KYC Weaknesses Exposed: Millions of Driver's Licenses Leaked Online
Two separate security incidents have exposed weaknesses in Know Your Customer (KYC) processes. The first incident involved over 153 million US and Canadian driver's licenses being leaked online, while a second case saw fintech Revolut tricked into releasing sensitive customer information, including passports and verification selfies.
The leaked IDs reportedly ended up on a dark web identity service called Nexus, while the hacker behind the Revolut breach is demanding a 10,000 Bitcoin ransom for the sensitive documents belonging to 680 customers. Zero-knowledge (ZK) proofs have been proposed as an alternative to storing copies of identity documents.
Proponents argue that ZK can allow users to prove facts without handing over or storing the underlying documents. However, developers point out that adoption is held back by compliance workflows, governance incentives, and interoperability standards rather than cryptography itself.
Regulatory guidance often leads institutions to 'over-collect' and retain more data than necessary, creating a problem that password resets cannot solve once identity documents or their images are leaked.