Firm that verifies mugshots for ChatGPT and Roblox feeds US surveillance apparatus with 269 distinct checks
Every selfie or ID you upload to ChatGPT, Roblox, LinkedIn, and many other sites for verification is handled by a San Francisco firm called Persona. A massive leak has exposed its other side โ a platform capable of feeding the US government with 269 sophisticated surveillance checks on millions of users worldwide.
A security researcher at vmfunc.re, who goes by the alias Celeste, discovered exposed infrastructure belonging to Persona, the identity verification company used by ChatGPT and other major services.
Persona also runs a platform authorized by FedRAMP (Federal Risk and Authorization Management Program), offering federal agencies โto verify usersโ identitiesโ in over 200 countries, detect fraud, and ensure regulatory compliance.โ
Celeste claims they obtained the entire dashboard codebase from the ONYX government deployment โapp.onyx.withpersona-gov.com,โ which was left unprotected and publicly exposed.