Nine numbered incidents at identity-verification vendors push the conservative ten-year exposure proxy to 1.59 billion — 4.32 billion by raw record volume

Asked:“Create a compiled list of all breaches affecting identify verification vendors in the past 10 years - compile a running total list of all individual identity records leaked”

Best-effort open-source compilation covering 2016-09-02 to 2026-09-02, as of 2026-09-02. Nine incidents at identity-verification, background-screening and identity-data vendors carry a defensible public number. Two measures, never interchangeable: the conservative non-deduplicated person/record proxy of 1,588,120,333 (distinct-person estimates, falling back to record counts only where no person count exists), and the incident-volume total of 4,318,120,333 (reported record counts wherever available). Neither is a count of globally unique people.

Cumulative conservative exposure proxy, 2017–2026

confirmed by company / regulator researcher-discovered exposure or estimate litigation / complaints unverified threat-actor claim

What the curve cannot say alone

Five incidents dominate: National Public Data, IDMerit, IDScan.net, Equifax and MC2 Data account for over 99% of reported volume. asisonline.org
IDMerit's 1 billion (researcher-found exposed database, discovered 2025, disclosed 2026) counts records across 26 countries, not demonstrated unique people; 3 billion records were reported in total. tech.yahoo.com
Two of the largest figures are unverified threat-actor claims as of 2026-09-02: IDScan.net's 166.58 million documents and Fractal ID's 300,000 KYC users. byteiota.com
National Public Data's 2.9 billion is a reported record count; roughly 170 million is the people/unique-SSN proxy used in the conservative running total. asisonline.org
Equifax's 147 million (2017) remains the largest fully confirmed distinct-person figure in the set, settled with the FTC. ftc.gov

Incident ledger

Vendor · yearCategoryAffected peopleIdentity recordsRunning total (conservative)StatusExposed dataSource

Method: best-effort open-source compilation of breaches at identity-verification, document/biometric verification, background-screening and identity-data vendors, 2016-09-02 to 2026-09-02, from thousands of live web results; 9 numeric incidents shown, as of 2026-09-02. No authoritative worldwide registry exists, and “all” is bounded by discoverable public reporting and this vendor scope. Counts mix distinct-person estimates and record/document counts; the conservative running total prefers person counts and is non-deduplicated across incidents. Excluded: customer companies breached independently of the verification vendor; code-only exposures without identity records; duplicate reports of one event; and vendors with publicly reported incidents but no defensible affected-person count. Attribution warning: Persona is excluded from totals — its 2,500 figure refers to publicly accessible frontend files, and the 70,000-ID Discord incident was attributed to support vendor 5CA, not to a breach of Persona itself. Blank cells mean no public figure of that kind exists; blanks are not zeros.

This report was generated automatically by Keenable SELECT at a user's request, from publicly available web sources linked herein. Keenable does not review, verify, or endorse its contents and makes no representation as to accuracy, completeness, or timeliness; AI-based extraction may contain errors. Nothing in this report is investment, legal, financial, or other professional advice. All trademarks and referenced content remain the property of their respective owners; no affiliation or endorsement is implied. To report an error, rights concern, or request removal: legal@keenable.ai.

Keenable SELECTAsk your own question
Made with Keenable SELECT