Wednesday, September 16, 2026
HomeCrypto NewsRevolut ID Thefts Highlight KYC’s Dangers: Here’s How To Fix It

Revolut ID Thefts Highlight KYC’s Dangers: Here’s How To Fix It

The massive theft of more than 153 million US and Canadian driver’s licenses earlier this month should make one thing abundantly clear: the safest place for a copy of your driver’s license is nowhere at all.

The leaked IDs, which appear to have come from an identity verification provider, ended up on a dark web identity service dubbed Nexus, alongside millions of other stolen identity and travel documents.

The danger was underscored this week after fintech Revolut revealed it had been tricked by a hacker into handing over reams of sensitive customer data, including copies of passports and verification selfies. The hacker is now drip feeding the identification documents of 680 customers onto the web in an attempt to secure a 10,000 Bitcoin ransom.

The irony is hard to miss: Know Your Customer (KYC) processes are designed to make financial systems safer by establishing who customers are and making sure they’re not up to nefarious deeds.

But the way KYC is usually implemented requires companies to store vast quantities of sensitive information, which creates valuable honeypots for criminals.

And the problem is getting harder to ignore. In the first half of 2026 alone, US data breaches affected at least 343 million people, according to the Privacy Rights Clearinghouse. Even more frustratingly, it’s already possible to verify an individual’s identity without storing their identity documents using zero knowledge proofs:

Efrat Fenigson, host of You’re The Voice podcast, writes and speaks extensively about privacy and KYC. She tells Magazine:

“When regulators keep mandating a model that guarantees this outcome — while the technology to verify without storing already exists — it raises a red flag. It implies there is a lack of rational thinking and real will to solve problems.”

So how many more of these leaks will it take before that will starts to bend?

KYC was built to collect your identity, not just verify it

KYC systems today have pretty much evolved around the assumption that institutions should see customers’ passports or driver’s licenses, record the relevant information and then store evidence of the check.

343 million people have already been affected by US data breaches in 2026. Source: Privacy Rights Clearinghouse.

But there’s an obvious problem with that approach: it has created a vast ecosystem of identity providers, databases, vendors and compliance systems that all store separate treasure troves of your individual KYC data. Every additional copy of your data creates another potential point of failure — and hackers are increasingly creative about devising ways to access it.

In the Revolut case, the hacker sent emails requesting the KYC data from a legitimate Italian law enforcement address. Lyudmyla Kozlovska, Open Dialogue president said on X that EU laws meant Revolut had no other option but to comply.

“EU AML law imposes no verification duty on the bank and provides no meaningful mechanism to check who is really behind an authenticated state request. Refusal to answer carries fines in the millions. In practice, verification is impossible.”

Related: 200,000 fake AI ‘victims’ deployed to scam bait online fraudsters

Susie Violet Ward, director and co-founder of Bitcoin Policy UK, warns the real issue is in storing ID data unnecessarily:

“We need to stop treating identity verification and surrendering your identity as though they are the same thing.”

If a company only needs to know that someone is over 18, she argues it should not automatically need additional details like your full name, address, exact date of birth, and a permanent copy of the relevant identity documents:

“The irony is that KYC is designed to make systems safer, but the way we currently implement it can create an entirely different security problem. You can reset a password after a breach, but you cannot reset your identity in the same way.”

The technology to stop hoarding IDs already exists

For crypto proponents, the obvious solution is to use zero knowledge proofs. That’s a mathematical proof that demonstrates something is true without revealing the details. For example, you can use an phone app to generate a proof confirming your drivers license says you are older than 18, without sending through your birth date, or a picture of the license itself.

Zcash founder Zooko Wilcox provides a useful explanation of ZK tech in this video.

A useful explanation of ZK tech. Source: Crypto Fireside

Evin McMullen, chief executive and co-founder of Billions Network, which develops privacy-preserving digital identity and ZK solutions, tells Magazine:

“The technology works and is in production today, across thousands of applications and regulated institutions. What holds it back is that the entire compliance stack was built around collecting and storing copies of documents.”

McMullen says the barrier was “never the technology,” but the rules, incentives and infrastructure built around it:

“This is a governance…

cointelegraph.com

RELATED ARTICLES

Most Popular

Recent Comments