How Zero-Knowledge Technology Could Prevent KYC Data Breaches Like Revolut's

How zero-knowledge technology could prevent KYC data breaches like Revolut's

Technology enabling identity verification without document storage already exists. Yet why do companies continue defaulting to traditional KYC practices?

When more than 153 million driver's licenses from the United States and Canada were stolen earlier this month, it sent a stark message: the most secure location for a duplicate of your driver's license is actually no location whatsoever.

The compromised identification documents, which reportedly originated from a provider specializing in identity verification, surfaced on Nexus, a dark web service trafficking in stolen identities, joining countless other pilfered identity and travel credentials.

This week brought additional urgency to the issue when financial technology company Revolut disclosed that a cybercriminal had successfully deceived the company into releasing substantial volumes of confidential customer information, including passport copies and verification selfie images. The perpetrator is currently releasing identification documents belonging to 680 customers incrementally across the internet while demanding 10,000 Bitcoin as ransom.

The contradiction couldn't be more apparent: Know Your Customer (KYC) protocols exist to enhance security in financial systems by confirming customer identities and preventing illicit activities.

Yet conventional KYC implementation demands that organizations maintain enormous databases filled with confidential data, effectively creating attractive targets for cybercriminals.

And this challenge is becoming increasingly difficult to overlook. During just the initial six months of 2026, data breaches in the United States impacted no fewer than 343 million individuals, based on Privacy Rights Clearinghouse data. What makes this even more exasperating is that technology already exists to authenticate someone's identity without retaining their identification documents through zero knowledge proofs:

"When regulators keep mandating a model that guarantees this outcome — while the technology to verify without storing already exists — it raises a red flag. It implies there is a lack of rational thinking and real will to solve problems."

The question remains: how many additional breaches must occur before meaningful change begins to happen?

Traditional KYC systems were designed to gather identity information, not merely confirm it

Contemporary KYC frameworks have largely developed based on the premise that financial institutions must examine customers' passports or driver's licenses, document pertinent details and subsequently maintain proof of the verification process.

US data breaches in 2026 have impacted 343 million individuals so far. Source: Privacy Rights Clearinghouse.

However, this methodology presents a clear vulnerability: it has generated an extensive network of identity verification providers, storage systems, third-party vendors and compliance platforms that each maintain distinct repositories of your personal KYC information. Each additional duplicate of your information represents another vulnerability — and cybercriminals are becoming progressively more sophisticated in their methods to exploit it.

In Revolut's situation, the cybercriminal transmitted email requests for the KYC information from an authentic Italian law enforcement email address. Lyudmyla Kozlovska, Open Dialogue president said on X that EU laws meant Revolut had no other option but to comply.

"EU AML law imposes no verification duty on the bank and provides no meaningful mechanism to check who is really behind an authenticated state request. Refusal to answer carries fines in the millions. In practice, verification is impossible."

Susie Violet Ward, director and co-founder of Bitcoin Policy UK, warns the real issue is in storing ID data unnecessarily:

"We need to stop treating identity verification and surrendering your identity as though they are the same thing."

When a business simply requires confirmation that an individual has reached 18 years of age, she contends it shouldn't automatically demand extra information such as complete legal names, residential addresses, precise birthdates, and permanent duplicates of the supporting identification documents:

"The irony is that KYC is designed to make systems safer, but the way we currently implement it can create an entirely different security problem. You can reset a password after a breach, but you cannot reset your identity in the same way."

Solutions for eliminating ID hoarding are already available

For those in the cryptocurrency space, zero knowledge proofs represent the logical answer. This involves a cryptographic proof that validates truth without disclosing underlying information. As an illustration, a mobile application can generate proof confirming a driver's license indicates someone exceeds 18 years of age, eliminating the need to transmit the actual birthdate or a photograph of the license document.

Zcash founder Zooko Wilcox provides a useful explanation of ZK tech in this video.

An informative overview of ZK technology. Source: Crypto Fireside
"The technology works and is in production today, across thousands of applications and regulated institutions. What holds it back is that the entire compliance stack was built around collecting and storing copies of documents."

McMullen says the barrier was "never the technology," but the rules, incentives and infrastructure built around it:

"This is a governance and standards problem wearing a technology costume."

What prevents widespread adoption if the technology is functional?

The European Union is already incorporating ZK technology into its digital identity and age verification systems design, developing privacy-preserving age verification that allows users to prove their age without revealing their full identity or exact date of birth.

Its Digital Identity Wallet also supports "selective disclosure," so users reveal only the information needed for a particular transaction.

The pressing question is: why hasn't this been implemented more broadly for financial sector KYC requirements?

According to McMullen, "regulation and understanding" are the biggest obstacles to adoption:

"The most common blocker is that compliance teams conflate 'we saw the ID' with 'we must keep the ID,' so they over-collect to be safe."

She identifies interoperability as an additional challenge, noting that cryptographic proofs only provide value "if the party relying on it can check it without calling back to whoever issued it." This necessitates establishing universal standards, which presents significant practical difficulties.

Zero-knowledge technology isn't a complete solution to KYC challenges

An important consideration exists: substituting an identification document with a zero-knowledge proof doesn't automatically resolve all privacy or security concerns.

Fenigson points out that what a ZK credential remains tied to is equally important:

"The incentives point toward control, not privacy. Zero-knowledge proofs let someone prove a fact, like being over 18 or not on a sanctions list [...] What's missing is what that proof gets bound to. Right now it's usually bound to an account inside someone else's database."
Selective disclosure functionality is supported by the EU's Digital Identity Wallet. Source: European Commission

Ultimately, the critical factor is determining who maintains authority over the credential. When an individual creates a privacy-protecting proof that gets linked to an account within another entity's database, dependency on a centralized authority persists.

Regulatory requirements are more ambiguous than commonly assumed

Frequently, regulations don't explicitly mandate ID data retention — it's become standard practice simply because that's how it's traditionally been handled.

The Financial Action Task Force (FATF)'s guidance explicitly considers how digital ID systems can be used to conduct customer due diligence, rather than requiring institutions to rely on physical identity documents.

FATF's recommendations also operate as a risk-based framework, leaving individual countries to implement standards through their own legal and regulatory systems.

"In many regimes, the rule is that you must verify identity and retain records of that verification, not that you must keep the raw document image forever," McMullen says.

This suggests that a cryptographically authenticated attestation accompanied by documentation demonstrating the appropriate verification was conducted might satisfy compliance requirements without generating another perpetual duplicate of the identification document.

However, due to the "ambiguous" nature of the guidance, McMullen indicates institutions simply choose to preserve everything because their compliance departments understand that auditors and regulators will find it acceptable.

Put differently, even when regulations technically accommodate alternative methodologies, organizations remain hesitant to pioneer untested approaches, as Ward explains:

"There is an instinct in regulation that more information means more control and therefore more safety."

Significant change appears unlikely unless regulations are explicitly modified to accommodate zero-knowledge proofs. While no approach is flawless, ZK technology at minimum eliminates the requirement to gather and store such extensive quantities of confidential data. As McMullen says:

"You cannot lose what you never held."
← Back to Blog