Cyber Security News

Revolut Alleged Data Breach – Hackers Claiming to Access Over 75 Million Users’ Records

Revolut is currently under scrutiny after hackers claimed to be selling a database containing records of more than 75 million users. However, the company asserts that it has found no evidence of a new breach at this time.

A threat actor has advertised what they describe as a Revolut customer database on a cybercrime forum, allegedly containing 75 million records linked to the popular fintech platform.

Samples shared with researchers include partial card data, email addresses, full names, phone numbers, physical addresses, account identifiers, device information, and hashed user credentials.

The seller is reportedly offering the dataset for around $500, which appears to be a suspiciously low price given the claimed scale of the data.

Security researchers who examined the samples noted the presence of payment card details, such as the last four digits, card type, expiration dates, and card status, as well as personally identifiable information such as email addresses, names, countries, and registration IPs.

The dataset appears to contain bcrypt or argon2id password hashes, as well as metadata on device models and operating systems. This information could enable detailed profiling of targeted users.

Revolut Data Breach

Initial analysis suggests that the records could extend up to around May 2025. Investigators have not yet linked the samples to any previously documented incidents involving Revolut, raising the possibility that the data is aggregated from multiple sources rather than a single new compromise.

Revolut is aware of the forum listing, but strongly disputes that it reflects an actual breach of its systems. According to a CyberWatch post on X, the company stated that the alleged breach lacks a verifiable record count, meaningful data samples, or technical evidence indicating a new compromise.

Revolut insists that its internal monitoring and security controls have not shown signs of unauthorized access related to this purported leak, and the company is conducting an ongoing investigation.

Alleged Revolut Data Breach ( Source : CyberWatch05 )

In 2022, Revolut revealed a targeted social engineering attack that exposed data for approximately 50,150 customers, about 0.16% of its then-20 million-user base.

This earlier breach involved access to personal details, including names, addresses, email addresses, phone numbers, and partial card data, but it did not permit direct access to customer funds.

If the newly reported leak of 75 million records is legitimate, it would represent a significantly larger event than the 2022 incident, greatly increasing the risk of phishing, identity theft, and financial fraud against Revolut’s global user community.

Even without full verification, the presence of detailed contact information and partial card data in criminal marketplaces can facilitate highly convincing phishing and social engineering campaigns targeting Revolut customers.

Users are advised to treat unsolicited messages referencing Revolut with caution, avoid clicking on embedded links, and authenticate communications only through official channels and in-app notifications.

Enabling multi-factor authentication, regularly changing credentials, and closely monitoring account activity for suspicious transactions are essential steps. At the same time, investigators work to confirm or debunk the hackers’ claims.

Abinaya

Abi is a Security Editor and fellow reporter with Cyber Security News. She is covering various cyber security incidents happening in the Cyber Space.

Recent Posts

Top 10 Best SaaS Security Posture Management (SSPM) Tools in 2026

Your SaaS estate M365, Salesforce, Workday, Slack, hundreds of others is a sprawl of misconfigurations,…

1 minute ago

Top 10 Best Data Security Posture Management (DSPM) Tools in 2026

DSPM finds sensitive data you didn’t know you had, classifies it, maps who can reach…

7 minutes ago

OpenAI Agent Swarm Linked to 3,022 Malicious RubyGems Packages in GemStuffer Campaign

Open-source packages are meant to save developers time. In the GemStuffer campaign, that trust became…

18 minutes ago

Google Chrome 153 Update Fixes 42 Security Flaws, Including 3 Critical Ones

Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…

5 hours ago

CISA and NIST Release Technical Checklist for Safeguarding Identity Tokens From Theft and Misuse

The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology…

15 hours ago

CISA Shares 17 Techniques Used by Hackers to Compromise Active Directory Environments

CISA and five international cybersecurity agencies have released detailed guidance describing 17 common techniques hackers…

16 hours ago