WRITTEN IN PLAIN AMERICAN ENGLISH.
About
CLAY TRIBUNE.
ShopCartAccount
Advertisement

How Revolut’s Identity Theft Proves Know Your Customer Is Broken — and How Banks Can Fix It

A hacker stole KYC data from 343 million Americans in 2026. The fix is not the technology; it's the rules.

By mitch·4 min read
A cracked digital identity icon symbolizes stolen personal data in a dark, moody cybersecurity scene.

In 2026, a hacker asked for KYC information from Revolut, and the firm gave it up after receiving what appeared to be a genuine law enforcement email. The solution is sitting right in front of us. The issue does not lie with the technology itself. It lies with the rules.

The Revolut Case

Italian authorities made a direct demand of Revolut, and Lyudmyla Kozlovska, president of Open Dialogue, said on X that EU AML law left the company with no other option than to comply.

“EU AML law imposes no verification duty on the bank and provides no meaningful mechanism to check who is really behind an authenticated state request. Refusal to answer carries fines in the millions. In practice, verification is impossible.”

Advertisement

A criminal actor used emails to ask for KYC data from what appeared to be an official Italian law enforcement address. Revolut had no choice but to reply, since refusing would have exposed it to ruinous fines.

Why Storing Data Is The Problem

Susie Violet Ward, who runs Bitcoin Policy UK alongside a co-founder, argues that the core problem is keeping ID information stored anywhere.

“We need to stop treating identity verification and surrendering your identity as though they are the same thing.”

A business that merely needs to confirm an individual has reached 18 should not gather their complete name, physical address, precise date of birth, and a lasting record of the documents used to prove identity. A password can be restored following a data breach. An identity cannot be undone.

Personal data should stay protected by the system. What actually happens instead is that companies end up storing huge amounts of private information, which then gets taken without permission.

Zero-Knowledge Proofs Already Work

A technology called ZK allows proof of truth without exposing any underlying data. Through it, a phone app can verify that a driver’s license states an individual is over 18, all without transmitting their birth date or sharing an image of the document itself.

The founder of Zcash, Zooko Wilcox, provides a helpful explanation of ZK tech in this video. Evin McMullen, co-founder of Billions Network, which builds privacy-preserving digital identity and ZK solutions, tells Magazine that the technology is working and already in production today.

Today’s technology is working and deployed across thousands of applications and regulated institutions. What stands in its way is that the whole compliance system was designed around gathering and keeping copies of documents.

“This is a governance and standards problem wearing a technology costume.”

The EU Is Already Doing It

The EU is already folding ZK tech into its digital identity and age verification systems. The Digital Identity Wallet lets users share just what’s needed for a given transaction, per the European Commission.

What a ZK credential stays attached to is just as significant, according to Fenigson.

“The incentives point toward control, not privacy. Zero-knowledge proofs let someone prove a fact, like being over 18 or not on a sanctions list […] What’s missing is what that proof gets bound to. Right now it’s usually bound to an account inside someone else’s database.”

Why Companies Keep Collecting Everything

McMullen says regulation and comprehension stand as the principal barriers to adoption.

“The most common blocker is that compliance teams conflate ‘we saw the ID’ with ‘we must keep the ID,’ so they over-collect to be safe.”

Regulation often carries an assumption that more data leads to greater command and thus greater security.

Nobody wants to take the lead in trying something else when the rules allow it.

The Bottom Line

The technology exists. The law permits it. The incentives do not.

The issue at hand is that businesses gather far more personal information than what is required by law. The solution is simple: they must cease doing so.

Date Event
2026 343 million people affected by US data breaches
Present ZK technology in production across thousands of applications
  • 343 million people affected by US data breaches in 2026
  • EU AML law imposes no verification duty on banks and provides no meaningful mechanism to check who is behind a state request
  • Revolut had no other option but to comply with the Italian law enforcement request
  • ZK technology is already incorporated into the EU’s Digital Identity Wallet
  • The EU’s Digital Identity Wallet supports selective disclosure

A straightforward tale exists, along with a straightforward correction to it, yet the resolve needed to carry out that correction is missing.

The Notebook

Get the Notebook.

The day's best stories and every fresh verdict, in plain English, in your inbox by seven. One email a day, no more.

We send one note to confirm. Every issue has a one-click way out.

Advertisement

Leave a Reply

Your email address will not be published. Required fields are marked *

As an Amazon Associate, Clay Tribune earns from qualifying purchases.