Revolut ID thefts highlight KYC’s dangers: Here’s how to fix it

A recent wave of identity breaches — including the theft of over 153 million US and Canadian driver’s licenses and a hacker attack that forced Revolut to disclose customer passports and verification selfies — has exposed the risks of current KYC practices that require firms to store copies of identity documents. Experts say zero-knowledge cryptography can prove attributes like age or identity without retaining underlying documents, but regulatory, governance and interoperability hurdles have kept it from widespread use.

By AI NewsroomPublished about 1 hour agoUpdated about 1 hour ago0 views
Revolut ID thefts highlight KYC’s dangers: Here’s how to fix it

Why It Matters

KYC is meant to secure financial systems, yet the common practice of hoarding identity files creates lucrative targets that can never be 'reset' after a breach. Wider adoption of privacy-preserving verification could reduce such systemic risk, but that shift depends on rules and compliance practices changing as much as technology.

Key Facts

  • Driver’s licenses stolen: More than 153 million US and Canadian driver’s licenses were leaked earlier this month.
  • Where leaked IDs surfaced: The stolen IDs appeared on a dark web identity service called Nexus.
  • Revolut incident: A hacker tricked Revolut into releasing passports and verification selfies; identification documents for 680 customers have been published incrementally amid a 10,000 Bitcoin ransom demand.
  • US breaches in 1H 2026: At least 343 million people in the US were affected by data breaches in the first half of 2026 (Privacy Rights Clearinghouse).
  • Zero-knowledge adoption claim: Evin McMullen says zero-knowledge technology is in production today across thousands of applications and regulated institutions.

This month’s massive identity leaks — capped by the exposure of more than 153 million US and Canadian driver’s licenses and a separate attack that led to Revolut disclosing customers’ passports and verification selfies — have renewed scrutiny of how companies gather and hold personal identity data. The stolen documents were posted on a dark web service known as Nexus, and in the Revolut case a hacker has been publishing files for 680 customers while demanding a 10,000 Bitcoin ransom.

Current KYC workflows typically ask firms to inspect and retain copies of passports, driver’s licenses and other records as proof of identity. That model has created an ecosystem of identity holders and vendors, each keeping its own archive of sensitive material. Every duplicate becomes a fresh point of failure, and recent incidents show how social engineering and legal pressure can be used to extract those holdings — a problem highlighted by critics who say regulators and compliance regimes offer too few practical checks before institutions hand over data.

Privacy-focused technologists point to zero-knowledge proofs as an alternative. These cryptographic techniques let someone prove a fact — for example, that they are over 18 — without revealing the underlying personal data or images. Proponents note the technology is already in use: one industry founder and a privacy-focused identity company executive say ZK systems are live in many applications and could replace the need to store full identity documents if the surrounding rules and infrastructure were updated.

Adoption barriers are largely non-technical, according to those working in the field. They cite regulatory interpretations that equate seeing an ID with the need to retain it, compliance teams that over-collect to avoid fines, and interoperability gaps that make cryptographic proofs less useful unless relying parties can verify them without complex back-and-forth. The European Union is moving toward privacy-preserving designs — including selective disclosure and age verification in its Digital Identity framework — but industry experts say broader change will require updates to governance, standards and compliance practices before zero-knowledge approaches become commonplace.

Keep Reading