Biometric data leaked: what it means and what to do

Risk level: critical. Can you change it: no. Found in 1 breaches in this directory.

What this data is

Measurements of your body used to recognise you: fingerprint templates, face geometry, iris scans, voice prints and sometimes palm or vein patterns. Workplaces, gyms, banks and identity verification services collect them.

The risk on its own

Biometrics are the one credential you can never rotate, so the leak is permanent in a way a password leak is not. Most systems store a mathematical template rather than an image, and a template is harder to turn back into a usable fingerprint or face. The harm grows over time as matching tools improve and more services accept the same body parts as a login.

The risk combined with other data

Attached to your name and ID number, a face or fingerprint record ties your body to your legal identity in a file you do not control. That supports attempts to pass the selfie and document checks used for remote account opening, and lets anyone holding the data match you in photos or footage. Where the breach also held scans of your ID, the pair is the exact kit those checks rely on.

How criminals use it

  • A fraudster pairs your leaked enrolment selfies with a scan of your licence to attempt an online identity check for a new bank or crypto account in your name.
  • A leaked voice print is used against a phone banking line that recognises customers by voice.
  • Your face data is matched against social media photos to identify you in pictures where you were never named.
  • Enrolment video from the breach is used to build a deepfake that tries to pass a live video verification call.

What to do now

  1. Ask the organisation in writing exactly what was stored, raw images, templates or both, and whether ID document scans were held alongside.
  2. Where a bank or telco uses your voice or face as a login, ask for it to be removed and replaced with a PIN plus an authenticator app or passkey.
  3. Prefer passkeys and on device unlock, where the template stays in your phone's secure chip, over services that keep your face or fingerprint on their servers.
  4. Place a credit freeze or fraud alert so an identity check passed with your face still cannot open credit in your name.
  5. Request deletion using the law that covers you: GDPR in the UK and Europe, the Biometric Information Privacy Act in Illinois, and the Privacy Act in Australia all treat biometrics as sensitive.
  6. Agree a family code word, because a familiar face or voice on a call is no longer proof of who is there.

Frequently asked questions

Can I change my fingerprints or face after a breach?

No, which is why this class is rated critical. The defence moves to everything around the biometric: a second factor, a credit freeze, and asking services to stop relying on it alone.

Does Face ID or fingerprint unlock on my phone put me at risk?

Not from this kind of breach. Phone unlock keeps the template inside the device and does not hand it to app makers. The risk comes from services that store biometrics on their own servers.

Can someone rebuild my fingerprint from a leaked template?

It is difficult, and good systems are designed to make it so. It is not impossible, and templates can still be used to match and track you, so treat the leak as permanent rather than harmless.

Breaches that exposed this data

  • COMELEC (Philippines Voters): 2016-03-27, 229K accounts, Biometric data, Dates of birth, Email addresses, Family members' names, Genders, Job titles

Tools that help

Related guides

Breach data sourced from Have I Been Pwned, used under CC BY 4.0. Additional breach metadata provided by XposedOrNot. DataExposed is an independent service and is not affiliated with or endorsed by either.