Revolut Breach Exposes KYC Weakness: Is Zero-Knowledge Proof the Solution?
The massive data breach affecting Revolut has highlighted the dangers of Know Your Customer (KYC) processes, which can create valuable honeypots for hackers. According to reports, over 153 million US and Canadian driver's licenses were stolen earlier this month from an identity verification provider.
The leaked IDs ended up on a dark web identity service called Nexus, alongside millions of other stolen identity and travel documents. This incident is the latest in a string of data breaches that have compromised sensitive customer information.
Revolut revealed it had been tricked by a hacker into handing over reams of sensitive customer data, including copies of passports and verification selfies. The hacker is now attempting to secure a 10,000 Bitcoin ransom by releasing the identification documents of 680 customers online.
Efrat Fenigson, host of You're The Voice podcast, notes that KYC processes were designed to make financial systems safer but have created an entirely different security problem. She argues that regulators mandate a model that guarantees this outcome while ignoring the technology to verify identities without storing them.