CSIDB logo
Incident

IDMerit

Incident posture

Attack window
Nov 2025
Location
United States of America
Status
Resolved
CIA posture
Available to members
Updated
2026-08-27 01:38

Linked entities

Victim
IDMerit
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Undetermined
Discovered
Nov 2025
Disclosed
Nov 2025
Resolved
Nov 2025

Summary

IDMerit left a MongoDB database unprotected, exposing roughly one billion identity records that included names, addresses, dates of birth, national identification numbers, phone numbers, email addresses and gender information for individuals in 26 countries, with the United States accounting for over 203 million of those records. Researchers discovered the open database and notified the company, which secured the system the next day; IDMerit stated that it does not store customer data and that its partners confirmed no breach occurred in their systems, while noting there is currently no public evidence that the data was downloaded by malicious actors.

Motives

Detailed motive labels are available to members.

2 motives

TTPs

Detailed technique labels are available to members.

0 techniques

Description

On November 11, 2025, researchers from Cybernews discovered an unprotected MongoDB database that they attributed to IDMerit, a global identity verification provider serving banks, fintech firms and other financial services companies. The database lacked any password protection, allowing anyone who knew its location to access its contents. Inside the exposed store were full names, home addresses, postal codes, dates of birth, national ID numbers, phone numbers, email addresses and gender information, with some records also containing telecom‑related metadata and internal flags that may have referenced prior incidents. The exposure spanned 26 countries, with the United States accounting for more than 203 million of the roughly one billion records, while Mexico, the Philippines, Germany, Italy and France were also heavily affected. Researchers noted that automated bots continuously scan the internet for open databases and can copy the data within minutes, though no public evidence indicated that criminals had downloaded the information at the time of discovery.

Following the discovery, the researchers notified IDMerit, and the company secured the database the next day, on November 12, 2025. Upon being alerted by an ethical hacker about potentially open data ports linked to independent data sources, IDMerit conducted a comprehensive review of its software, security controls, configurations and system logs, which revealed no exposure, vulnerability or unauthorized access within its own environment. The firm stated that its systems and security infrastructure had never been compromised and that it does not own, control or store customer data, instead connecting to authorized data sources globally to verify identities on behalf of its clients. IDMerit simultaneously informed all relevant data source partners, who performed internal investigations and confirmed that there had been no breach or exfiltration from their systems before, during or after the event. When IDMerit requested a security incident report from the ethical hackers as proof, the hackers responded with a demand for money, leading the company to characterize the episode as a ransom‑related attempt. Based on its internal review and the partners’ confirmations, IDMerit asserted that there was no indication any customer data had been compromised and said it continued to maintain robust security safeguards while investigating the matter in coordination with its partners.

Sources

Sources available to members: 1 source.

CSIDB