Researchers Find Exposed Persona Identity Verification Frontend Revealing Extensive KYC, AML, and Biometric Monitoring Capabilities
A report by The Rage describes how three security researchers investigating Persona, an identity verification company used by platforms such as Discord, discovered thousands of publicly accessible frontend files exposed on the internet. According to the article, the exposed code revealed capabilities extending far beyond simple age verification. Persona’s software allegedly performs hundreds of identity checks, including biometric facial analysis, age estimation, device and browser fingerprinting, government ID validation, watchlist screening, sanctions checks, and anti-money laundering (AML) monitoring. The researchers claim the system can compare selfies against watchlists, analyze facial characteristics, generate risk scores, and retain personal information for extended periods. The article further states that the software integrates with blockchain analytics providers and supports the filing of suspicious activity reports to government authorities. Researchers also reported finding references to a separate FedRAMP-authorized government-oriented implementation, suggesting similar identity verification and monitoring capabilities could exist in government environments. The exposed infrastructure reportedly included references to OpenAI-related identity verification databases and tools used for user monitoring and analytics. The researchers argue that age-verification systems can create significant privacy and security risks by centralizing sensitive biometric and identity data, making them attractive targets for attackers. The article notes that Discord later announced it would not proceed with Persona for identity verification. Overall, the report raises concerns about the expansion of biometric identity verification, surveillance capabilities, financial compliance monitoring, and the growing intersection between private technology companies and government oversight systems.
