Revolut ID thefts highlight KYC’s dangers: Here’s how to fix it
Source Entity
Cointelegraph by Christina Comben

Recent massive data breaches, including the theft of 153 million driver's licenses and a targeted attack on Revolut, highlight the critical vulnerabilities in current KYC document storage. Experts advocate for the adoption of zero-knowledge technology to verify identities without the need to retain sensitive personal documents.
The Crisis of Centralized Identity Storage
The recent breach involving over 153 million US and Canadian driver’s licenses, which subsequently surfaced on the dark web marketplace 'Nexus', represents a systemic failure in how modern financial and digital institutions handle user verification. When identity providers act as centralized honeypots for sensitive information, they become inevitable targets for bad actors. The scale of this leak proves that storing static copies of government-issued IDs creates a permanent liability for both the consumer and the service provider.
The Revolut Incident and the Dangers of KYC
The situation was further exacerbated by a sophisticated breach at fintech giant Revolut. In this instance, hackers utilized social engineering and technical manipulation to trick the company into surrendering sensitive customer data, including passports and biometric verification selfies. By 'drip-feeding' this stolen information, the attackers demonstrate the long-term danger of these breaches; once data is exfiltrated, it remains a persistent threat that can be used for identity theft, fraud, and unauthorized account access for years to come.
Why Traditional KYC is Obsolete
Current Know Your Customer (KYC) regulations often force companies to collect and store physical or digital copies of identity documents to satisfy compliance requirements. However, this 'collect everything' approach is fundamentally flawed in an era of advanced cybercrime. By keeping these documents on file, companies are essentially building a roadmap for identity thieves, as these databases become the primary sources for dark web identity services like Nexus.
The Zero-Knowledge Solution
Zero-knowledge technology offers a transformative path forward. It allows a service provider to verify that a user is who they claim to be—or that they meet specific criteria, such as being over 18—without ever needing to see or store the actual identity document. By moving to a model where the verification result is cryptographically signed rather than stored as a raw document, the risk of mass data exfiltration is virtually eliminated.
Barriers to Industry Adoption
If the technology exists, why has it not become the standard? The transition requires a shift in both regulatory frameworks and corporate architecture. Many companies are hesitant to pivot due to the initial costs of implementation and the rigid, often outdated, nature of current financial compliance mandates. Furthermore, legacy systems are deeply integrated with traditional document-upload workflows, making a total overhaul a complex logistical challenge.
Future Trends and Security Implications
As identity theft continues to rise, the pressure on regulators to modernize compliance standards will likely intensify. We are moving toward a future where privacy-preserving technologies are not just a luxury, but a necessity for business continuity. Companies that fail to adopt decentralized or zero-knowledge verification methods will increasingly find themselves at a competitive disadvantage, both in terms of cybersecurity resilience and consumer trust.
Conclusion
The era of storing massive databases of customer identity documents must come to an end. The recent breaches at Revolut and the massive license leaks serve as a final wake-up call. By embracing zero-knowledge proofs, the industry can maintain compliance while ensuring that the safest place for a customer’s identity document remains with the customer alone.