IDMerit
Incident posture
Timeline
Summary
IDMerit left a MongoDB database unprotected, exposing roughly one billion identity records that included names, addresses, dates of birth, national identification numbers, phone numbers, email addresses and gender information for individuals in 26 countries, with the United States accounting for over 203 million of those records. Researchers discovered the open database and notified the company, which secured the system the next day; IDMerit stated that it does not store customer data and that its partners confirmed no breach occurred in their systems, while noting there is currently no public evidence that the data was downloaded by malicious actors.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
On November 11, 2025, researchers from Cybernews discovered an unprotected MongoDB database that they attributed to IDMerit, a global identity verification provider serving banks, fintech firms and other financial services companies. The database lacked any password protection, allowing anyone who knew its location to access its contents. Inside the exposed store were full names, home addresses, postal codes, dates of birth, national ID numbers, phone numbers, email addresses and gender information, with some records also containing telecom‑related metadata and internal flags that may have referenced prior incidents. The exposure spanned 26 countries, with the United States accounting for more than 203 million of the roughly one billion records, while Mexico, the Philippines, Germany, Italy and France were also heavily affected. Researchers noted that automated bots continuously scan the internet for open databases and can copy the data within minutes, though no public evidence indicated that criminals had downloaded the information at the time of discovery.
Following the discovery, the researchers notified IDMerit, and the company secured the database the next day, on November 12, 2025. Upon being alerted by an ethical hacker about potentially open data ports linked to independent data sources, IDMerit conducted a comprehensive review of its software, security controls, configurations and system logs, which revealed no exposure, vulnerability or unauthorized access within its own environment. The firm stated that its systems and security infrastructure had never been compromised and that it does not own, control or store customer data, instead connecting to authorized data sources globally to verify identities on behalf of its clients. IDMerit simultaneously informed all relevant data source partners, who performed internal investigations and confirmed that there had been no breach or exfiltration from their systems before, during or after the event. When IDMerit requested a security incident report from the ethical hackers as proof, the hackers responded with a demand for money, leading the company to characterize the episode as a ransom‑related attempt. Based on its internal review and the partners’ confirmations, IDMerit asserted that there was no indication any customer data had been compromised and said it continued to maintain robust security safeguards while investigating the matter in coordination with its partners.
Sources
Sources available to members: 1 source.