TL;DR: Lost or stolen physical IDs can expose enough personal information to support fraud, prompting Yoti to argue that digital identity should share less data and add device-level protections; the article says more than 20 million people have downloaded its ID app. The governance lesson is that identity proofing should minimise disclosure and reduce what a stolen document can reveal.
NHIMG editorial — based on content published by Yoti: guidance on what to do if your ID is lost or stolen and why digital identity matters
By the numbers:
- More than 20 million people have downloaded the Yoti ID app, using it to create a Digital ID that can help them prove who they are or how old they are, both online and in person.
- 96% of organisations store secrets outside of secrets managers in vulnerable locations including code, config files, and CI/CD tools.
- Only 5.7% of organisations have full visibility into their service accounts.
Questions worth separating out
Q: How should organisations reduce identity exposure when verifying age or identity?
A: Use the minimum attributes required for the transaction and avoid exposing full document data when a single assertion will do.
Q: Why do lost identity documents create ongoing fraud risk after replacement?
A: Because the information on the document can still be reused in phishing, account recovery, or impersonation attempts.
Q: What do security teams get wrong about digital identity interoperability?
A: They often assume interoperability is only a technical integration problem.
Practitioner guidance
- Minimise attributes in every proofing flow Remove fields that are not necessary for the specific transaction, and use age or attribute assertions where the relying party does not need full document data.
- Treat lost ID events as fraud signals Connect replacement, banking, and account recovery workflows so that a reported lost document triggers monitoring for suspicious activity across relevant services.
- Add step-up verification to sensitive identity actions Require stronger verification before changing passwords, updating contact details, or approving account recovery when personal document data may have been exposed.
What's in the full article
Yoti's full article covers the practical consumer identity details this post intentionally leaves for the source:
- Step-by-step guidance for replacing a lost passport or driving licence.
- Advice on updating passwords, bank contacts, and credit monitoring after an identity loss.
- Explanation of how the Yoti ID app uses phone security and biometric verification.
- Examples of everyday identity use cases such as age checks, job onboarding, and renting.
👉 Read Yoti's guidance on lost ID, fraud risk, and digital identity →
Digital ID and lost identity documents: what changes for trust?
Explore further
Selective disclosure is the most underused control in human identity verification. The article’s central point is not that identity must move to phones, but that identity proofing often reveals more than the transaction requires. That is a governance failure because excess disclosure expands fraud impact when a document is lost or stolen. Practitioners should treat attribute minimisation as a baseline control, not a privacy extra.
A few things that frame the scale:
- 96% of organisations store secrets outside of secrets managers in vulnerable locations including code, config files, and CI/CD tools, according to Ultimate Guide to NHIs.
- 91.6% of secrets remain valid five days after the targeted organisation is notified, showing a critical gap in remediation procedures.
A question worth separating out:
Q: How can fraud teams and IAM teams work together after a document loss?
A: They should share signals from replacement requests, suspicious account changes, and unusual credit or recovery activity. That gives both teams a fuller picture of whether the identity event is isolated or being used as the starting point for fraud.
👉 Read our full editorial: Digital ID reduces exposure when physical identity documents are lost