{
  "id": 7795805,
  "title": "Revolut ID thefts highlight KYC’s dangers: Here’s how to fix it",
  "url": "https://urgent.news/2026/09/16/revolut-id-thefts-highlight-kycs-dangers-heres-how-to-fix-it",
  "topic": "finance",
  "section": "Finance & Markets",
  "published": "2026-09-16T13:30:00.000Z",
  "source": {
    "name": "Cointelegraph",
    "slug": "cointelegraph",
    "url": "https://cointelegraph.com/magazine/revolut-id-thefts-highlight-kycs-dangers-heres-how-to-fix-it"
  },
  "original_language": "en",
  "account": "Identity theft has become a growing concern, particularly with the recent leak of over 153 million US and Canadian driver's licenses. This data, believed to have originated from an identity verification provider, surfaced on a dark web service known as Nexus, alongside millions of other stolen personal records. The issue was further highlighted when fintech company Revolut fell victim to a hacker who tricked the company into sharing sensitive customer data, including passports and verification images.\n\nThe irony of this situation is stark, as Know Your Customer (KYC) processes are intended to ensure financial systems' security by confirming customer identities and preventing illicit activities. However, traditional KYC methods often require companies to store vast amounts of sensitive information, creating attractive targets for cybercriminals. In the first half of 2026 alone, US data breaches affected at least 343 million individuals, as reported by the Privacy Rights Clearinghouse.\n\nThe core problem lies in the fact that most KYC systems operate under the assumption that financial institutions must retain customers' identity documents, such as passports or driver's licenses, and store records of the verification checks. This approach has led to a proliferation of identity providers, databases, and compliance systems, each storing separate copies of individuals' KYC data. Every additional copy of personal information increases potential vulnerabilities, and cybercriminals are continually devising new methods to exploit these weaknesses.\n\nIn the case of Revolut, the hacker sent emails to a legitimate Italian law enforcement address, requesting KYC data. The company complied, as per EU laws, which impose no verification duty on banks and do not provide a clear mechanism for verifying the identity of the requesting entity. As a result, the hacker proceeded to leak the personal data of 680 Revolut customers in an attempt to extort a 10,000 Bitcoin ransom.\n\nTo address this issue, zero-knowledge proofs (ZKPs) offer a promising solution. ZKPs are mathematical proofs that demonstrate the validity of information without revealing the underlying data. For example, a user could generate a proof showing that their driver's license indicates they are over 18 years old without sharing their birth date or picture of the license itself. Companies such as Billions Network are developing privacy-preserving digital identity solutions and ZK technologies to mitigate these risks.\n\nHowever, the widespread adoption of ZKPs in financial KYC is hindered by regulatory challenges, misunderstandings about data storage, and lack of interoperability between systems. Compliance teams often conflate the act of verifying an ID with the necessity of storing it, leading to over-collection of personal information. Additionally, the integration of cryptographic proofs into existing compliance stacks requires changes in governance and standards.\n\nThe European Union is already incorporating ZK technology into its digital identity and age verification systems, demonstrating the potential for privacy-preserving age verification that allows users to prove their age without disclosing their full identity or exact date of birth. As the technology matures and regulatory frameworks adapt, it may be possible to significantly reduce the risks associated with identity theft and improve the overall security of financial systems.",
  "summary": "Zero-knowledge technology could let companies verify who you are without storing your identity documents. So why isn’t it already standard practice?",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}