KYC Data Leaks Renew Calls for Zero-Knowledge Identity Verification
The theft of more than 153 million US and Canadian driver’s licenses earlier this month has renewed scrutiny of how identity data is collected and stored. According to Cointelegraph, the leaked IDs appeared to come from an identity verification provider and were later found on a dark web identity service called Nexus, alongside millions of other stolen identity and travel documents. The issue gained further attention this week after fintech Revolut said a hacker had tricked the company into handing over sensitive customer data, including passport copies and verification selfies. The hacker is now releasing the identification documents of 680 customers online while seeking a $3 million ransom in Monero. The incidents have intensified criticism of Know Your Customer systems, which are intended to improve financial security but often require companies to store large amounts of sensitive information that can become targets for criminals. In the first half of 2026 alone, US data breaches affected at least 343 million people, according to the Privacy Rights Clearinghouse, while zero knowledge proofs already offer a way to verify identity without storing documents.
Efrat Fenigson, host of You’re The Voice podcast, said regulators are still mandating a model that creates these risks even though the technology to verify without storing documents already exists. She said this suggests a lack of rational thinking and real will to solve the problem. The article argues that KYC systems have evolved around the assumption that institutions should inspect passports or driver’s licenses, record the relevant details and keep evidence of the check. That approach has created a broad ecosystem of identity providers, databases, vendors and compliance systems, each holding separate copies of sensitive data. In the Revolut case, the hacker reportedly requested KYC data from a legitimate Italian law enforcement address, and Lyudmyla Kozlovska, Open Dialogue president, said on X that EU laws left Revolut with no practical choice but to comply. Susie Violet Ward, director and co-founder of Bitcoin Policy UK, said the real issue is storing ID data unnecessarily and argued that identity verification should not be treated as the same thing as surrendering identity. She added that if a company only needs to know whether someone is over 18, it should not automatically require a full name, address, exact date of birth and a permanent copy of identity documents. Evin McMullen, chief executive and co-founder of Billions Network, said the technology works in production today, but the compliance stack was built around collecting and storing document copies. She described the problem as a governance and standards issue rather than a technology issue.
The article says zero knowledge proofs could reduce the need to hoard identity documents by allowing someone to prove a fact without revealing the underlying details. It notes that the European Union is already incorporating ZK technology into digital identity and age verification systems, including privacy-preserving age checks and a Digital Identity Wallet that supports selective disclosure. McMullen said regulation and understanding remain the biggest barriers, adding that compliance teams often confuse seeing an ID with needing to keep it. She also pointed to interoperability challenges, saying cryptographic proofs are only useful if the relying party can verify them without contacting the issuer. The article adds that ZK technology does not automatically solve every privacy or security issue, because the credential still matters if it is tied to an account in someone else’s database. It also says the rules are not always as strict as they appear: the Financial Action Task Force’s guidance considers digital ID systems for customer due diligence, and its recommendations leave countries to implement standards through their own legal and regulatory systems. McMullen said many regimes require verification and record retention, not permanent storage of raw document images. Still, because the guidance is ambiguous, institutions often keep everything to avoid problems with auditors and examiners. Ward said regulation tends to favor more information because it is seen as more control and more safety. The article concludes that broader adoption may depend on explicit rule changes allowing zero-knowledge proofs, while McMullen said, “You cannot lose what you never held.”