Sign up
Subscribe
Home / news / Revolut ID thefts show why KYC data storage is the real risk
news

Revolut ID thefts show why KYC data storage is the real risk

Revolut ID thefts show why KYC data storage is the real risk

The theft of more than 153 million US and Canadian driver’s licenses earlier this month, plus Revolut’s recent exposure of customer passports and verification selfies, puts a familiar problem back on the table: KYC (Know Your Customer) often protects the payment stack by creating a second, very attractive data target. For PSPs and banks, the question is no longer whether to collect identity data, but how much of it should ever be stored.

  1. The leaked IDs appear to have come from an identity verification provider and ended up on a dark web identity service called Nexus, alongside millions of other stolen identity and travel documents. That is the basic plumbing of the problem: once identity data leaves the customer and gets copied into third-party systems, it becomes part of a wider resale market.
  2. Revolut said it was tricked by a hacker into handing over sensitive customer data, including copies of passports and verification selfies. The hacker is now drip-feeding the identification documents of 680 customers online in an attempt to secure a 10,000 Bitcoin ransom. For high-risk merchants and PSPs, the mechanics matter: a KYC file is not just a compliance record, it is ransom material.
  3. KYC is supposed to establish who a customer is and keep financial systems cleaner. In practice, the standard implementation requires companies to store large volumes of sensitive information, which creates honeypots for criminals. Every extra copy of a passport or driver’s license adds another place where the same data can be stolen, leaked, or sold.
  4. The scale of the issue is already visible in breach data. In the first half of 2026 alone, US data breaches affected at least 343 million people, according to the Privacy Rights Clearinghouse. That is the backdrop for a familiar industry question: if identity can be verified without storing documents, why keep building systems that store them anyway?
  5. Efrat Fenigson, host of You’re The Voice podcast, said: “When regulators keep mandating a model that guarantees this outcome — while the technology to verify without storing already exists — it raises a red flag. It implies there is a lack of rational thinking and real will to solve problems.” Her point is blunt, and for PSPs it lands on operations: if the compliance model requires document retention, the storage architecture becomes part of the risk profile.

Zero knowledge proofs are already mentioned in the source as a way to verify identity without storing identity documents. For payment businesses that live with chargeback scrutiny, AML reviews, and partner risk audits, the practical takeaway is simple: the less raw KYC data you retain, the less there is to lose when a provider, bank workflow, or law-enforcement request gets abused.

Weekly high-risk digest

Regulation, sanctions and payment news across your verticals — once a week, free.

Please check your inbox and click the link to confirm your subscription.

Please enter a valid email address!