Fintech company Revolut recently disclosed that a hacker successfully obtained sensitive customer data, including passport copies and verification selfies, by sending emails from a legitimate Italian law enforcement address. The attacker is now releasing identification documents for 680 customers online to demand a ransom of 10,000 Bitcoin. This incident occurred shortly after more than 153 million US and Canadian driver’s licenses were leaked onto a dark web service called Nexus, allegedly originating from an identity verification provider.

These breaches underscore the vulnerability inherent in traditional Know Your Customer (KYC) processes, which require institutions to store vast quantities of personal information. According to the Privacy Rights Clearinghouse, US data breaches affected at least 343 million people in the first half of 2026 alone. Experts note that while zero-knowledge proofs offer a method to verify identity without retaining raw document images, regulatory ambiguity and institutional inertia continue to drive the default practice of permanent data storage.