KYC data is an irresistible honeypot for hackers, and we must change how it is collected

The article argues that the widespread collection of personally identifiable information (PII) by third-party verification services creates significant security risks. It highlights how centralized data storage makes companies like IDScan prime targets for cybercriminals and foreign adversaries.
Why it matters
As digital identity verification becomes ubiquitous, the systemic risk of massive data breaches poses a threat to individual privacy and national security.
Cyberattacks targeting personally identifiable information (PII) have been prevalent for some time and are only getting worse. In 2017, Equifax — one of the largest credit reporting agencies in the U.S. — underwent a cyberattack that led to the compromise of nearly 148 million Americans’ sensitive personal information. Nearly 45% of Americans had their data stolen. The Department of Justice alleged that the Chinese People’s Liberation Army was behind the hack in a 2020 indictment, but this was merely a band-aid to the underlying and increasingly prevalent problem.
Laz Pieper is the research director at Coin Center, which defends the rights of individuals to build, use, and assemble free and open peer-to-peer networks, and the right to do so privately.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in