Twin AI data leaks expose over a billion personal KYC records and private media files

Cybersecurity researchers have uncovered two massive data leaks linked to two AI-related apps that have exposed the sensitive personal data and media files of millions of users globally. The leak was revealed in two separate reports by Cybernews (first reported by Forbes), in which the security researchers warned that over a billion records could be compromised.

IDMerit data leak

The first leak has been attributed to an AI-powered Know Your Customer (KYC) tool used by digital identity verification provider IDMerit. The company is an AI-powered digital identity verification solutions provider that serves the fintech and financial services sectors by providing real-time verification tools.

“Our researchers noticed the exposed instance on 11 November 2025, and immediately contacted the company, which promptly secured the database. While there is no current evidence of malicious misuse, automated crawlers set up by threat actors constantly prowl the web for exposed instances, downloading them almost instantly once they appear,” the cybersecurity researchers wrote.

Countries affected by data leak

Countries affected by data leak

The leak exposed 1 billion sensitive personal records spanning individuals from 26 countries. The United States was the most affected, with over 203 million exposed records, followed by Mexico (124 million) and the Philippines (72 million).

The exposed data included “core personal identifiers used for your financial and digital life,” including full names, addresses, postcodes, dates of birth, national IDs, phone numbers, genders, email addresses and telco metadata.

Researchers say that the downstream risks of this data leak could include account takeovers, targeted phishing, credit fraud, SIM swaps, and long-tail privacy harms.

Video AI Art Generator & Maker leak

The second leak is linked to an Android app named “Video AI Art Generator & Maker,” which has been downloaded over 500,000 times on Google Play and rated 4.3 stars with over 11,000 reviews.

The app was found leaking user data due to a misconfigured Google Cloud Storage bucket that allowed anyone access to stored files without authentication. Researchers say the app leaked over 1.5 million user images and 385,000 videos, along with millions of media files generated by users using AI.

The exposed bucket contained approximately 8.27 million media files and over 12TB of users’ media. Researchers say that it has stored and leaked every file uploaded since its launch on 13 June 2023, while the oldest file in the bucket dates back to three days before the launch.

The app was developed by Turkey-registered Codeway Dijital Hizmetler Anonim Sirketi, a company that previously saw another of its apps, Chat & Ask AI, leak roughly 300 million messages tied to more than 25 million users.

Latest

How to use whatsApp on two phones with same number? A step-by-step guide

How to use whatsApp on two phones: With Companion Mode, you can easily use WhatsApp on two phones. It is useful if you carry both a personal and a work phone.

Amazon is buying Globalstar to rival Starlink, Apple makes it default satellite service provider for iPhone

Amazon's strategic acquisition to rival Starlink in satellite services

Vivo X300 Ultra and X300 FE launch date leaks online, here is all you need to know

The Vivo X300 Ultra was launched in China on March 30, and it is now expected to make its way to India alongside the Vivo X300 FE on May 7. Both devices are tip

IPhone 18 Pro is launching soon, leak says Android is getting ready to copy its one big feature

The iPhone 18 Pro models may arrive in a deep red colour option, while rumours suggest that the next-generation lineup might skip the classic black finish this

Meta’s Muse Spark: Mark Zuckerberg’s AI reset raises uncomfortable questions about jobs, data and its future

What looks like a product upgrade is really a deeper structural shift, one that could redefine jobs, data use and growth in Big Tech.

Topics

MP Board Class 10, 12 results out: 78.14% pass in Class 10, over 76% in Class 12

The MP Board has declared Class 10 and 12 results today at 11 am. Over 16 lakh students can now check their scores online on the official website and plan next

Happy Vishu Day 2026: 50+ wishes, messages, and quotes to share with your loved ones

Happy Vishu Day 2026 celebrates the Malayalam New Year with hope, prosperity, and new beginnings. Share heartfelt wishes, messages, and quotes with your loved o

How to use whatsApp on two phones with same number? A step-by-step guide

How to use whatsApp on two phones: With Companion Mode, you can easily use WhatsApp on two phones. It is useful if you carry both a personal and a work phone.

Sensex, Nifty open higher on hopes of renewed US-Iran talks

The S&P BSE Sensex was up 1,189.51 points to 78,037.08, while the NSE Nifty50 rose 366.40 points to 24,209.05 as of 9:26 am. 

Sensex, Nifty opening: Will stock market open higher or lower today?

Markets anticipate positive opening with diplomatic hopes in focus

US-Iran mistrust cannot be solved overnight, Vance says as talks near

Diplomatic efforts continue despite deep-rooted mistrust and challenges

Roelf Meyer appointed as South Africa’s ambassador to the United States

Veteran negotiator Roelf Meyer takes on diplomatic role in the US

Secret Saudi-Pakistan war pact exposed as Islamabad’s neutral role unravels

Leaked documents reveal a secret Saudi-Pakistan defense pact that could draw Islamabad into the Iran conflict, raising doubts about its neutrality as ceasefire
spot_img

Related Articles

Popular Categories

spot_imgspot_img