KYC Data Remains a Hacker Target, Says Coin Center
Coin Center warns that mandatory KYC actually centralizes more sensitive ID data. The debate also touches zero-knowledge verification, DeFi, and stricter compliance requirements in Europe.

Key Takeaways
- Coin Center warns that mandatory KYC identification centralizes sensitive data and therefore creates an attractive target for hackers.
- A possible data breach at IDScan.net shows, according to the organization, how vulnerable identity checks are; the FBI is investigating the case.
- Coin Center argues for privacy-friendly verification that proves only the necessary information, without storing full ID data.
A new possible data breach involving IDScan.net shows, according to Coin Center, how vulnerable mandatory identity checks are. More than 153 million American and Canadian driver’s license records were reportedly being offered for sale on a dark web service, while the FBI is investigating the alleged breach. According to the organization, the core of the problem is that KYC processes often collect exactly the sensitive data that criminals want.
Why KYC Is So Vulnerable
Laz Pieper of Coin Center says companies and regulators want to fight fraud with identity checks, but at the same time they create a major risk. When names, addresses, and ID documents are stored centrally, they become an attractive target for hackers. That applies not only to banks, but also to companies like hotels, car rental firms, casinos, and retailers that use IDScan technology.
The piece also points to earlier major incidents, such as the 2017 Equifax hack, which affected nearly 148 million Americans. Pieper also notes that temporary codes sent by text or email are often easy to abuse, and that biometric checks are under pressure because of rapid AI developments. The picture that emerges is that many current checks do collect data, but do not always provide enough protection.
Privacy-Friendly Verification
Coin Center therefore argues for systems where someone only proves what is needed, instead of handing over a full copy of an ID. Think of proving age, access to an account, or authorization, without the underlying data ending up directly with a company. Such privacy-friendly verification is still being developed, but it fits broader experiments in the sector, such as zero-knowledge age verification and other forms of decentralized identity.
For European crypto readers, this matters because identity checks are also being expanded outside the US, including toward age verification and stricter compliance requirements. At the same time, interest is growing in solutions that combine privacy and verification better, including in DeFi and cross-border payments. That makes the debate over data minimization important not just legally, but also practically for crypto and fintech companies.
Data minimization remains a recurring theme within the industry itself too. In an earlier data breach at a crypto broker, for example, it became clear how quickly identity data, contact information, and wallet data can end up in the wrong hands together.
More Pressure on Rules
Pieper also warns that lawmakers in Washington and at the state level should not introduce extra verification requirements in places where they are not needed. According to him, those rules increase the amount of sensitive data that gets stored without really solving fraud. His bottom line is simple: if a service does not need full identification, then that data should not be collected either.