Revolut Data Breach Allegations: 75 Million Records at Risk

Unverified claim of 75m Revolut records for sale, Revolut denies breach

The Revolut data breach allegations have sparked concern across the fintech sector, after threat actors claimed to possess and sell a database containing over 75 million user records. While Revolut strongly denies evidence of a new compromise, the sheer volume of data described in criminal forums has raised serious questions about potential risks for users and organisations alike.

Details of the Revolut Data Breach Allegation

On 29 July 2026, a cybercrime forum post appeared advertising what the seller described as a database of 75 million Revolut customer records. The dataset, offered for the relatively low price of $500, allegedly includes a wide range of personally identifiable information (PII) and financial details. Security researchers analysing sample data noted the following fields were present:

  • Partial payment card details: last four digits, card type, expiration dates, and card status
  • Email addresses and full names
  • Phone numbers and physical addresses
  • Account identifiers and registration IPs
  • Device information: models and operating systems
  • Hashed user credentials (bcrypt or argon2id)

The breadth of the leaked information, particularly the combination of contact details and partial card data, could enable sophisticated social engineering and phishing attacks if the data is genuine.

Timeline and Discovery

The listing first came to light in late July 2026, with researchers noting that the included records appeared to be current as of May 2025. This timeline suggests that, if authentic, the data might be sourced from a relatively recent compromise or an aggregation of multiple incidents.

Revolut, when made aware of the post, initiated an internal review. The company has publicly disputed the legitimacy of the breach, stating that:

  • No verifiable record count or meaningful data samples have been produced
  • Technical analysis has found no evidence of unauthorised access to Revolut systems
  • Ongoing monitoring and security controls have not detected any indication of a new compromise

According to the company’s statement on social media and direct communication with researchers, Revolut believes the dataset may be aggregated from prior breaches or third-party sources, rather than the result of a fresh, large-scale intrusion.

What is in the Alleged Dataset?

Researchers reviewing the sample data reported the presence of sensitive attributes:

  • Card details limited to non-sensitive fragments (such as last four digits and expiry)
  • Comprehensive contact lists with names, numbers, and addresses
  • Technical metadata on customer devices and operating systems
  • Password hashes using strong algorithms (bcrypt or argon2id), which are difficult to reverse

The presence of hashed credentials and device metadata could enable threat actors to build detailed profiles of users, increasing the effectiveness of spear-phishing attacks. However, there is no evidence that full card numbers, CVVs, or direct access to accounts are included in the dataset.

Comparisons with Previous Revolut Security Incidents

This is not the first time Revolut has faced data security concerns. In September 2022, Revolut confirmed a targeted social engineering attack led to unauthorised access, affecting around 50,150 customers. That breach exposed similar data types: names, addresses, email addresses, phone numbers, and partial card data. Importantly, however, no customer funds were directly accessed in that incident.

If the current 75 million record claim is accurate, it would dwarf the 2022 breach in scale and potential impact. The increase in exposed contact and card details would significantly heighten the risk of phishing, identity theft, and financial fraud for Revolut’s global user base.

Status of the Alleged Revolut Data Leak

As of publication, there is no independent confirmation that Revolut’s core systems have been breached. The company continues to monitor the situation, stating that their security mechanisms have not detected any unauthorised access or anomalous activity consistent with a compromise of this scale.

Researchers remain cautious, noting the low asking price for the dataset and the lack of clear provenance. There is speculation that the data could be a compilation from earlier leaks, purchased data, or even fabricated samples designed to attract attention or extort the company.

Despite Revolut’s assurance, the presence of detailed user information in criminal forums—regardless of its source—means phishing and fraud attempts targeting Revolut customers are likely to increase. Attackers may use convincing details such as names, partial card data, and device information to craft targeted scams, making it more difficult for recipients to spot suspicious messages.

Current Exploitation Risks

  • Phishing emails and SMS messages impersonating Revolut customer support or payment verification teams
  • Social engineering calls using accurate user details to build trust
  • Potential credential stuffing attempts if any hashes are cracked
  • Broader financial fraud schemes targeting Revolut’s global user community

Why This Matters to Organisations

Even without confirmation of a new Revolut breach, the event highlights the ongoing risks posed by the circulation of PII and payment data in criminal markets. UK businesses, especially those who use Revolut for payments or payroll, should anticipate an uptick in phishing attempts using Revolut branding. Raising employee awareness and verifying payment requests are particularly important at this time.

What Organisations Should Do Now

  • Alert staff to the increased likelihood of phishing emails or calls impersonating Revolut
  • Advise users to verify any payment-related communications directly with Revolut, using official contact channels
  • Monitor for signs of targeted attacks referencing Revolut credentials or payment information

Maintaining vigilance and encouraging healthy scepticism around unsolicited Revolut messages can help limit the effectiveness of socially engineered attacks in the wake of this event.

Originally reported by cybersecuritynews.com.

Share this bulletin

About the Author

Headshot of Jonny Pelter, leading cyber security expert in the UK and CISO

Jonny Pelter

Partner

  • CIPM
  • CIPP/E
  • CISSP
  • CISM
  • CRISC
  • ISO27001
  • Prince2
  • MSc
  • BSc

Jonny Pelter

Jonny is a Founding Partner at CyPro and executive group level CISO who has worked closely with the British intelligence agencies NCSC and GCHQ.

An ex-professional rugby player and originating from KPMG and Deloitte, Jonny has a wealth of experience across numerous sectors including technology, critical national infrastructure, financial services, oil & gas, insurance, betting, pharmaceuticals and utilities.

Jonny is a leading cyber security expert in the UK, having featured on national media for his professional commentary such as BBC News, iPlayer, Telegraph and Times Radio.

View Profile
Back to Bulletins

Related CyPro Services

  • Managed Detection and Response (MDR)

    Managed Detection and Response (MDR) is an end-to-end managed service designed to help organisations detect, analyse and respond to cyber threats quickly and effectively. It...
    View Service
CyPro Cookie Consent

Hmmm cookies...

Our delicious cookies make your experience smooth and secure.

Privacy PolicyOkay, got it!

We use cookies to enhance your experience, analyse site traffic, and for marketing purposes. For more information on how we handle your personal data, please see our Privacy Policy.

Schedule a Call