous.
High-quality identity documents and selfies can potentially help attackers construct more convincing impersonation attempts.
Deepfakes Increase the Stakes
As synthetic media becomes more sophisticated, stolen verification data could become valuable raw material for fraud campaigns.
Identity databases therefore represent future risk, not merely today’s risk.
Security Teams Need a New Mental Model
Identity information should be treated closer to critical infrastructure than ordinary application data.
It deserves exceptional protection.
Data Minimization Should Become a Default
If the application needs one bit of information, it should not collect fifty.
That principle could eliminate enormous amounts of unnecessary exposure.
The Future Should Be More Private, Not More Centralized
The internet does not necessarily need more giant databases of passports and selfies.
It needs better ways to prove facts without exposing everything about the person.
The Central Question Is Trust
Ultimately, identity verification depends on trust.
Users trust companies with their documents.
Companies trust vendors.
Governments trust databases.
But trust without verification is not security.
The 88-Incident Pattern Matters
The
It is the repeated pattern.
Different companies.
Different countries.
Different technologies.
Different mistakes.
Yet the same fundamental problem appears again and again.
The Industry Has an Opportunity
Identity verification is not inherently dangerous.
Poorly designed identity verification is.
The industry can still build systems that collect less, retain less, expose less, and decentralize sensitive information.
Undercode’s Bottom Line
The uncomfortable lesson is straightforward:
The more systems we build to prove who people are, the more carefully we must design systems that ensure nobody else can steal that identity.
The next generation of identity technology should not be defined by how much information it can collect.
It should be defined by how little information it needs.
✅ The Report Documents 88 Identity-Related Incidents
The supplied article accurately presents the central claim of the Mysterium VPN report: it examines 88 documented incidents involving identity or age-verification data since 2011. The distinction between confirmed records and attacker or seller claims is important because those categories do not have equal evidentiary strength.
✅ Biometric and Identity Documents Create Long-Term Risk
The
⚠️ Record Totals Require Context
The reported 2.15 billion verified records and additional 4.54 billion claimed records should not be treated as equally confirmed breaches. The latter category depends on claims attributed to attackers or data sellers, so readers should distinguish verified evidence from unconfirmed assertions.
Prediction
(+1) Privacy-Preserving Age Verification Will Grow
As governments and platforms demand stronger age assurance, pressure will increase for technologies that can prove age without exposing a complete identity document. Selective disclosure, cryptographic credentials, and privacy-preserving verification are likely to become increasingly important.
(+1) Identity Vendors Will Face Much Greater Security Scrutiny
Major platforms will increasingly demand stronger evidence that verification providers can protect sensitive documents. Vendor security reviews will likely become deeper, with greater attention to privileged access, retention, subcontractors, incident detection, and deletion guarantees.
(+1) Data Minimization Will Become a Competitive Advantage
Companies that can verify users while storing less sensitive information will have a meaningful security and privacy advantage. “Collect everything and protect it” is becoming increasingly difficult to defend as a long-term strategy.
(-1) Centralized Identity Databases Will Remain Prime Targets
Large identity repositories will continue attracting cybercriminals because the potential rewards are enormous. As more services introduce mandatory verification, the number of valuable databases will probably increase unless organizations adopt stronger decentralization and privacy-preserving architectures.
(-1) Stolen Identity Data Will Become Harder to Contain
Once identity documents and biometric material enter criminal ecosystems, removing every copy is practically impossible. The combination of leaked documents, AI-assisted impersonation, synthetic media, and increasingly sophisticated fraud could make future identity breaches more damaging than many organizations currently anticipate.
▶️ Related Video (74% Match):
🕵️📝Let’s dive deep and fact‑check.
🎓 Live Courses & Certifications:
Join Undercode Academy for Verified Certifications
🚀 Request a Custom Project:
Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands
References:
Reported By: securityaffairs.com
Extra Source Hub (Possible Sources for article):
https://www.discord.com
Wikipedia
OpenAi & Undercode AI
Image Source:
Unsplash
Undercode AI DI v2
🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]
📢 Follow UndercodeNews & Stay Tuned:
𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin | 🦋BlueSky | 🐘Mastodon | 📺Youtube




