September 25, 2026

US Securities and Exchange Commission (SEC) Commissioner Hester Peirce wants financial firms to stop stockpiling customer data after breaches exposed the cost of mandatory identity collection.

This week, the SEC Commissioner called for wider use of reusable digital credentials that could establish facts about customers without requiring every financial institution to collect the underlying personal information again.

According to her:

“Today society is at a crossroads. Down one path lies the status quo: more data collection, more intermediary surveillance, more “know your customer’ requirements that turn our financial rails into a panopticon. Down the other path lies an opportunity to use new technologies to improve our ability to catch criminals while collecting less personal information than ever before, and monitoring more sparingly to protect Americans’ privacy.”

Her remarks follow recent security incidents at major financial platforms like Revolut that exposed identity documents, addresses, and other information these companies collect to meet customer-verification and anti-money-laundering requirements.

Peirce said regulators should reconsider whether institutions need particular pieces of information or merely need confirmation of the facts those records establish. Attribute-based credentials, she said, could prove whether someone meets an age requirement, holds a particular citizenship or appears on sanctions lists without revealing information such as their name, income or address.

“Does more than one firm need to collect it?” Peirce asked, arguing that technology already exists to reduce the information customers surrender and the number of institutions that receive it. She said the remarks represented her own views rather than those of the SEC.

The question is becoming more consequential as Washington builds a new compliance regime for stablecoins.

The GENIUS Act requires permitted payment stablecoin issuers to maintain customer-identification programs, and regulators are proposing rules that would continue requiring covered issuers to obtain and retain identifying information from customers.

Breaches turn KYC records into targets

Coinbase provided one of the clearest examples of the risk last year.

Attackers bribed contractors or employees working in overseas customer-support roles to obtain information from the exchange’s internal systems. Coinbase later disclosed that 69,461 customers were affected.

The compromised information included names, addresses, phone numbers, email addresses, partial Social Security numbers, government-issued identification images, account balances and transaction histories. Passwords and private keys were not stolen, but Coinbase warned that the information could be used in social-engineering attacks against customers.

Chief Executive Officer Brian Armstrong then turned the breach into an argument against how much information financial companies are required to retain.

“We don’t want to collect it, and our customers hate it,” Armstrong said while calling for lawmakers to reconsider the Bank Secrecy Act and anti-money-laundering requirements.

He also argued that Congress should review the laws or they should face a constitutional challenge, a position that goes considerably further than Peirce’s proposal to change how required information is collected and verified.

The problem resurfaced this month at Revolut through a different route.

The fintech company said an unauthorized party used a legitimate government-agency email domain to send fraudulent information requests.

Revolut disclosed customer information in response, including identity and contact details and copies of passports and driver’s licenses. Depending on the customer, the material could also include verification selfies, account statements, and transaction histories. Revolut said its systems and customer funds were unaffected.

The episodes illustrate the vulnerability Peirce is targeting: once institutions accumulate identity records, stealing money does not require breaching private keys or directly compromising financial accounts. Personal information can itself become an asset for extortion, impersonation, and subsequent attacks.