A cracked smartphone screen displaying several
Crypto

Revolut says hacker tricked it into handing over KYC files as 680 IDs leak

The incident and a separate 153M+ driver’s license dump are fueling calls for zero-knowledge KYC that avoids storing raw IDs.

By Marcus Hale7 min read

Revolut disclosed it was socially engineered into providing sensitive KYC materials, including passport copies and verification selfies, to a hacker. The attacker is publishing documents tied to 680 customers while seeking a 10,000 BTC ransom, renewing scrutiny of how regulated ramps store identity data.

Key Takeaways

  • Revolut said a hacker tricked the firm into disclosing KYC data, including passport copies and verification selfies, and 680 customers’ ID documents are being posted online alongside a 10,000 BTC ransom demand.
  • A separate breach earlier this month involved more than 153 million US and Canadian driver’s licenses that appeared to originate from an identity verification provider and were offered via a dark web service dubbed “Nexus.”
  • Zero-knowledge proofs can verify attributes like age or sanctions status without revealing or retaining raw ID images, but adoption is slowed by compliance-stack inertia, regulatory ambiguity, and missing interoperability standards.
  • The EU’s Digital Identity Wallet design is described as supporting “selective disclosure” and incorporating ZK-based approaches for digital identity and age verification.

Revolut’s KYC Leak: Passports, Selfies, 680 IDs Posted, and a 10,000 BTC Demand

Revolut said it was tricked into handing over sensitive customer KYC data, including copies of passports and verification selfies. The attacker is now drip-feeding identification documents of 680 customers onto the web while seeking a 10,000 Bitcoin ransom.

The operational detail that matters is the vector. The hacker sent emails requesting KYC data from a legitimate Italian law enforcement address. The packet does not clarify whether that address was spoofed, compromised, or otherwise misused, and that distinction changes the defensive playbook for every regulated exchange and fintech that processes government-style information requests.

For traders, this is not abstract privacy discourse. KYC artifacts sit upstream of account recovery, SIM-swap escalation, and social-engineering attempts against support desks. Once passport images and selfies are out, the damage profile looks more like permanent counterparty risk than a reversible credential leak.

Privacy advocate and podcaster Efrat Fenigson framed the policy failure bluntly: “When regulators keep mandating a model that guarantees this outcome — while the technology to verify without storing already exists — it raises a red flag. It implies there is a lack of rational thinking and real will to solve problems.”

From Revolut to “Nexus”: The 153M+ Driver’s License Dump and the Scale of Breach Risk

The Revolut incident is being discussed alongside a separate breach earlier in the month: the theft of more than 153 million US and Canadian driver’s licenses. The leaked IDs appeared to come from an identity verification provider and were listed on a dark web identity service dubbed “Nexus,” alongside millions of other stolen identity and travel documents.

That pairing is the point. Even if a single exchange, broker, or neobank runs a tight internal security program, KYC is a supply chain. Identity providers, databases, and compliance vendors can each hold their own copy of the same documents. Every duplicate is another breach surface.

The scale is already visible in broader breach data. US data breaches affected at least 343 million people in the first half of 2026, according to Privacy Rights Clearinghouse figures cited in the packet. That number is not a crypto-specific statistic, but it is the backdrop for why “store everything forever” is turning into a liability rather than a compliance comfort blanket.

Susie Violet Ward, director and co-founder of Bitcoin Policy UK, argued the core mistake is treating verification as surrender: “We need to stop treating identity verification and surrendering your identity as though they are the same thing.” She also pointed to the asymmetry of the harm: “The irony is that KYC is designed to make systems safer, but the way we currently implement it can create an entirely different security problem. You can reset a password after a breach, but you cannot reset your identity in the same way.”

How Zero-Knowledge KYC Would Change the Data-Retention Game

The proposed fix is not “no KYC.” It is narrower: verify the specific attribute a platform needs without transmitting or retaining the underlying document image.

A zero-knowledge proof (ZKP) is a cryptographic method to prove a statement is true without revealing the private data behind it. In KYC terms, that can look like proving “over 18” or “not on a sanctions list” without sending a birth date, address, or a photo of a passport. The practical implication is fewer raw ID files sitting in ticketing systems, vendor dashboards, and long-lived storage buckets.

Evin McMullen, CEO and co-founder of Billions Network, said the technology is already deployed: “The technology works and is in production today, across thousands of applications and regulated institutions. What holds it back is that the entire compliance stack was built around collecting and storing copies of documents.” She described the bottleneck as institutional rather than technical: “This is a governance and standards problem wearing a technology costume.”

The near-term friction is that auditors and examiners tend to accept what they can see. McMullen put the failure mode in operational language: “The most common blocker is that compliance teams conflate ‘we saw the ID’ with ‘we must keep the ID,’ so they over-collect to be safe.”

The packet also flags a standards constraint that matters for real adoption. Proofs only scale if the relying party can verify them without calling back to the issuer, which requires shared interoperability standards that are not yet widely in place.

ZK is also not a magic privacy switch. Fenigson warned that the binding layer still centralizes power: “Zero-knowledge proofs let someone prove a fact, like being over 18 or not on a sanctions list [...] What’s missing is what that proof gets bound to. Right now it’s usually bound to an account inside someone else’s database.”

What the EU Digital Identity Wallet Signals About Selective Disclosure

The European Union is described as incorporating ZK technology into its digital identity and age verification system design, including privacy-preserving age verification that lets users prove age without revealing full identity or an exact date of birth. Its Digital Identity Wallet is also described as supporting “selective disclosure,” meaning users can reveal only the specific information needed for a transaction.

That matters because it is a mainstream identity rail, not a crypto-native workaround. If selective disclosure becomes normal in state-backed identity tooling, regulated platforms get a cleaner justification for minimizing what they store, especially where rules focus on verifying identity and retaining records of verification rather than keeping raw document images.

The packet frames FATF guidance as explicitly considering digital ID systems for customer due diligence and as a risk-based framework implemented differently by each country. McMullen’s claim is that the rules are often less prescriptive than institutional behavior: “In many regimes, the rule is that you must verify identity and retain records of that verification, not that you must keep the raw document image forever.”

The forward path is still messy. Revolut’s case turns on how that “legitimate Italian law enforcement address” was used, because spoofing and compromise imply different controls for request authentication. The other open loop is the unnamed identity verification provider tied to the 153M+ driver’s license leak, since vendor concentration would determine whether this is a one-off failure or a systemic shared dependency. The last gating item is standards: without interoperable verification that does not require calling back to centralized databases, ZK-based KYC stays stuck in pilots rather than becoming a default.

My Take: KYC ‘Honeypots’ Are Becoming a Counterparty-Risk Variable for Traders

The threshold that matters is not whether ZK proofs “work.” The packet already has a credible claim that they are in production. The real test is whether regulators and auditors accept a record of verification without forcing platforms to warehouse passport images and selfies that can be exfiltrated through hacks or social engineering.

If the EU Digital Identity Wallet’s selective disclosure milestones translate into relying-party standards that do not require issuer callbacks, the setup starts to look structural rather than narrative-driven. Until then, KYC data retention stays a balance-sheet-adjacent risk for every centralized venue, because “You cannot lose what you never held” only helps if institutions are allowed to hold less.

Sources