2026 Unsecured MongoDB database — ~1B KYC records
Data compromised
Full names, dates of birth, addresses, postal codes, phone numbers, email addresses, national ID numbers, gender, telecom metadata, KYC/AML verification logs
Technical writeup
Cybersecurity researchers discovered an unsecured MongoDB database linked to IDMerit on November 11, 2025. The repository contained over 3 billion total records (system logs, metadata) with roughly 1 billion containing highly sensitive PII (~1 TB). No password protection or encryption; database was left accessible on the open internet. Exposed fields: full names, dates of birth, physical addresses, postal codes, phone numbers, email addresses, national ID numbers, gender, telecom metadata. Records associated with KYC/AML identity verification logs. Highest concentrations: US (203M+), Mexico (124M), Philippines (72M), Germany (61M), Italy/France (~53M each). Database secured the day after disclosure. No evidence banks were directly breached—exposure at third-party identity verification vendor layer.
Root cause
Misconfigured MongoDB; no authentication or encryption; left accessible on open internet
References
- https://www.biometricupdate.com/202602/one-billion-identity-records-exposed-in-unsecured-id-verification-database
- https://cybernews.com/security/global-data-leak-exposes-billion-records/
- https://tomsguide.com/computing/online-security/1-billion-personal-records-from-26-countries-exposed-in-massive-new-data-leak-how-to-stay-safe