Revolut Hack Exposes KYC Vulnerabilities as Zero-Knowledge Proofs Gain Traction
The massive leak of driver's licenses and other sensitive information highlights the dangers of Know Your Customer (KYC) processes, which are designed to make financial systems safer by verifying customer identities. However, this approach often requires companies to store vast quantities of sensitive data, creating valuable targets for hackers.
Recently, Revolut revealed it had been tricked into handing over reams of sensitive customer data, including copies of passports and verification selfies, to a hacker. The hacker is now drip-feeding the identification documents of 680 customers onto the web in an attempt to secure a 10,000 Bitcoin ransom.
Experts warn that KYC systems have evolved around the assumption that institutions should see customers' passports or driver's licenses, record the relevant information, and then store evidence of the check. This approach creates a vast ecosystem of identity providers, databases, vendors, and compliance systems that all store separate treasure troves of customer data.
However, there is an alternative solution: zero-knowledge proofs, which allow individuals to verify their identities without revealing sensitive information. The European Union is already incorporating this technology into its digital identity and age verification systems design, allowing users to prove their age without revealing their full identity or exact date of birth.