A theft of over 153 million U.S. and Canadian driver's licenses and subsequent incidents involving compromised customer data at fintech platform Revolut have highlighted vulnerabilities in how financial institutions manage Know Your Customer (KYC) compliance processes.
In the Revolut case, a hacker obtained sensitive customer information including passport copies and verification selfies belonging to 680 customers. The incident underscores a paradox: while KYC processes are designed to enhance financial system security by verifying customer identities, the current approach of storing copies of identification documents creates centralized repositories that attract criminal activity.
According to the Privacy Rights Clearinghouse, at least 343 million people were affected by U.S. data breaches in the first half of 2026 alone.
The Storage Problem
Current KYC implementations typically require financial institutions to collect, record, and retain physical copies of identity documents. This creates what industry observers describe as "honeypots" for criminals—multiple databases across identity verification providers, compliance vendors, and financial institutions, each storing separate copies of sensitive personal information.
Susie Violet Ward, director and co-founder of Bitcoin Policy UK, distinguishes between identity verification and identity surrender: "We need to stop treating identity verification and surrendering your identity as though they are the same thing." She argues that if a company only needs to confirm a customer is over 18, it should not automatically require full name, address, date of birth, and permanent identity document copies.
The Revolut breach also exposed regulatory vulnerabilities. The hacker sent requests from a spoofed Italian law enforcement address. According to Open Dialogue's Lyudmyla Kozlovska, EU anti-money laundering law imposes verification duties that leave banks with limited options to authenticate such requests, with potential fines in the millions for non-compliance.
Zero-Knowledge Proof Technology
Zero-knowledge proofs represent a mathematical approach to identity verification that could reduce document storage requirements. This technology allows a person to prove a fact—such as being over 18 or not appearing on a sanctions list—without revealing underlying personal details or sending copies of identity documents.
The European Union has begun incorporating zero-knowledge technology into its digital identity systems design, developing privacy-preserving age verification methods and supporting selective disclosure through its Digital Identity Wallet, enabling users to share only information necessary for specific transactions.
Evin McMullen, CEO and co-founder of Billions Network, which develops privacy-preserving digital identity solutions, states: "The technology works and is in production today, across thousands of applications and regulated institutions."
Regulatory and Practical Barriers
Despite the technology's availability, adoption in financial KYC remains limited. McMullen identifies the primary obstacles as regulatory interpretation and institutional practice rather than technological capability: "This is a governance and standards problem wearing a technology costume."
Compliance teams often default to retaining all identity documents due to ambiguity in regulatory guidance. The Financial Action Task Force (FATF) guidance explicitly allows digital identity systems for customer due diligence rather than requiring physical documents, and operates on a risk-based framework that permits individual countries to implement their own standards. However, many institutions collect and store everything because compliance auditors typically accept this approach.
Interoperability and standardization present additional challenges. Cryptographic proofs are only useful if relying parties can verify them without contacting the issuing institution, requiring shared standards across systems.
Remaining Concerns
Privacy advocate Efrat Fenigson notes that zero-knowledge proofs do not automatically eliminate all security concerns. The credential remains dependent on where it is bound. If a privacy-preserving proof is tied to an account in someone else's database, users remain dependent on centralized intermediaries.
Despite these limitations, the technology addresses a core vulnerability: institutions cannot lose data they never collected. Regulatory clarity explicitly permitting zero-knowledge proofs in financial compliance could incentivize wider adoption without requiring institutions to assume regulatory risk.


