← IDMerit

2026 Unsecured MongoDB database — ~1B KYC records

2026 1.0B records affected Share on X

Data compromised

Full names, dates of birth, addresses, postal codes, phone numbers, email addresses, national ID numbers, gender, telecom metadata, KYC/AML verification logs

Technical writeup

Cybersecurity researchers discovered an unsecured MongoDB database linked to IDMerit on November 11, 2025. The repository contained over 3 billion total records (system logs, metadata) with roughly 1 billion containing highly sensitive PII (~1 TB). No password protection or encryption; database was left accessible on the open internet. Exposed fields: full names, dates of birth, physical addresses, postal codes, phone numbers, email addresses, national ID numbers, gender, telecom metadata. Records associated with KYC/AML identity verification logs. Highest concentrations: US (203M+), Mexico (124M), Philippines (72M), Germany (61M), Italy/France (~53M each). Database secured the day after disclosure. No evidence banks were directly breached—exposure at third-party identity verification vendor layer.

Root cause

Misconfigured MongoDB; no authentication or encryption; left accessible on open internet

References