Urgent.News

What's breaking now, across thousands of outlets.

Finance & Markets

Revolut ID thefts highlight KYC’s dangers: Here’s how to fix it

Zero-knowledge technology could let companies verify who you are without storing your identity documents. So why isn’t it already standard practice?

Revolut ID thefts highlight KYC’s dangers: Here’s how to fix it

Identity theft has become a growing concern, particularly with the recent leak of over 153 million US and Canadian driver's licenses. This data, believed to have originated from an identity verification provider, surfaced on a dark web service known as Nexus, alongside millions of other stolen personal records. The issue was further highlighted when fintech company Revolut fell victim to a hacker who tricked the company into sharing sensitive customer data, including passports and verification images.

The irony of this situation is stark, as Know Your Customer (KYC) processes are intended to ensure financial systems' security by confirming customer identities and preventing illicit activities. However, traditional KYC methods often require companies to store vast amounts of sensitive information, creating attractive targets for cybercriminals. In the first half of 2026 alone, US data breaches affected at least 343 million individuals, as reported by the Privacy Rights Clearinghouse.

The core problem lies in the fact that most KYC systems operate under the assumption that financial institutions must retain customers' identity documents, such as passports or driver's licenses, and store records of the verification checks. This approach has led to a proliferation of identity providers, databases, and compliance systems, each storing separate copies of individuals' KYC data.

Every additional copy of personal information increases potential vulnerabilities, and cybercriminals are continually devising new methods to exploit these weaknesses.

In the case of Revolut, the hacker sent emails to a legitimate Italian law enforcement address, requesting KYC data. The company complied, as per EU laws, which impose no verification duty on banks and do not provide a clear mechanism for verifying the identity of the requesting entity. As a result, the hacker proceeded to leak the personal data of 680 Revolut customers in an attempt to extort a 10,000 Bitcoin ransom.

To address this issue, zero-knowledge proofs (ZKPs) offer a promising solution. ZKPs are mathematical proofs that demonstrate the validity of information without revealing the underlying data. For example, a user could generate a proof showing that their driver's license indicates they are over 18 years old without sharing their birth date or picture of the license itself. Companies such as Billions Network are developing privacy-preserving digital identity solutions and ZK technologies to mitigate these risks.

However, the widespread adoption of ZKPs in financial KYC is hindered by regulatory challenges, misunderstandings about data storage, and lack of interoperability between systems. Compliance teams often conflate the act of verifying an ID with the necessity of storing it, leading to over-collection of personal information. Additionally, the integration of cryptographic proofs into existing compliance stacks requires changes in governance and standards.

The European Union is already incorporating ZK technology into its digital identity and age verification systems, demonstrating the potential for privacy-preserving age verification that allows users to prove their age without disclosing their full identity or exact date of birth. As the technology matures and regulatory frameworks adapt, it may be possible to significantly reduce the risks associated with identity theft and improve the overall security of financial systems.

Written by urgent.news from Cointelegraph's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at cointelegraph.com →

More in Finance & Markets

More from Wednesday 16 September →