There is an uncomfortable irony at the heart of modern identity verification: the more information companies collect to prove that we are legitimate, the more valuable the target becomes for criminals.
KYC data sits at the center of that contradiction. Names, addresses, government IDs, photographs and other personal details are routinely gathered to prevent fraud and illicit activity. But once enough of that information is stored in one place, the database can become a honeypot for hackers.
That risk is back in focus after a dark-web service reportedly offered more than 153 million driver’s license records belonging to people in the U.S. and Canada. The FBI is also investigating an apparent breach involving IDScan.net, a company that provides identity-verification technology to businesses.
The episode points to a problem larger than one company or one breach. The machinery built to make the internet safer can sometimes create a much more concentrated prize for attackers.
Why KYC data makes such an attractive target
IDScan may not be a household name, but its technology can be found behind everyday identity checks. Its systems are used by businesses including banks, car-rental companies, hotels, casinos, retailers and cannabis dispensaries.
The technology can scan both sides of an ID, extract personal information, compare an ID photo with a selfie and send the resulting data to cloud systems for businesses to access later.
Convenient for verification. Potentially lucrative for an attacker.
Personal information is among the most valuable data on the modern internet, particularly when it includes government-issued identification. A stolen name is one thing. A stolen identity document paired with other personal details can become a tool for opening accounts, impersonating victims or carrying out financial fraud in their name.
The basic structure of KYC data collection can make the problem worse. Instead of proving one narrow fact, people are often asked to hand over an entire identity profile.
Banks are a clear example. Under the Bank Secrecy Act and related regulations in the U.S., financial institutions must collect and retain personal information about customers as part of efforts to fight fraud and illicit finance.
The information is often stored centrally, creating what cybersecurity experts would recognize as a highly attractive target: one place containing enormous amounts of valuable personal data.
The numbers suggest the broader system is not exactly winning the war it was designed to fight. The U.S. Federal Trade Commission received 6.47 million reports involving fraud, identity theft and other consumer problems in 2024, compared with roughly 860,000 in 2004.
At the same time, illicit financial activity remains enormous. Estimates cited in the source put global illicit financial activity at $4.4 trillion last year.
More verification has not made fraud disappear.
And the defenses layered on top of KYC data have their own weaknesses. One-time codes sent by text or email can be defeated through phishing and other attacks. Biometric checks are also facing pressure as artificial intelligence becomes increasingly capable of imitating or manipulating visual information.
The result is an awkward trade: organizations collect more sensitive information in the name of security, while attackers gain more incentives to steal it.
KYC data needs a different kind of privacy
That does not necessarily mean identity verification should disappear.
There is a legitimate reason businesses need to establish that someone is allowed to open an account, access a service or control an asset. Removing every identity check could create a different set of problems, particularly for companies responsible for protecting customers and their own operations.
The more interesting question is whether verification requires surrendering the entire identity dossier.
Emerging privacy-preserving systems offer another possibility. Instead of handing a company a complete copy of an ID, a person could prove a specific fact — such as being old enough to use a service, being eligible for something or having authority over an account — without exposing every other detail attached to their identity.
In that model, KYC data becomes less about transferring ownership of information and more about proving a limited claim.
The technology is still developing, and the regulatory framework has not fully caught up. The argument is not that every institution should immediately abandon existing verification systems. Regulators could instead give financial institutions room to test privacy-preserving approaches as they mature.
Lawmakers could also reconsider requirements that encourage organizations to collect and retain more personal information than they actually need.
That distinction matters. Anti-fraud controls can remain useful without creating permanent repositories of sensitive information that may eventually be stolen.
The stakes extend beyond finance, too. Governments in the U.S. and elsewhere are considering broader identification requirements, including age-verification rules intended to protect children online.
Those efforts raise the same underlying question: does demanding more identity information actually make people safer, or does it simply create more databases that eventually become targets?
The lesson from breaches such as the one now surrounding IDScan is not that verification has no value. It is that collecting information carries a security cost of its own.
The safest piece of KYC data may ultimately be the piece a company never receives.
