r/dataprotection • u/PureVPNcom • 1d ago
General Discussion Every time you've uploaded your ID or a selfie to verify your age or identity online, here's what's been happening to that data
A report dropped this week that's worth reading if you've ever had to scan your passport, take a verification selfie, or submit a government ID to use an online service.
A VPN company compiled 88 documented incidents going back to 2011 where data collected specifically to verify someone's identity or age got breached, exposed, or sold. The confirmed and researcher-verified total sits at 2.15 billion records, with attacker claims adding another 4.54 billion on top of that.
The numbers are large enough to go numb to them. The specific detail that actually matters is this: in 41 of the 88 incidents, what leaked included the source documents themselves. ID scans, verification selfies, fingerprints, full biometric templates. A password gets reset in thirty seconds. A face doesn't.
The timing is the other thing. 37 of the 88 incidents happened between January 2024 and August 2026, right when mandatory identity and age checks were spreading around the world fastest. Every major ID verification vendor from the current era, AU10TIX, IDMerit, Sumsub, Persona, inVOID, has appeared in this timeline. Persona specifically handles age verification for Discord and Roblox.
The core problem is structural. A lot of these verification requirements exist because platforms or governments want to comply with age laws or anti-fraud rules. So they outsource the verification to a third party, that third party collects and stores biometric data, and then that third party gets breached. The platform that told you to verify is often completely unaffected. The company holding your face and your ID scan is the one that had the incident.
There's not much you can do retroactively about data you've already submitted. Going forward though it's worth knowing that "verify with a government ID" is not a neutral step anymore, it's handing sensitive permanent data to a company whose security posture you probably can't evaluate. Worth asking what happens to that data after verification before you submit it.
Sources: Security Affairs