Revolut data breach exposes KYC storage risks as zero-knowledge alternative grows
Revolut hacked via spoofed law enforcement request
Revolut revealed that a hacker trickled sensitive data from 680 customers onto the web in an attempt to secure a $3 million ransom in Monero, a privacy-focused cryptocurrency. The stolen files included copies of passports and verification selfies.
The attacker sent emails requesting the data from a spoofed Italian law enforcement address. Lyudmyla Kozlovska, president of Open Dialogue, said EU anti-money laundering laws left the bank with no practical choice but to comply. She noted that verifying the true identity behind an authenticated state request is nearly impossible, and refusing to answer carries fines in the millions.
This incident follows a larger breach earlier in September, where more than 153 million US and Canadian driver’s licenses appeared on a dark web service called Nexus. Experts say the safest place for a copy of your ID is nowhere at all.
Centralized ID storage creates high-value targets
Current Know Your Customer (KYC) processes are designed to establish who customers are and prevent illicit activity. However, the standard implementation requires companies to store massive amounts of sensitive personal information. This creates valuable targets, or "honeypots," for criminals.
In the first half of 2026 alone, US data breaches affected at least 343 million people. The current ecosystem involves identity providers, databases, and vendors all storing separate copies of individual KYC data. Each additional copy creates another potential point of failure.
Zero-knowledge proofs allow verification without storage
Zero-knowledge proofs are a form of cryptography that lets one party prove a statement is true without revealing any information beyond the validity of the statement itself. For example, an app can generate a proof that a user is over 18 without sharing their exact birth date or a photo of their license.
Evin McMullen, co-founder of Billions Network, stated that the technology is already in production across thousands of applications and regulated institutions. He argued that the barrier to adoption is not technology, but rather the rules, incentives, and infrastructure built around collecting and storing document copies.
Regulatory and cultural barriers remain
Despite the availability of the technology, adoption is slow. McMullen identified "regulation and understanding" as the biggest obstacles, noting that compliance teams often conflate seeing an ID with keeping it. Susie Violet Ward of Bitcoin Policy UK added that there is a regulatory instinct that more information equals more control and safety.
The Financial Action Task Force (FATF) guidance does not explicitly require institutions to keep raw document images forever, but rather to verify identity and retain records of verification. However, because the guidance is ambiguous, most institutions default to keeping everything to satisfy auditors.
What remains unclear
While zero-knowledge technology reduces the need to hold sensitive data, it does not automatically solve all privacy issues. Efrat Fenigson noted that if a proof is tied to an account in a centralized database, the user remains dependent on that intermediary. It is also unclear when regulators will update standards to explicitly allow these privacy-preserving methods for financial KYC.
Why this matters for crypto users
For crypto users, the risk of centralized data storage is a constant threat. As financial platforms increasingly require identity verification to comply with regulations, the concentration of personal data makes them attractive targets for hackers. Moving toward verification methods that do not require storing raw identity documents could significantly reduce the impact of future breaches.