Home Blockchain SKN | Revolut Data Breach Renews Debate Over the Risks of Traditional KYC
Blockchain

SKN | Revolut Data Breach Renews Debate Over the Risks of Traditional KYC

Share
Share
Key Points:
  • Recent identity-data breaches have highlighted the security risks created when financial institutions and verification providers retain copies of passports, driver’s licenses and other sensitive documents.
  • Privacy and digital-identity advocates argue that zero-knowledge technology can allow companies to verify specific facts about customers without receiving or storing their underlying identity documents.
  • Adoption remains limited by regulatory uncertainty, fragmented standards and compliance practices that often favor retaining documents even when the rules may only require proof that verification was completed.

KYC Creates a New Security Challenge

Know Your Customer procedures were designed to strengthen financial systems by allowing institutions to establish who their customers are and assess risks such as fraud, money laundering and sanctions violations.

Yet the traditional implementation of KYC can create another security vulnerability: the accumulation of highly sensitive identity records.

Recent incidents have brought that issue into sharper focus. More than 153 million US and Canadian driver’s licenses were reportedly exposed earlier this month, with the stolen documents appearing on a dark-web identity service alongside other compromised identification and travel documents.

Revolut also disclosed a separate incident in which a hacker allegedly obtained sensitive customer information, including passport copies and verification selfies. The attacker has reportedly threatened to release documents belonging to hundreds of customers while demanding a ransom.

The incidents illustrate the dilemma at the heart of conventional KYC: information collected to establish identity can become valuable data for attackers.

The Problem With Storing Copies of Identity Documents

Modern KYC infrastructure involves financial institutions, identity-verification companies, technology vendors and other service providers. Each may hold some portion of a customer’s identifying information.

Every additional database or retained document creates another potential target.

Efrat Fenigson, who focuses on privacy and KYC issues, argues that the problem stems partly from a regulatory model that encourages organizations to collect information rather than simply verify the required facts.

Susie Violet Ward, director and co-founder of Bitcoin Policy UK, similarly argues that identity verification should not automatically mean surrendering and permanently storing a person’s identity documents.

The distinction is particularly relevant when an institution only needs to establish a limited fact. For example, verifying that a customer is over 18 does not necessarily require retaining their full name, address, date of birth and a permanent copy of their identification document.

Unlike a password, however, identity information cannot simply be replaced after a breach.

Zero-Knowledge Technology Offers an Alternative

Zero-knowledge proofs provide a potential alternative by allowing one party to demonstrate that a statement is true without revealing the underlying information.

In an identity context, a digital credential could potentially prove that a person is above a required age or satisfies a particular eligibility condition without transmitting the complete identity document to the organization performing the check.

Evin McMullen, CEO and co-founder of Billions Network, which develops privacy-preserving digital identity infrastructure, argues that the technology itself is no longer the primary obstacle.

According to McMullen, zero-knowledge technology is already being used across applications and regulated institutions. The challenge is that compliance infrastructure was built around collecting and retaining documentation.

She describes the problem as one involving governance, standards and incentives rather than simply technology.

Europe Is Already Exploring Privacy-Preserving Verification

The European Union has incorporated privacy-preserving approaches into the design of its digital identity infrastructure, including systems for age verification and selective disclosure.

Selective disclosure allows users to provide only the information required for a particular transaction rather than exposing their entire identity profile.

The approach could have implications for financial services, where different transactions require different levels of customer information.

However, wider adoption requires organizations to be able to independently verify digital credentials and cryptographic proofs. That means different identity providers, financial institutions and regulators need interoperable technical standards.

Without those standards, a cryptographic credential may still depend on an intermediary that maintains the underlying account or identity record.

Zero-Knowledge Proofs Do Not Eliminate Every Risk

Privacy-preserving technology is not a complete solution by itself.

Fenigson points out that the structure surrounding a digital credential matters just as much as the information disclosed through the proof. A system can minimize the data revealed during verification while still linking the credential to an account controlled by a centralized intermediary.

That creates an important question over who ultimately controls the identity credential and the associated data.

For zero-knowledge systems to deliver their full privacy benefits, users need more than a new verification mechanism. They also need appropriate control over the credentials and clear limits on how those credentials can be linked to centralized databases.

Regulation May Already Allow More Flexibility

Another issue is whether financial regulations actually require institutions to retain complete copies of identity documents in every circumstance.

The Financial Action Task Force’s digital identity guidance recognizes digital identification systems as a potential mechanism for customer due diligence. Its broader framework is risk-based, with individual jurisdictions determining how the recommendations are implemented.

McMullen argues that in some regulatory environments, institutions are required to verify identity and retain evidence of that verification rather than necessarily maintaining the original identity document indefinitely.

If that interpretation is accepted, cryptographically verifiable attestations could potentially provide evidence that the appropriate checks were performed without creating another permanent copy of a passport or driver’s license.

The difficulty is that uncertainty encourages institutions to follow established practices. Compliance teams may prefer retaining complete documentation because it provides a familiar record for auditors and regulators.

Outlook

The debate over KYC is increasingly shifting from whether financial institutions should verify customers to how much personal information they actually need to retain after verification. Zero-knowledge proofs, selective disclosure and digital identity credentials provide technological alternatives, but broader adoption will depend on regulatory clarity, interoperability standards and changes in institutional compliance practices. The underlying security principle remains straightforward: reducing the amount of sensitive identity information held by organizations also reduces the amount of information that can be stolen from them.

Comparison, examination, and analysis between investment houses

Leave your details, and an expert from our team will get back to you as soon as possible

    Share

    Don't Miss

    SKN | Anchorage Digital Adds Institutional Access to Frgmnt’s fUSD Stablecoin

    Key Points Anchorage Digital will allow institutional clients to hold, mint, redeem, stake and unstake Frgmnt’s fUSD stablecoin directly through its custody platform....

    SKN | Hyperliquid’s Biggest Risk Is Regulation, Says Ran Neuner

    Key Points Crypto Banter founder Ran Neuner identified regulatory uncertainty as Hyperliquid’s biggest risk, particularly as governments turn their attention toward decentralized exchanges....

    Related Articles

    SKN | Balancer Proposes Wind-Down After Revenue Fails to Recover From $128M Exploit

    Key Points Balancer has proposed an orderly shutdown after its post-exploit restructuring...

    SKN | Anchorage Digital Adds Institutional Access to Frgmnt’s fUSD Stablecoin

    Key Points Anchorage Digital will allow institutional clients to hold, mint, redeem,...

    SKN | Coinbase and Moov Bring Stablecoin Infrastructure to US Community Banks

    Key Points: Coinbase and Moov are partnering to provide stablecoin payment infrastructure...

    SKN | Consensys to Split Into MetaMask and Institutional Blockchain Companies

    Key Points Consensys plans to separate its consumer-facing MetaMask business from its...

    Investcoin

    GET A FREE, EXPERT-BACKED
    INVESTMENT COMPARISON TODAY