SLC Digital is coming to FinovateFall 2026 — September 9–11 · SLC will be live on stage

SLC at FinovateFall 2026 · Sept 9–11

Someone finally sat down and counted every publicly documented identity verification breach since 2011, every case where data collected to verify someone's identity or age ended up exposed, stolen, or sold. They found 88 of them, exposing 2.15 billion confirmed records, and attackers and sellers claim another 4.54 billion on top of that.

Read that timeline start to finish and a pattern falls out that no single breach report ever shows on its own. This isn't 88 unrelated failures. It's one failure mode, repeated for fifteen years, across every kind of organization that has ever decided to collect this category of data.

The mechanism has never changed. Someone builds a place to store identity documents. Eventually, that place gets breached. Call it what it is: an identity verification breach, any incident where data collected to prove who you are, an ID scan, a selfie, a fingerprint, gets exposed, stolen, or sold.

What's driving the surge in identity verification breaches



Of the 88 incidents in the timeline, 37 of them, 42% of the total, happened between January 2024 and August 2026. That's not a coincidence. That's the exact window in which mandatory identity and age verification spread fastest across the internet: the UK Online Safety Act, US state-level age verification laws, KYC requirements nearly everywhere you turn. Every new law that makes an ID check mandatory creates a new pile of identity documents somewhere. Every pile eventually becomes a target.

And the damage from these incidents doesn't reset the way other breaches do. In 41 of the 88 cases, what actually leaked was the underlying document: the ID scan, the verification selfie, the fingerprint, the biometric template. A password can be changed in thirty seconds. A face cannot. Once that data is out, it's out permanently, and it can be reused against the same person for the rest of their life.



The most concerning detail in the whole dataset isn't a single incident. It's how many repeat appearances there are. Some of the biggest names in identity verification, the vendors that check IDs and ages for major social platforms, marketplaces, and fintechs, show up more than once in the timeline: exposed admin credentials left open for over a year, support-system intrusions that ran undetected for a year and a half, frontend misconfigurations, open databases with identity records sitting unprotected. These are the companies the internet is currently trusting to hold everyone's most sensitive documents, and the record shows they haven't demonstrated they can do that safely.

It isn't only vendors. Governments have fared no better with their own centralized registries, and a government identity data leak tends to be even larger in scale.

  • Argentina's national identity system reportedly leaked 45 million records, including ID scans and selfies

  • France's ANTS, the agency that literally issues French identity documents, confirmed 11.7 million people affected earlier this year

  • India's Aadhaar-linked exposure

  • Thailand's visitor database

  • Philippines' voter rolls

  • Brazil's tax registry

and the pattern repeats at country scale about as often as it does at startup scale.

The uncomfortable conclusion

This dataset isn't arguing that identity verification is pointless. Verifying who someone is, or how old they are, serves a real purpose. The argument is narrower and harder to ignore: every organization that has ever centralized a store of identity documents, whether a five-person startup or a national government, has eventually watched that store get breached, exposed, or sold. Fifteen years of evidence say this isn't a series of bad actors or unlucky configurations. It's what happens by default when the model for verifying identity is "collect the document and store it somewhere."

That's the part worth sitting with if you're building or buying identity infrastructure right now. The question isn't whether your vendor is reputable. Every vendor named in this timeline was, until the day they weren't. The question is whether the system was ever designed to hold a centralized, reusable copy of someone's most sensitive data in the first place.

Why hardware-rooted identity verification avoids this failure mode

This is exactly the failure mode SLC was built to avoid. The vendors in this timeline all rely on the same underlying model: collect a document, store a copy, verify against that copy every time someone needs to prove who they are. That store is the target, and as this data shows, it gets hit eventually no matter who's running it.

SLC takes a different approach. Instead of centralizing scanned documents or biometric templates in a database that someone eventually has to defend, SLC anchors identity in the SIM or eSIM itself, a hardware root of trust that already lives on the device and never needs to be uploaded, stored, or pooled anywhere. There's no repository of selfies or ID scans sitting on a server waiting for the next credential leak or misconfigured bucket. Verification happens as a cryptographic, non-repudiable proof tied to the hardware.

The 88 incidents in this timeline all trace back to the same design decision: build a place to store identity data, and eventually defend it. SLC's bet is that the fix isn't a better-defended database. It's not having one.