Auditen
framework watch

Your KYC Folder Is a Honeypot

The Spanish Data Protection Agency, or AEPD, just logged its first data breach caused by an AI agent. It's a milestone. The firm involved probably isn't celebrating.

People spent years saying AI would change how we handle paperwork. Now it's changing how people steal it. An automated agent can mimic a real request or poke at holes in a system with a kind of persistence no human could match. Does "we have a process" still count as a defense? It doesn't look like it.

This brings us back to the GDPR, and specifically the uncomfortable tension between data minimisation and the relentless demand for KYC—Know Your Customer—verification.

The mess at Revolut feels like a case study in that specific kind of friction, and anti-money laundering rules force companies to chase down passports, utility bills, and facial scans. You end up building these massive, shimmering pools of identity data just to prove you aren't moving cash for oligarchs. But here is the problem: once you have built that reservoir, you actually have to keep it locked tight.

It turns out Revolut may have let customer data walk out the door because of a fake government request, and if you don't follow these stories closely, it sounds like some kind of high-level heist. If you do look at the paperwork, it looks more like a verification failure. It is honestly baffling. If a firm has enough tech muscle to demand a crisp, high-res selfie just so someone can open an account, why was it so hard to check if that government demand was real before handing over the keys?

The rulebook says you must only collect what is necessary. The AML rules say you must collect everything.

There's a weird paradox in play here: doing exactly what one set of laws requires actually bumps up the risk of breaking another. When firms tick that "Know Your Customer" box, they're basically building high-value honeypots. It isn't just names and email addresses sitting there; it's the specific documents that make identity theft trivial.

You'll usually get a shrug as the biggest counterargument ("We have no choice"). The logic is that if we stop collecting this data, regulators shut us down for failing to follow financial crime laws, and that isn't entirely wrong, to be fair. But it misses the second half of the equation, and collecting the data is just the legal minimum. How you store it? Who can trigger its release? That's where actual professional judgment lives (or should live).

If your "process" for responding to government requests involves a few clicks and an email attachment, your process is broken.

The damage won't stop with the firms. Auditors and insurers are next; for years, auditors just ticked boxes if a company had a written policy for data requests. That tick is now a liability because AI agents make those policies obsolete in real time. Insurers will eventually stop covering breaches where the attack vector was a failure to verify a PDF's origin, and they'll want proof of cryptographic verification for every single piece of outgoing data.

Fines are another issue. Telia paid SEK 1 million, about £75,000, because they deleted law enforcement data too early, and it's a small amount compared to other corporate penalties, but it shows the trap the data custodian is in. You get fined if you lose the data and you get fined if you delete it.

The DPO is the only one who gets how thin this tightrope is. They have 72 hours to report breaches. That deadline feels like a joke when you're still trying to figure out if an AI agent just walked through your front door.

Reasonable security can no longer be defined by static controls; manual reviews are useless if attackers use agents that adapt in seconds.

Are boards weighing the cost of KYC obligations against the price of the breach they're courting? Most aren't. They treat KYC as a regulatory hurdle instead of a permanent increase in risk.

Government requests will have to change. Regulators might start signing requests with verifiable digital keys so people can stop wondering if an email looks official, and until that happens, firms will keep collecting piles of passports and hope AI agents don't want their specific pile.

Watch whether the AEPD starts penalising firms for failing to anticipate that AI agents would be tools. If state of the art includes AI phishing, then a lack of AI defence is a failure of the GDPR requirement for technical and organisational measures.

It’s a lovely bit of irony: we spent a decade worrying about hackers in hoodies, and it turns out we should have been worrying about scripts that don't sleep.

Sources

The reporting this piece was written from. Check the originals before relying on anything here.

  1. The AEPD registers the first data breach in Spain attributed to an attack carried out by an AI agent. - Demócrata Data Privacy (Google News)
  2. Telia handed SEK 1 mln fine over deleted law enforcement data - Telecompaper Data Privacy (Google News)
  3. California Privacy Protection Agency warns data brokers of fines for inaccurate registration disclosures - JD Supra Data Privacy (Google News)
  4. Revolut’s Bitcoin Privacy Scandal: How a Fake Government Request Exposed Customer Data - Bitcoin Foundation Data Privacy (Google News)
  5. Personal, Financial Info Exposed in Revolut Data Breach - SecurityWeek Data Privacy (Google News)
  6. FTC Rescinds 2021 Policy Statement on Health App Data Breaches - The HIPAA Journal InfoSec Compliance (Google News)
  7. SEC Proposes Rescinding Investment Adviser Pay-to-Play Rule, but Compliance Risks Remain - WilmerHale Compliance Week (Google News)
  8. AI Agent Security Readiness: The Federal Standard You Should Get Ahead Of - Security Boulevard InfoSec Compliance (Google News)

How stories are selected and assessed