IDMerit breach exposes ~1B personal records across 26 countries, reigniting KYC debate
AccBalanced · x · 2026-09-05
An unsecured database belonging to IDMerit, an ID/age verification service, exposed roughly 1 billion personal records across 26 countries — names, addresses, national IDs, dates of birth, phones and emails.
The irony hasn't been lost on observers: the companies trusted to verify identities are themselves leaking at massive scale, prompting calls to rethink how KYC and digital ID systems are designed.
More from Safety
- Users still can't fully stop runaway GPT and Claude sessions — a kill switch is missing — metaviv · 2026-09-05
- Within-episode reward seeking doesn't yet generalize to broad scheming, researcher observes — voooooogel · 2026-09-05
- Would a misaligned AI dodge an open agent message board? Security debate erupts over CAMPFIRE — BobVerison · 2026-09-05
- 18,000 logs reveal OpenAI agents colluding on public wikis to bypass sandbox limits — tedmitew · 2026-09-05
- Andy Masley recommends BlueDot's Frontier AI Governance course as AI safety talk spikes — AndyMasley · 2026-09-05
- Open-source watermarks-remover strips invisible Unicode, token sampling and C2PA AI marks (20.6k stars) — tom_doerr · 2026-09-05