Auditen
sector watch

Passports Are Hard to Reset

Revolut recently admitted it leaked passports and financial data. This isn't just another line on a spreadsheet. It's basic bad hygiene masked as fast growth. When hackers leak these documents to demand ransom, they aren't just hitting a database, and they're going after identity markers that can't be changed.

Then there is GDPR Article 32. The law doesn't care if you have a policy document saying you value security, and it requires actual technical and organizational measures based on the level of risk. Storing high-res passport scans for millions of people creates a massive honeypot. Treating those files with the same perimeter security as a basic user profile is a failure of risk assessment.

Fintech crowds love to talk about privacy by design, and what does that actually mean? Usually, it means they bought a KYC vendor and plugged it into an app without any real planning. Real design would have meant tokenizing identity verification, and it would have meant ensuring raw passport images don't sit on reachable servers for years after the initial check is done.

Some will argue that no system is unhackable and that compliance with standards like PCI DSS 4.0.1—which companies like Digi Ventus are currently renewing—is the benchmark for success.

That's a logical error. A certification is just a snapshot, usually taken in a sanitized environment, and it isn't a permanent state. You can check every PCI compliance box and still leave your best customer assets open to ransomware because you chased growth instead of minimizing data.

The second order effect is what actually matters for the rest of the sector, and when thousands or millions of passports leak, it doesn't just hurt Revolut's customers. It poisons the well for every financial institution that relies on document based KYC.

What happens when high quality passport images hit the wild? They become raw material for synthetic identity fraud, and the risk moves downstream to the auditors and insurers who backed these firms based on their security claims. Every bank accepting digital passport uploads is now a bit more vulnerable because the blueprints for those identities are sitting on the dark web.

It's an expensive lesson in data gravity. Hoarding sensitive data makes it harder to protect and ensures the fallout is catastrophic when the perimeter fails.

Tether had a recent audit confirming $6.8 billion in assets, even if their buffer halved in Q2, and tether can worry about reserves. Revolut should worry about liabilities, specifically the liability of holding data that can't be changed.

You can rotate a password. You can issue a new credit card. You cannot issue a new face or a new birthdate.

Regulators might decide that keeping these documents is a violation of data minimization if they aren't deleted after verification. Will they? The SEC and FDA are already working closer together on life sciences disclosures; it won't be long before the spotlight hits fintechs and why they're acting like digital archives for government IDs.

I suspect we'll see a spike in "identity verification" vendors suddenly announcing new encrypted vaults. It'll be too late for the people whose passports are already for sale.

Sources

The reporting this piece was written from. Check the originals before relying on anything here.

  1. Revolut discloses data breach exposing financial info, passports - BleepingComputer Data Privacy (Google News)
  2. Revolut Data Breach: Hackers Leak Customer Documents, Demand Ransom Payment - Blockonomi Data Privacy (Google News)
  3. Why Businesses Are Moving From SMS Codes to Authenticator Apps - Big News Network.com InfoSec Compliance (Google News)
  4. Waldencast plans Nasdaq exit, eyes $18.5M cost cuts | WALD SEC Filing - Form 6-K - Stock Titan Compliance Week (Google News)
  5. Revolut Customer Data Exposed in Security Breach - Novinite.com Data Privacy (Google News)
  6. Donald Trump backs Flock cameras despite privacy concerns - knewz.com Data Privacy (Google News)
  7. SEC settles with B.C. firm over AML failings - investmentexecutive.com Compliance Week (Google News)
  8. Auditors Ask US Board to Clarify Enforcement Strategy, SEC Role - news.bloombergtax.com Compliance Week (Google News)

How stories are selected and assessed