Skip to content
Lyon & Fiurex

Global KYC / AML Vendor Intelligence

KYC, AML and Identity Vendors: Market, Pricing and Documented Risk

KYC • CDD • UBO • PEP • EDD • AML/CFT • CPF Part I: market landscape, capability coverage and pricing. Part II: publicly documented security, privacy, legal and operational findings.

Document dated 1 October 2026 · L&F Research Desk · 35 min read

Basis: vendor materials, market research, court records, regulator and attorney-general notices, security advisories and press reporting. Prepared for Lyon & Fiurex LLC Group.

“Dirty secrets” is treated here as documented adverse information, not rumor. Allegations are labelled as allegations. A lawsuit is not a finding of liability, and a settlement generally is not an admission.

Source-verification status

Live recheck pending

This report reflects a research document dated 1 October 2026. A live check on 4 October 2026 corroborated the attributed statements in the Sumsub disclosure [S20], Persona arbitration ruling [S22], AU10TIX response [S26] and Veriff / Total Wireless notice [S36]. Automated retrieval and searching do not verify every claim: the remaining findings require human editorial review, and inaccessible sources remain unverified. Each statement is attributed to its source and date.

  • Re-check every cited source on the day you publish, procure or advertise from this report.
  • Court matters can be dismissed, settled or amended; incident scopes can change; prices and privacy policies change.
  • Absence of a located breach, CVE or lawsuit is not evidence that none exists.
  • Each statement carries a label: primary record, vendor statement, media report, allegation, procedural outcome, research or unconfirmed lead.

Review policy

Lyon & Fiurex monitors the cited sources and vendors on a 15-day cycle while the API service is running; overdue checks resume after a restart. Automated change detections and unverified reports are routed to human editorial review and are not published automatically. Primary records (regulator notices, court dockets) are given more weight than complaints or press reports; for example, on Veriff the Total Wireless breach notice [S36] is preferred over complaint allegations [S27], and the litigation is classified separately [S37].

Executive Summary

This report combines a competitive-pricing benchmark and an adverse-vendor research brief into one financial-crime-compliance study. It keeps the evidentiary standard of both: official list prices first, then quote-only status, reseller evidence and public procurement; and a strict separation of allegations from findings.

  • KYC software. US$7.75B estimated for 2026 and US$35.86B projected for 2034, per Fortune Business Insights. [S1]
  • Identity verification. US$15.5B estimated for 2026 and US$38.5B projected for 2033, per Grand View Research. [S2]
  • AML market. Taxonomies differ: US$2.0B (2025) to US$4.24B (2030) per Grand View Research; US$4.13B (2025) to US$9.38B (2030) per MarketsandMarkets. [S3, S4]
  • Vendor universe. 70 vendors across identity verification, KYB, ownership discovery, sanctions/PEP screening, transaction monitoring, client lifecycle, crypto AML and export-control intelligence. This is not an exhaustive census; one July 2026 directory independently tracks 60 providers. [S5]
  • Pricing transparency. Only a minority publish usable list prices, for example ComplyAdvantage from US$99/month, Sumsub at US$1.35 to US$1.85 per verification, ComplyCube, iDenfy and Ondato. Enterprise incumbents are predominantly quote-based. [S8, S9, S10, S11, S31]
  • Documented risk signals. World-Check accuracy and PEP-classification disputes [S14, S15, S17]; a LexisNexis incident affecting 364,333 people [S18]; a Sumsub support-environment incident [S20]; biometric-privacy litigation involving Onfido, Jumio and Persona [S22, S24, S25]; an AU10TIX legacy-credential event the vendor says caused no data exposure [S26]; and 2026 litigation tied to Veriff and Total Wireless [S36, S37]. Each is presented with its procedural and vendor-response context.

Important limitation. Absence of a located breach, CVE or lawsuit is not evidence that none exists. Vendor posture, ownership, pricing, scope and legal status change over time.

Market Size and Growth Signals

SegmentBase / current estimateForecastGrowthSource
KYC softwareUS$6.4B (2025); US$7.75B (2026)US$35.86B by 203421.11% CAGR 2026–2034[S1]
Identity verificationUS$13.4B (2025); US$15.5B (2026)US$38.5B by 203313.9% CAGR 2026–2033[S2]
AML market, GVR taxonomyUS$1.73B (2024); about US$2.0B (2025)US$4.24B by 203016.2% CAGR 2025–2030[S3]
AML market, M&M taxonomyUS$4.13B (2025)US$9.38B by 203017.8% CAGR 2025–2030[S4]

Why estimates differ: research firms define the category differently. Some fold identity verification, KYC/CDD and services into AML; others isolate transaction monitoring or identity verification. Use the figures as directional evidence and do not add them together. [S3, S4]

Methodology, Scope and Definitions

Evidence hierarchy: primary vendor pages and trust disclosures; regulator and attorney-general notices; court judgments and dockets; government procurement; then established journalism and specialist research. Marketing claims are treated as vendor claims, not independent verification.

Definitions

KYC / CDD
Identity verification and customer-risk assessment at onboarding and through the relationship.
UBO / KYB
Business verification and beneficial-ownership discovery or ownership-chain analysis.
PEP / sanctions
Politically exposed persons, relatives and close associates, sanctions and watchlist screening.
EDD
Enhanced due diligence: adverse media, source of funds or wealth, or investigator-led deeper review.
AML/CFT
Anti-money-laundering and counter-terrorist-financing controls, including screening, transaction monitoring and case management.
CPF
Counter-proliferation financing. It often overlaps with sanctions, export-control, military-end-use and proliferation-network intelligence; few vendors market a standalone CPF module.

Adverse research means documented incidents, vulnerabilities, privacy disputes, litigation, regulatory or civil-liberties controversies, significant advisories and material public-risk signals. Allegations are never stated as proven liability unless a court or regulator has made that finding. Research cut-off: 1 October 2026; internet research is non-exhaustive.

Evidence classes used in the deep dive

ClassMeaningHow it should be stated
A Confirmed / primaryRegulator notice, breach notice, final judgment, vendor admission, official advisory or authenticated court order.State as documented fact, with date and scope.
B Settlement / proceduralSettlement, injunction, arbitration ruling, consolidation or stay, or dismissal without a merits finding.State the outcome precisely; do not imply an admission of liability.
C AllegationComplaint, claimant allegation, advocacy report or disputed factual assertion.Use “alleged”, name the claimant or source, and include the vendor response where found.
D Technical exposure / researchDemonstrated bypass, attack class, vulnerability, advisory or test finding.Distinguish a product-specific weakness from a sector-wide technique and from a successful compromise.
E Structural diligence signalVendor-disclosed retention, cross-customer data use, data sourcing, government deployment or architecture that raises governance questions.Treat as procurement and privacy diligence, not misconduct.

Global Vendor Universe: 70 Vendors

Identified vendors with primary segment, public-pricing status and research depth. The list is broad but not a mathematically exhaustive census: the market is fragmented and private or regional vendors may have no discoverable footprint. One July 2026 directory is a market-map input. [S5]

Showing 12 of 70 vendors

VendorPrimary segmentPublic pricingResearch depthPrice source
ActicoAML · Transaction monitoringQuote / not located publiclyMarket-mapNo public price source located
AU10TIXIdentity verification · BiometricsQuote / not located publiclyDeep-diveNo public price source located
ChainalysisCrypto · AMLQuote / not located publiclyDeep-diveNo public price source located
ComplyAdvantageSanctions · PEP · Adverse media · AMLPublic starterDeep-dive[S8]
FaceTecLiveness · BiometricsQuote / not located publiclyDeep-diveNo public price source located
FenergoKYC · KYB · Client lifecycleQuote / not located publiclyMarket-mapNo public price source located
IDfyIdentity verification · Background checksQuote / not located publiclyMarket-mapNo public price source located
IDnowKYC · Identity verificationQuote / not located publiclyMarket-mapNo public price source located
IdentityMindIdentity verification · Fraud · AMLQuote / not located publiclyMarket-mapNo public price source located
idwallIdentity verification · AML · BrazilQuote / not located publiclyMarket-mapNo public price source located
iProovLiveness · BiometricsQuote / not located publiclyDeep-diveNo public price source located
JumioIdentity verification · KYC · AMLQuote / not located publiclyDeep-diveNo public price source located

Pricing status reflects the research document of 1 October 2026; “reported” entries must be checked live before use. [S5]

Core Capability Matrix: Selected Providers

ProviderKYC/CDDUBO/KYBPEP/SanctionsEDDAML/CFTCPF / proliferation relevance
LSEG World-Check [S12]YesYesYesYesYesStrong sanctions / PF-relevant data
LexisNexis Risk SolutionsYesYesYesYesYesSanctions / risk-data support
Dow Jones Risk & ComplianceYesYesYesYesYesSanctions / trade-control data
Moody’s KYC / Grid [S32]YesYesYesYesYesSanctions / ownership intelligence
ComplyAdvantage [S8]YesYesYesYesYesSanctions screening; CPF via list/risk coverage
Sumsub [S9]YesYesYesYesYesVia sanctions/PEP providers and monitoring
TruliooYesYesYesPartialYesSanctions / PEP; CPF not standalone
JumioYesPartialYesPartialYesAML screening; CPF not standalone
Entrust / OnfidoYesPartialPartialNoPartialPrimarily IDV; partner integrations
PersonaYesYesPartialPartialPartialWorkflow / integration dependent
FenergoYesYesYesYesYesCLM orchestration; data-provider dependent
NICE ActimizeYesYesYesYesYesEnterprise FCC / transaction monitoring
Napier AIYesPartialYesPartialYesAML / sanctions focus
QuantexaYesYesYesYesYesNetwork / entity-risk analytics
Kharon [S13]PartialYesYesYesYesExplicit proliferation / export-control intelligence
Castellum.AIPartialPartialYesPartialYesSanctions / export-control / watchlist focus
Sanction ScannerYesPartialYesPartialYesSanctions/PEP/TM; CPF via list coverage
ComplyCube [S10]YesYesYesPartialYesIntegrated KYC/KYB/AML
iDenfy [S11]YesYesYesPartialYesAML screening/monitoring add-ons
Ondato [S31]YesYesYesPartialYesKYC/KYB/AML
EncompassYesYesYesYesPartialKYC / UBO / ownership automation
SayariPartialYesYesYesPartialOwnership / sanctions / supply-chain risk
ChainalysisPartialPartialYesYesYesCrypto AML / sanctions exposure
Unit21YesPartialYesPartialYesAML / fraud / case management
Hawk AIYesPartialYesPartialYesTransaction monitoring / screening

Legend: Yes = direct or core capability; Partial = partner-dependent, data-dependent or adjacent; No = not a primary publicly marketed function in this review. CPF is rarely sold as a standalone module; strong CPF relevance is inferred only where the vendor explicitly covers proliferation networks, export controls, military end use or sanctions-ownership analytics.

Classification by the research brief. Itemised vendor-page sources are shown only where the report supplies one; other rows are analyst classification and need a live recheck.

Public Pricing Benchmark

Pricing is not directly comparable: units differ (per verification, per monitored entity, platform credit, annual licence, API quota, data entitlement, services scope). The table keeps the unit and the evidence type. Rows without a located public source say so.

VendorPublic benchmarkEquivalent / commitmentEvidenceQualificationSource
ComplyAdvantage EssentialsFrom US$99/month, annual billing (100 monitored entities)US$1,188/year starting pointOfficial pageEnterprise is custom; monitored-entity allowances scale.[S8]
ComplyAdvantage AgenticFrom US$149/month, annual billing (100 monitored entities)US$1,788/year starting pointOfficial pageAgentic alert-resolution workflows included.[S8]
Sumsub BasicUS$1.35 per successful verificationUS$149 minimum monthly commitmentOfficial pageIDV with liveness and face match; non-regulated positioning.[S9]
Sumsub ComplianceUS$1.85 per successful verificationUS$299 minimum monthly commitmentOfficial pageIncludes AML screening, ongoing monitoring and proof of address.[S9]
ComplyCube StarterUS$99/month platform creditAML standard US$0.50/check; extensive US$1.05/checkOfficial pageOnly successful verifications charged; mix depends on checks.[S10]
ComplyCube CoreUS$299/month platform creditAML standard US$0.35/check; extensive US$0.85/checkOfficial pageLower per-check pricing and ongoing-monitoring options.[S10]
iDenfy BasicUS$1.35 per verificationUS$135 minimum monthlyOfficial pageSanctions/PEP add-on +US$0.50/check.[S11]
iDenfy EnterpriseUS$0.75 / 0.65 / 0.55 base by annual volume3k–6k / 6k–12k / 12k+ credits per yearOfficial pageBundles and add-ons change the effective rate.[S11]
Ondato IDVAbout €1.40 to €0.50 per completed verificationVolume dependentOfficial pageSolution mix affects total cost.[S31]
LSEG World-CheckCustom quoteNot publicly listedQuote-basedDepends on product, users, data and integration.[S12]
Moody’s KYC / GridCustom quoteNot publicly listedVendor sales modelEnterprise data and platform licensing.[S32]
LexisNexis Risk SolutionsCustom quoteNot publicly listedVendor sales modelMultiple products and data configurations.No public price source located
Dow Jones Risk & ComplianceCustom quoteNot publicly listedVendor sales modelData and due-diligence scope varies.No public price source located
FenergoCustom quoteNot publicly listedVendor sales modelEnterprise CLM implementation scope is material.No public price source located
NICE ActimizeCustom quoteNot publicly listedVendor sales modelEnterprise modules and implementation vary.No public price source located
JumioCustom / volume-basedNo reliable official list locatedVendor sales modelIdentity, AML and workflow mix changes the quote.No public price source located
TruliooCustom / volume-basedNo reliable official list locatedVendor sales modelCoverage and product mix affect pricing.No public price source located
PersonaCustom / usage-based enterpriseNo reliable official list locatedVendor sales modelWorkflow components priced by configuration.No public price source located
Entrust Identity Verification / OnfidoCustom / volume-basedNo reliable current official list locatedVendor sales modelPost-acquisition commercial structure varies.No public price source located

Pricing interpretation

  • Per-check prices suit digital-onboarding vendors but often exclude KYB registry costs, proof of address, manual review, NFC, biometric deduplication, ongoing AML monitoring, data-provider charges, support and minimum commitments. [S9, S10, S11]
  • Enterprise AML and CLM vendors usually quote because price depends on customer count, transaction volume, geography, list and data rights, deployment, modules, implementation and support.
  • For UBO and EDD, price per check can mislead: ownership-chain depth, registry fees, analyst work and document retrieval can dominate cost.
  • For CPF and export-control intelligence, the commercial unit is often data coverage, API entitlement, a network dataset or platform access rather than a classic KYC check. [S13]

Comparative Findings Matrix

VendorPrimary signalFinding (as sourced)Sources
LSEG / Refinitiv World-CheckAccuracy / classification litigation2017: apology and damages to Finsbury Park Mosque. 2026: reported settlement over standalone PEP profiles of politicians’ grandchildren. Other claims continue.[S14, S15, S17]
LexisNexis Risk SolutionsSecurity incidentDec. 2024 breach of a third-party software-development platform, disclosed 2025; 364,333 people; SSN and driver-licence data for some.[S18, S19]
SumsubSecurity incidentJuly 2024 support-environment incident found Jan. 2026; vendor says limited data and no biometrics, ID images or core production compromise.[S20]
Sumsub / Merkur integrationThird-party integration failure2025: exposed integrator credentials; Sumsub says its own systems were not compromised.[S21]
PersonaBiometric privacy litigationIllinois BIPA claims over facial geometry; appellate court held Persona could not compel arbitration through the DoorDash agreement.[S22]
PersonaExposure report2026: researchers reported an exposed testing frontend; Persona said it was isolated and no personal data was exposed.[S23]
Entrust / OnfidoBiometric privacy litigationSosa BIPA litigation: reported settlement of about US$28.5M over alleged biometric collection without notice or consent.[S24]
JumioBiometric privacy litigationDavis v. Jumio BIPA putative class action; 2023 motion to dismiss denied.[S25]
AU10TIXCredential exposure signalVendor says inactive legacy credentials surfaced publicly in 2024; its forensic review found no production access, data exposure or customer impact.[S26]
Veriff2026 data-breach litigationClass complaints allege a 2025 incident affecting Total Wireless identity-verification data. These are allegations, not liability findings.[S27]
NICE ActimizeDependency / security advisorySpring4Shell / Log4j advisories: cloud solutions stated non-impacted; some on-premise Java 11 customers advised to contact support.[S28]
ChainalysisMethodology challenge / litigationBitcoin Fog defense challenged the methodology; evidence admitted. 2024–26 RICO/conversion allegations were dismissed.[S29, S30]
TruliooPrivacy regulator assessment2018 OAIC assessment: medium APP 11 documentation risk, low APP 5 notification risk; also strong controls recorded.[S34]
SignzySecurity incidentLate-2024 incident confirmed; CERT-In aware; public scope incomplete.[S35]
VeriffBreach notice + litigation2025 incident exposed government-ID images for some Total Wireless customers; 2026 consolidated litigation stayed for settlement talks.[S36, S37]
IncodeBiometric privacy settlementBIPA allegations over facial geometry resolved by a reported US$4M settlement.[S38, S39]
iProovKYC bypass researchRed-team face-swap / virtual-camera injection able to evade mobile KYC liveness, published in MITRE ATLAS.[S40]
FaceTecBiometric / IP litigationBIPA claim dismissed per FaceTec; separate patent disputes exist.[S41, S48]
MiddeskTrade-secret / insider risk2025 DTSA dispute: temporary restraints and consent orders over specified information; no admission of liability.[S42]
SocureStructural privacy / public-sector scrutinyVendor discloses broad derived-risk and biometric processing and multi-year retention for some data; officials and advocates raised transparency concerns.[S43, S44]
AiPriseCross-customer risk networkVendor discloses fraud flags and tokenized prior-verification signals across customers, with a controller role for this use.[S45]

Interpretation: a security incident and a lawsuit are not equivalent. A breach is a documented security event; a complaint is an allegation; an appellate ruling on arbitration is procedural; a settlement generally does not establish liability; and a vendor advisory can show remediation rather than exploitation.

Expanded Adverse and Diligence Matrix (Deep Dive)

Cut-off 1 October 2026. Each row carries the evidence class defined in the methodology (A to E) and its status or mitigation context.

VendorSignalClassDocumented findingStatus / mitigation contextSource
TruliooPrivacy governanceAThe OAIC found a medium APP 11 risk if information-security documentation gaps went unchecked, and a low APP 5 risk because individuals were not always clearly told of Trulioo’s role.2018 assessment; the OAIC also recorded strong staff understanding and good security practice. Historical, not a current breach.[S34]
SignzyCyber incidentA / CSignzy confirmed a late-2024 incident; CERT-In said it was aware. Reporting described alleged customer data appearing briefly on a cybercrime forum.Investigation engaged; some named customers said they had no exposure. Scope not fully disclosed.[S35]
VeriffBreach / litigationA / C / BA Total Wireless notice states an unauthorized party obtained personal information from Veriff systems, including government-ID images and possibly address and date of birth. Three 2026 cases were consolidated and stayed for settlement talks.The notice supports access to data; litigation allegations remain allegations.[S36, S37]
IncodeBiometric privacyB / CAspel v. Incode alleged unlawful facial-geometry collection under BIPA; settlement materials describe US$4M.A settlement is not an adjudicated admission of liability.[S38, S39]
iProovKYC bypass researchDiProov’s red team demonstrated a live face-swap injection attack able to evade mobile KYC facial recognition and liveness; published in MITRE ATLAS.Concerns an attack class demonstrated by iProov, not a breach of its production platform.[S40]
FaceTecBiometric litigationB / CA BIPA lawsuit naming FaceTec was dismissed in 2023. FaceTec says plaintiffs’ counsel concluded its architecture meant it did not itself collect end-user biometric data.Vendor-sourced account; no merits finding of wrongdoing.[S41]
MiddeskTrade-secret / personnel disputeA / B / CMiddesk sued Baselayer and former personnel under the Defend Trade Secrets Act; temporary restraints, then consent orders restricting use of specified information; resolved by stipulated dismissals.Orders state they are not admissions of fault. An insider and IP-control signal, not a customer-data breach.[S42]
SocureData use / public-sector scrutinyE / CSocure’s privacy notice describes derived network risk intelligence, biometric processing and retention up to seven years for some behavioral and risk data. Officials and advocates raised concerns about sourcing and eligibility decisions.Vendor disclosures are facts; public criticisms are attributed concerns, not regulatory findings.[S43, S44]
AiPriseCross-customer data governanceEAiPrise’s 2026 policy says it may keep fraud flags and tokenized prior-verification indicators across customers, as controller for that use; raw personal and biometric data are not shared across customers.Vendor-disclosed architecture; needs DPIA and contract scrutiny; not evidence of misconduct.[S45]
QuantexaThird-party incident exposureEQuantexa’s trust center says it reviewed the 2025 F5 incident and found no impact to its production environment or relevant subprocessors.Source states no impact; a supply-chain monitoring signal.[S46]
SocureContract / employment disputeBSocure and former executive Ori Snir filed related 2026 federal actions; a Delaware court denied Socure’s TRO and preliminary-injunction request and stayed the case pending the New Jersey action.Employment and contract dispute; not an identity-data security incident.[S47]
FaceTec / iProovIP litigationCFaceTec publicly announced patent-infringement litigation against iProov over liveness technology.Commercial IP dispute; allegations are not proof of copying.[S48]

Vendor-by-Vendor Findings

Every dated statement below names the kind of source behind it. Vendor responses and remediation are shown beside the allegation or incident they answer.

LSEG / Refinitiv World-Check

Data accuracy, PEP classification and de-risking consequences

  • Media report2017

    Thomson Reuters, then owner of World-Check, apologised in open court and agreed damages and costs after a profile placed Finsbury Park Mosque in a terrorism category. Contemporary reporting said the profile contributed to a bank-account closure. [S14]

  • Media report2026

    The Financial Times reported that Refinitiv agreed to delete standalone profiles of four children, including two claimants who challenged being treated as PEPs through political-family links. [S15]

  • Primary recordJun 2026

    A High Court judgment records Wenjun Tian’s claim seeking disclosure about the creation and update of his World-Check entry and alleging reputational and financial harm. The judgment concerned jurisdiction and privacy applications. [S17]

  • Media report2024

    An Ontario case summary records claims against Refinitiv in Miguna v. Sitel as dismissed. [S16]

  • Vendor statement2026

    LSEG states World-Check supports KYC, AML, PEP, sanctions, CDD and UBO workflows and holds 5.8M+ individuals and organisations. Scale makes correction procedures and explainability materially important. [S12]

Response, remediation and procedural contextThe 2026 settlement was not a general finding that the PEP methodology is unlawful. The Tian judgment is not a merits determination; other claims continue.

LexisNexis Risk Solutions

Large third-party-platform data breach disclosed in 2025

  • Primary recordMay 2025

    The Maine Attorney General notice records 364,333 affected people, an external-system hacking event dated 25 December 2024, and notification in May 2025. [S18]

  • Media reportMay 2025

    Reporting based on the vendor’s notices said data was acquired from GitHub, a third-party software-development platform, through a compromised company account, and could include names, contact details, SSNs, driver-licence numbers and dates of birth. [S19]

  • Diligence note2025

    Because the company sells identity, risk and fraud data, a breach of identity attributes is material to vendor diligence even when the affected system sits outside the core product environment. [S19]

Response, remediation and procedural contextLexisNexis said its own production networks were not compromised and it had no evidence of further misuse. [S19]

Sumsub

Support-environment compromise and third-party integration exposure

  • Vendor statementFeb 2026

    Sumsub disclosed that a July 2024 malicious attachment submitted through a third-party ticketing platform enabled limited unauthorized access to a support-related internal environment. Exposed data was primarily names, with a smaller subset including emails or phone numbers. [S20]

  • Vendor statementFeb 2026

    Sumsub said biometric data, identity-document images, bank or payment details and government ID information were not accessed, and that live verification, APIs and core production were unaffected. The event was detected retrospectively in a January 2026 review. [S20]

  • Vendor statementMar 2025

    A separate incident involving Merkur AG, per Sumsub, resulted from an external integrator’s authentication or API-token misconfiguration; Sumsub said its own systems were not compromised. [S21]

Response, remediation and procedural contextAll scope statements are the vendor’s own. The discovery delay (July 2024 to January 2026) is a procurement question about detection.

Persona

Biometric privacy litigation and a test-environment exposure report

  • Allegation2024

    In Washington v. Persona Identities, plaintiffs alleged Persona collected, analysed and stored facial-geometry scans in DoorDash verification flows in violation of Illinois BIPA. [S22]

  • Procedural outcome2024

    The Illinois Appellate Court reversed an order compelling arbitration, so the claims can proceed outside that arbitration theory. [S22]

  • Media report2026

    Malwarebytes reported that researchers found an exposed Persona testing frontend. [S23]

Response, remediation and procedural contextPersona clarified that the environment was isolated from production and that no personal data was exposed. [S23] The arbitration ruling is procedural, not a liability finding.

Entrust Identity Verification / Onfido

Biometric privacy litigation and settlement

  • Allegation2020 onward

    Sosa v. Onfido alleged that identity-verification technology collected facial biometric data without the notice and consent Illinois BIPA requires. [S24]

  • Procedural outcomeSettlement

    Public settlement summaries report a class settlement of approximately US$28.5M. [S24]

Response, remediation and procedural contextA settlement resolves litigation and is not an adjudicated admission of liability unless its terms say so.

Jumio

BIPA biometric-privacy litigation

  • Allegation2022 onward

    In Davis v. Jumio a plaintiff alleged Jumio extracted biometric identifiers and created facial templates during Binance identity verification without BIPA notice and consent. [S25]

  • Procedural outcomeFeb 2023

    The federal district court denied Jumio’s motion to dismiss. [S25]

Response, remediation and procedural contextThe ruling accepted pleaded facts for the motion; it was not a final liability determination.

AU10TIX

Legacy credential exposure with vendor-reported zero customer impact

  • Vendor statementJun 2024

    AU10TIX says inactive employee credentials tied to a decommissioned log-management tool surfaced in a public Telegram post. It says an independent forensic review found no production access, no data exposure and no customer impact. [S26]

  • Diligence note2024

    Even with a zero-impact conclusion, exposed credentials are a diligence signal: validate credential lifecycle, decommissioning, personal-device controls and monitoring. [S26]

Response, remediation and procedural contextThe no-impact conclusion is the vendor’s statement of an independent review; the review itself is not published in the cited source.

Veriff

Confirmed third-party identity-data breach notice plus consolidated litigation

  • Primary recordJan 2026

    A Total Wireless notice filed with Massachusetts states that an unauthorized party obtained personal information from Veriff systems: an image of the government-issued ID and possibly postal address and date of birth. Total Wireless said Veriff identified affected individuals on 10 December 2025. [S36]

  • AllegationJan 2026

    Reed, Stockton and McLaughlin actions were filed in the Southern District of New York against Veriff and Verizon Value / Total Wireless, alleging exposure of verification data. [S27, S37]

  • Procedural outcomeJun 2026

    The matters were consolidated and, in June 2026, stayed through 21 December 2026 while settlement discussions continue. [S37]

Response, remediation and procedural contextThe notice is stronger evidence for occurrence and data categories than the complaints. Negligence, deception, damages and responsibility remain unproven unless settlement terms or a judgment establish them.

NICE Actimize

Software dependency advisories, not a confirmed product breach

  • Vendor statementAdvisory page

    NICE’s advisory page said its cloud solutions were not impacted by Spring4Shell and Log4j, while some on-premise customers running Java 11 were advised to contact support about possible Spring4Shell exposure. [S28]

Response, remediation and procedural contextA patch and dependency-management signal relevant to on-premise stacks and SBOM governance; not evidence of compromise.

Chainalysis

Contested analytics methodology and litigation exposure

  • Procedural outcomeBitcoin Fog

    In United States v. Sterlingov the defense challenged Chainalysis analytics under Daubert; per Chainalysis’s account the federal court admitted the methodology as reliable. [S29]

  • Allegation2024–2026

    In Reca v. Flashdot / KuCoin, plaintiffs added Chainalysis and alleged RICO and aiding-and-abetting conversion. [S30]

  • Procedural outcomeJan 2026

    An order adopted recommendations granting dismissal. [S30]

Response, remediation and procedural contextThe outcomes favoured Chainalysis; the existence of litigation alone is not evidence of misconduct.

Trulioo

Historical regulator-identified privacy-governance and notification gaps

  • Primary record2018

    The Office of the Australian Information Commissioner assessed Trulioo’s handling of personal information through the Document Verification Service and identified one medium risk from gaps in supporting information-security documentation. [S34]

  • Primary record2018

    The OAIC considered Trulioo more than a passive intermediary because it retained some personal information, and found a low risk that notification practices could breach APP 5. [S34]

  • Primary record2018

    The same assessment recorded strong staff understanding, good access controls and no issue with data-breach response plans. [S34]

Response, remediation and procedural contextHistorical (2018); not evidence of a current deficiency.

Signzy

Confirmed 2024 security incident with incomplete public scope

  • Media reportDec 2024

    TechCrunch reported that Signzy confirmed a security incident and engaged a professional investigation firm; India’s CERT-In said it was aware and taking action. [S35]

  • Unconfirmed leadDec 2024

    Sources cited by TechCrunch said customer-related data appeared briefly on a cybercrime forum. Signzy did not confirm the extent of exfiltration in that report; this is an unconfirmed lead. [S35]

  • Media reportDec 2024

    PayU and ICICI Bank said they had no exposure; PayU described the event as information-stealer malware. [S35]

Response, remediation and procedural contextScope not fully disclosed. Customers should obtain tenant-specific confirmation, credential-revocation and forensic conclusions rather than assume no impact.

Incode Technologies

Biometric-privacy class action and monetary settlement

  • Allegation2023 onward

    Aspel v. Incode alleged identity-verification software collected Illinois residents’ facial geometry without notice and consent under BIPA; the docket shows a stay for settlement discussions. [S38]

  • Procedural outcomeSettlement

    Settlement materials describe a US$4 million settlement resolving the proposed class action. [S39]

Response, remediation and procedural contextNot a judicial finding that Incode violated BIPA.

iProov

Demonstrated deepfake and injection weakness in remote KYC workflows

  • Research / technicalMITRE ATLAS case

    iProov announced that its internal red team demonstrated a live face-swap injection attack able to evade mobile KYC facial recognition and passive and active liveness checks; the scenario was published in MITRE ATLAS. [S40]

  • Research / technicalMechanics

    The description used readily available face-swap tooling, OBS and an Android virtual-camera mechanism on a genuine, non-rooted device to replace the camera feed. [S40]

Response, remediation and procedural contextNot a breach of iProov. It shows that liveness plus face match is insufficient if the device and media path can be subverted.

FaceTec

BIPA claim dismissed; separate IP dispute with iProov

  • Vendor statementMay 2023

    FaceTec states that a BIPA case naming it was dismissed in May 2023 after plaintiffs’ counsel concluded its customer-managed architecture meant it did not itself collect end-user biometric data. [S41]

  • Allegation2024 onward

    FaceTec separately announced patent litigation against iProov relating to liveness technology. [S48]

Response, remediation and procedural contextThe dismissal account is vendor-sourced with no merits finding; the patent suit is a commercial dispute, not proof of infringement.

Middesk

Trade-secret litigation involving former personnel and a competitor

  • Primary record2025

    Middesk filed a Defend Trade Secrets Act action against Osiris Ratings / Baselayer and former personnel. The docket records temporary restraints and later consent orders limiting use, disclosure and retention of specified Middesk information. [S42]

Response, remediation and procedural contextThe orders state they are not an admission of fault or liability, and the disputes ended by stipulated dismissals. Primarily an insider-risk and IP-governance signal, not customer-data compromise. [S42]

Socure

Identity graph, biometric retention and public-sector scrutiny

  • Vendor statementOct 2026

    Socure’s privacy notice says it creates derived network and graph-based risk intelligence, processes facial landmarks and embeddings, and may retain behavioral data and risk insights for up to seven years, with identity documents and images generally kept for shorter periods. [S43]

  • AllegationJun 2026

    Congressional Record material reproducing reporting on New York government use records concerns from officials and advocates about data sourcing, transparency and automated identity systems for public services. These are attributed policy concerns, not findings of illegality. [S44]

  • Vendor statementTerms

    Socure’s DocV terms include individual arbitration and a class-action waiver where legally permissible, and state that facial geometry may be extracted during verification. [S49]

  • Procedural outcome2026

    In Socure v. Snir a Delaware court denied Socure’s TRO and preliminary-injunction request and stayed the case pending the New Jersey action. [S47]

Response, remediation and procedural contextVendor notices are facts about the vendor’s stated practice. The Snir matter is an employment and contract dispute, not a security incident.

AiPrise

Cross-customer fraud intelligence and verification-network governance

  • Vendor statementJul 2026

    AiPrise’s policy says that when a customer reports an entity as associated with fraud, it may retain the flag and make it available to other customers in de-identified form, and describes tokenized signals that an entity was previously verified. [S45]

  • Vendor statementJul 2026

    The policy states AiPrise is a controller for this aggregated network data though a processor for many verification flows, and that raw personal data and biometrics are not shared across customers. [S45]

Response, remediation and procedural contextVendor-disclosed architecture. False flags, entity-resolution errors and correction rights need contractual controls; not evidence of misconduct.

Quantexa

Supply-chain incident monitoring and negative-impact disclosure

  • Vendor statement2025

    Quantexa’s trust center says it reviewed the 2025 F5 incident, that F5 appliances were not used in its production environment, and that it had no indication affected subprocessors impacted its systems or data. [S46]

Response, remediation and procedural contextNot an adverse finding. Included because deep research must record exculpatory and remediation context as carefully as adverse material.

Vendors Without a High-Confidence Vendor-Specific Adverse Finding

For many of the 70 vendors this review found no comparably strong, vendor-specific public incident within the time available and the sources reviewed. This is not a clean bill of health: it means only that no finding met the inclusion threshold. Examples include ComplyAdvantage, Dow Jones Risk & Compliance, Moody’s KYC/Grid, Fenergo, Quantexa, Kharon, Quantifind, Sanction Scanner, ComplyCube, iDenfy, Ondato, Encompass, Sayari, Hawk AI, Napier AI, FullCircl, KYC360, SmartSearch, NameScan and MemberCheck.

A procurement-grade review should still request: recent SOC 2 / ISO reports, penetration-test summaries, subprocessor lists, data-residency details, breach-notification history, biometric-retention controls, model-validation evidence, false-positive and false-negative testing, sanctions-list update SLAs, UBO source provenance, business-continuity metrics, and contractual liability and indemnity terms.

70-Vendor Adverse-Research Triage

Where the research found a dossier, the row names it and links its sources. All other rows record a non-finding only.

VendorDeep-search statusInterpretationSources
ActicoNo comparably strong vendor-specific adverse finding added in this research passA public OSINT non-finding is not evidence of absence; request private assurance evidence.—
AU10TIXDeep dive: legacy credential eventSee the vendor dossier above and preserve procedural and remediation context.[S26]
ChainalysisDeep dive: methodology litigationSee the vendor dossier above and preserve procedural and remediation context.[S29, S30]
ComplyAdvantageNo comparably strong vendor-specific adverse finding added in this research passA public OSINT non-finding is not evidence of absence; request private assurance evidence.—
FaceTecDeep dive: dismissed BIPA claim and IP disputeSee the vendor dossier above and preserve procedural and remediation context.[S41, S48]
FenergoNo comparably strong vendor-specific adverse finding added in this research passA public OSINT non-finding is not evidence of absence; request private assurance evidence.—
IDfyNo comparably strong vendor-specific adverse finding added in this research passA public OSINT non-finding is not evidence of absence; request private assurance evidence.—
IDnowNo comparably strong vendor-specific adverse finding added in this research passA public OSINT non-finding is not evidence of absence; request private assurance evidence.—
IdentityMindNo comparably strong vendor-specific adverse finding added in this research passA public OSINT non-finding is not evidence of absence; request private assurance evidence.—
idwallNo comparably strong vendor-specific adverse finding added in this research passA public OSINT non-finding is not evidence of absence; request private assurance evidence.—
iProovDeep dive: KYC injection and deepfake attack researchSee the vendor dossier above and preserve procedural and remediation context.[S40]
JumioDeep dive: BIPA litigationSee the vendor dossier above and preserve procedural and remediation context.[S25]
KYCAIDNo comparably strong vendor-specific adverse finding added in this research passA public OSINT non-finding is not evidence of absence; request private assurance evidence.—
LexisNexis Risk SolutionsDeep dive: breach affecting 364k+ peopleSee the vendor dossier above and preserve procedural and remediation context.[S18, S19]
MiddeskDeep dive: trade-secret and insider disputeSee the vendor dossier above and preserve procedural and remediation context.[S42]
NotabeneNo comparably strong vendor-specific adverse finding added in this research passA public OSINT non-finding is not evidence of absence; request private assurance evidence.—
Entrust Identity Verification (Onfido)Deep dive: BIPA settlementSee the vendor dossier above and preserve procedural and remediation context.[S24]
PersonaDeep dive: BIPA litigation and test-frontend reportSee the vendor dossier above and preserve procedural and remediation context.[S22, S23]
LSEG World-CheckDeep dive: accuracy and PEP litigationSee the vendor dossier above and preserve procedural and remediation context.[S14, S15, S16, S17]
RegulaNo comparably strong vendor-specific adverse finding added in this research passA public OSINT non-finding is not evidence of absence; request private assurance evidence.—
SEONNo comparably strong vendor-specific adverse finding added in this research passA public OSINT non-finding is not evidence of absence; request private assurance evidence.—
FeedzaiNo comparably strong vendor-specific adverse finding added in this research passA public OSINT non-finding is not evidence of absence; request private assurance evidence.—
Shufti ProNo comparably strong vendor-specific adverse finding added in this research passA public OSINT non-finding is not evidence of absence; request private assurance evidence.—
SumsubDeep dive: support and integrator incidentsSee the vendor dossier above and preserve procedural and remediation context.[S20, S21]
TruliooDeep dive: regulator privacy assessmentSee the vendor dossier above and preserve procedural and remediation context.[S34]
TruoraNo comparably strong vendor-specific adverse finding added in this research passA public OSINT non-finding is not evidence of absence; request private assurance evidence.—
VeriffDeep dive: breach notice and consolidated litigationSee the vendor dossier above and preserve procedural and remediation context.[S36, S37]
VerifyVASPNo comparably strong vendor-specific adverse finding added in this research passA public OSINT non-finding is not evidence of absence; request private assurance evidence.—
IDMERITNo comparably strong vendor-specific adverse finding added in this research passA public OSINT non-finding is not evidence of absence; request private assurance evidence.—
VeridasNo comparably strong vendor-specific adverse finding added in this research passA public OSINT non-finding is not evidence of absence; request private assurance evidence.—
Unit21No comparably strong vendor-specific adverse finding added in this research passA public OSINT non-finding is not evidence of absence; request private assurance evidence.—
VerifyMyNo comparably strong vendor-specific adverse finding added in this research passA public OSINT non-finding is not evidence of absence; request private assurance evidence.—
FourthlineNo comparably strong vendor-specific adverse finding added in this research passA public OSINT non-finding is not evidence of absence; request private assurance evidence.—
SignicatNo comparably strong vendor-specific adverse finding added in this research passA public OSINT non-finding is not evidence of absence; request private assurance evidence.—
Napier AINo comparably strong vendor-specific adverse finding added in this research passA public OSINT non-finding is not evidence of absence; request private assurance evidence.—
AMLRangerNo comparably strong vendor-specific adverse finding added in this research passA public OSINT non-finding is not evidence of absence; request private assurance evidence.—
ComplyCubeNo comparably strong vendor-specific adverse finding added in this research passA public OSINT non-finding is not evidence of absence; request private assurance evidence.—
SardineNo comparably strong vendor-specific adverse finding added in this research passA public OSINT non-finding is not evidence of absence; request private assurance evidence.—
IncodeDeep dive: BIPA settlementSee the vendor dossier above and preserve procedural and remediation context.[S38, S39]
GBGNo comparably strong vendor-specific adverse finding added in this research passA public OSINT non-finding is not evidence of absence; request private assurance evidence.—
iDenfyNo comparably strong vendor-specific adverse finding added in this research passA public OSINT non-finding is not evidence of absence; request private assurance evidence.—
KYC HubNo comparably strong vendor-specific adverse finding added in this research passA public OSINT non-finding is not evidence of absence; request private assurance evidence.—
KYC360No comparably strong vendor-specific adverse finding added in this research passA public OSINT non-finding is not evidence of absence; request private assurance evidence.—
SmartSearchNo comparably strong vendor-specific adverse finding added in this research passA public OSINT non-finding is not evidence of absence; request private assurance evidence.—
NameScanNo comparably strong vendor-specific adverse finding added in this research passA public OSINT non-finding is not evidence of absence; request private assurance evidence.—
MemberCheckNo comparably strong vendor-specific adverse finding added in this research passA public OSINT non-finding is not evidence of absence; request private assurance evidence.—
RelyComplyNo comparably strong vendor-specific adverse finding added in this research passA public OSINT non-finding is not evidence of absence; request private assurance evidence.—
Sanction ScannerNo comparably strong vendor-specific adverse finding added in this research passA public OSINT non-finding is not evidence of absence; request private assurance evidence.—
QuantexaDeep dive: third-party incident monitoring, no-impact disclosureSee the vendor dossier above and preserve procedural and remediation context.[S46]
NICE ActimizeDeep dive: dependency and security advisoriesSee the vendor dossier above and preserve procedural and remediation context.[S28]
SignzyDeep dive: confirmed cyber incidentSee the vendor dossier above and preserve procedural and remediation context.[S35]
StriseNo comparably strong vendor-specific adverse finding added in this research passA public OSINT non-finding is not evidence of absence; request private assurance evidence.—
Castellum.AINo comparably strong vendor-specific adverse finding added in this research passA public OSINT non-finding is not evidence of absence; request private assurance evidence.—
ADVANCE.AINo comparably strong vendor-specific adverse finding added in this research passA public OSINT non-finding is not evidence of absence; request private assurance evidence.—
AiPriseDeep dive: cross-customer fraud and verification networkSee the vendor dossier above and preserve procedural and remediation context.[S45]
VespiaNo comparably strong vendor-specific adverse finding added in this research passA public OSINT non-finding is not evidence of absence; request private assurance evidence.—
FullCirclNo comparably strong vendor-specific adverse finding added in this research passA public OSINT non-finding is not evidence of absence; request private assurance evidence.—
Hawk AINo comparably strong vendor-specific adverse finding added in this research passA public OSINT non-finding is not evidence of absence; request private assurance evidence.—
VerifiedNo comparably strong vendor-specific adverse finding added in this research passA public OSINT non-finding is not evidence of absence; request private assurance evidence.—
HorusCheckNo comparably strong vendor-specific adverse finding added in this research passA public OSINT non-finding is not evidence of absence; request private assurance evidence.—
Dow Jones Risk & ComplianceNo comparably strong vendor-specific adverse finding added in this research passA public OSINT non-finding is not evidence of absence; request private assurance evidence.—
Moody’s KYC / GridNo comparably strong vendor-specific adverse finding added in this research passA public OSINT non-finding is not evidence of absence; request private assurance evidence.—
KharonNo comparably strong vendor-specific adverse finding added in this research passA public OSINT non-finding is not evidence of absence; request private assurance evidence.—
QuantifindNo comparably strong vendor-specific adverse finding added in this research passA public OSINT non-finding is not evidence of absence; request private assurance evidence.—
AlloyNo comparably strong vendor-specific adverse finding added in this research passA public OSINT non-finding is not evidence of absence; request private assurance evidence.—
SocureDeep dive: data use, public-sector scrutiny, employment disputeSee the vendor dossier above and preserve procedural and remediation context.[S43, S44, S47, S49]
OndatoNo comparably strong vendor-specific adverse finding added in this research passA public OSINT non-finding is not evidence of absence; request private assurance evidence.—
EncompassNo comparably strong vendor-specific adverse finding added in this research passA public OSINT non-finding is not evidence of absence; request private assurance evidence.—
SayariNo comparably strong vendor-specific adverse finding added in this research passA public OSINT non-finding is not evidence of absence; request private assurance evidence.—
ACI WorldwideNo comparably strong vendor-specific adverse finding added in this research passA public OSINT non-finding is not evidence of absence; request private assurance evidence.—

Structural Risks Often Missed

The dataset, not the interface, can be the risk

PEP, sanctions and adverse-media vendors can propagate a wrong identity association to many banks and fintechs. Correction latency, source provenance and re-screening after a correction matter as much as uptime. [S14, S15]

Processor and controller boundaries shift

Some vendors are processors for customer verification but controllers for fraud networks, model training, derived intelligence or cross-customer signals, which changes lawful-basis, transparency and rights obligations. [S43, S45]

Biometric liability can depend on technical possession

BIPA litigation turns on which entity captures, derives or stores facial geometry and whether the end user received notice and consent. “We are only a vendor” does not replace mapping the data flow. [S22, S24, S25, S41]

Liveness is vulnerable at the media pipeline

A sophisticated liveness model can still fail if an attacker replaces the camera stream first. Device integrity and injection detection are separate control layers. [S40]

Third-party support tooling is a recurring attack surface

Support desks, developer platforms, OAuth tokens and integrators can expose sensitive data without compromising the core verification engine. [S19, S20, S21]

Government deployment changes the harm model

An error that causes friction in commercial onboarding can be far more serious in benefits, immigration, policing or national-security screening, so public-sector contracts deserve stronger explainability and appeal standards. [S44]

“No breach found” is weak assurance

Private settlements, contractual confidentiality, undisclosed penetration-test findings and regulator interactions may never be indexed publicly. Never treat OSINT silence as a clean bill of health.

Use in Competitive Materials and Procurement

RuleApplication
Date every claimInclude the incident, filing, judgment, settlement or advisory year.
Separate allegation from findingUse “alleged”, “complaint filed”, “settlement”, “court held” or “vendor states” precisely.
Preserve remediation contextDo not imply a fixed vulnerability or contained incident is still active.
Use primary sources firstPrefer regulator notices, court records, vendor disclosures and government procurement over SEO comparison pages.
Do not infer “safe” from silenceNo located breach or CVE does not prove absence.
Re-check before publicationPricing, litigation, ownership and security posture can change quickly.
Avoid feature-for-feature price claims without scopeDifferent quotas, data rights, verification units, user counts and services make nominal prices non-equivalent.

Procurement questions triggered by the deep dive

  1. Provide a five-year incident register covering production, support, developer, identity-provider, SaaS and subprocessor events, including “no customer impact” incidents.
  2. Provide the latest independent penetration-test executive summary, remediation status and scope, and state whether mobile SDK, web SDK, API, admin console and support tooling were included.
  3. Explain every biometric artifact created (raw image or video, template or embedding, liveness score), where each is processed, retention, deletion trigger and whether model training uses them.
  4. Identify where the company acts as controller rather than processor, especially for fraud consortiums, cross-customer risk signals, graph intelligence, model improvement and device intelligence.
  5. Describe correction and appeal procedures for false PEP, sanctions, adverse-media, fraud or identity-risk classifications, including how corrections propagate to customers.
  6. Demonstrate defenses against virtual-camera injection, emulator or device compromise, face-swap deepfakes, replay, synthetic IDs, document injection and compromised SDK or API tokens.
  7. List all sources used for PEP, sanctions, adverse media and UBO, and state update latency, archival rules, source hierarchy, entity-resolution controls and human-review thresholds.
  8. Provide public-sector use cases and explain whether configurations differ for benefits, immigration, policing, intelligence or national-security contexts.
  9. Provide litigation and regulatory disclosure for material privacy, biometric, data-accuracy, breach, IP and employment or trade-secret matters for the last five years.
  10. Contractually define breach-notification SLA, forensic cooperation, evidence preservation, subprocessor notification, regulator coordination and customer audit rights.

Research conclusions

  • The market is splitting into three overlapping layers: identity proofing, risk-data and screening, and end-to-end AML / CLM orchestration. Buyers often need more than one vendor, or an orchestrator with several data providers.
  • UBO quality and CPF coverage are the two areas most likely to be overstated in generic “all-in-one KYC” marketing. Ask which registries and ownership datasets are primary, how indirect ownership is calculated, and whether proliferation and export-control networks are explicitly covered. [S13]
  • Public pricing is strongest among digital-native IDV and SMB AML vendors. Enterprise incumbents stay quote-driven, so procurement evidence and pilot pricing matter more than web list prices. [S8, S9, S12]
  • Biometric privacy is a recurring litigation theme for identity-verification providers; data provenance and classification accuracy are a recurring risk for screening databases; third-party SaaS and support tooling remain a meaningful breach path even where core production systems are unaffected. [S15, S22, S24, S25, S20]

Sources and Direct Links

All 49 sources are linked directly and labelled by source type. Four primary or vendor records [S20, S22, S26, S36] were checked live on 4 October 2026 (UTC). Other findings still require editorial verification; automated accessibility checks are not claim verification. Inclusion does not imply endorsement.

  1. S1Fortune Business Insights — Know Your Customer Software Market 2026–2034Market research
  2. S2Grand View Research — Identity Verification Market 2026–2033Market research
  3. S3Grand View Research — Anti-money Laundering MarketMarket research
  4. S4MarketsandMarkets — Anti-money Laundering Market 2025–2030Market research
  5. S5BeVerified — KYC & AML Provider Directory (60 tracked providers, Jul 2026 audit)Market research
  6. S6LSEG — Best sanctions screening software and companies in 2026Vendor statement
  7. S7LSEG — Best AML solution providers in 2026Vendor statement
  8. S8ComplyAdvantage — Starter Plan pricingVendor statement
  9. S9Sumsub — Pricing & PlansVendor statement
  10. S10ComplyCube — PricingVendor statement
  11. S11iDenfy — PricingVendor statement
  12. S12LSEG — World-Check dataset and coverageVendor statement
  13. S13Kharon — About / sanctions, export control and proliferation-network intelligenceVendor statement
  14. S14Matrix Chambers / Guardian — 2017 Finsbury Park Mosque World-Check apology and damagesMedia / secondary report
  15. S15Financial Times — Refinitiv to delete standalone profiles of politicians’ grandchildren after lawsuit (2026)Media / secondary report
  16. S16Ontario case summary — Miguna v. Sitel / Refinitiv (claims dismissed)Media / secondary report
  17. S17BAILII — Tian v Refinitiv Ltd [2026] EWHC 1418 (KB)Primary record
  18. S18Maine Attorney General — LexisNexis Risk Solutions breach noticePrimary record
  19. S19TechCrunch — LexisNexis Risk Solutions breach affecting 364,000+ peopleMedia / secondary report
  20. S20Sumsub — Security Incident Update (4 Feb 2026)Vendor statement
  21. S21Sumsub — Merkur AG integration incident statement (17 Mar 2025)Vendor statement
  22. S22Justia — Washington v. Persona Identities, 2024 IL App (3d) 240210Primary record
  23. S23Malwarebytes — Persona testing frontend exposure report and vendor clarification (2026)Media / secondary report
  24. S24Justia / settlement reporting — Sosa v. Onfido BIPA litigationPrimary record
  25. S25Justia — Davis v. Jumio Corporation, 1:2022cv00776, Doc. 32Primary record
  26. S26AU10TIX — Statement on legacy credential eventVendor statement
  27. S27DocketNexus — McLaughlin v. Veriff OU complaint (2026)Court filing (allegations)
  28. S28NICE Actimize — Security AdvisoriesVendor statement
  29. S29Chainalysis — Bitcoin Fog Daubert / methodology discussionVendor statement
  30. S30Justia — Reca v. Flashdot / Chainalysis dismissal order (2026)Primary record
  31. S31Ondato — Identity Verification pricingVendor statement
  32. S32Moody’s — Grid risk databaseVendor statement
  33. S33LSEG — World-Check privacy statementVendor statement
  34. S34Office of the Australian Information Commissioner — Handling personal information: TruliooPrimary record
  35. S35TechCrunch — Signzy confirms security incident (2 Dec 2024)Media / secondary report
  36. S36Massachusetts / Total Wireless — Notice of Data Breach concerning VeriffPrimary record
  37. S37Justia — Reed v. Veriff OU et al., 1:2026cv00465Primary record
  38. S38Justia — Aspel v. Incode Technologies, Inc., 1:2023cv17093Primary record
  39. S39Aspel v. Incode Technologies — Settlement AgreementPrimary record
  40. S40iProov — MITRE ATLAS publishes KYC identity-process attack caseVendor statement
  41. S41FaceTec — BIPA lawsuit dismissal announcementVendor statement
  42. S42Justia — Middesk, Inc. v. Osiris Ratings, Inc. et al., 1:2025cv02677Primary record
  43. S43Socure — Global Services Privacy Notice (effective 1 Oct 2026)Vendor statement
  44. S44U.S. Congressional Record — June 9, 2026, public concerns regarding Socure government use/data practicesPrimary record
  45. S45AiPrise — Privacy Policy (effective 1 Jul 2026)Vendor statement
  46. S46Quantexa — Trust & Policy Center / F5 incident noticeVendor statement
  47. S47Justia — Socure, Inc. v. Snir, 1:2026cv00674Primary record
  48. S48Justia — iProov LTD v. Software Colombia Servicios Informaticos SAS / FaceTec public IP-dispute contextPrimary record
  49. S49Socure — Terms of Use for Document VerificationVendor statement

Research Disclaimer

This is an OSINT and public-source research brief, not legal advice, a penetration test, a warranty of vendor security, or a statement that any vendor is presently compromised. Findings reflect public material reviewed through 1 October 2026. Court complaints, settlements, procedural rulings, vendor disclosures and third-party reports are identified with context. Market-size estimates use different taxonomies and are not additive. Refresh pricing before procurement or public competitive claims.

Before using any adverse finding externally, re-check the source on the publication date. Litigation can be dismissed, settled or amended; incident scopes can change; privacy policies and retention periods can change; and a source describing a sector-wide bypass must not be misrepresented as a compromise of a specific vendor.

Vendor risk

Need this review for your own suppliers?

Tell us which vendors matter and we will scope an open-source review with you.

  • Open sources cited
  • Factual, not speculative
  • Scoped with you