Revolut Denies Data Breach Claims Amidst Sale of Alleged 75 Million User Records
Hackers are reportedly selling a database containing over 75 million Revolut user records, but the fintech company states it has found no evidence of a new breach.

A threat actor has surfaced on a cybercrime forum, claiming to possess and offer for sale a database containing records of more than 75 million users of the popular fintech platform Revolut. The alleged dataset reportedly includes personally identifiable information (PII), partial payment card details, and hashed credentials, sparking concern among security professionals.
Revolut, however, has strongly disputed these claims, asserting that its internal security monitoring and controls have not detected any signs of unauthorized access or a new breach. The company stated that the threat actor's advertisement lacks verifiable data samples or technical evidence to substantiate the claims of a compromise.
Security researchers who examined samples of the purported data noted the presence of sensitive information, including last four digits of payment cards, card types, expiration dates, and card status. Additionally, the dataset allegedly contains email addresses, full names, phone numbers, physical addresses, account identifiers, device information, and hashed user credentials. Initial analysis suggests the data may extend up to May 2025, and investigators are exploring whether it is aggregated from multiple sources rather than a single, recent incident.
The threat actor is reportedly offering the entire dataset for approximately $500, a price point considered suspiciously low given the claimed volume of records. If legitimate, such a large dataset could be exploited for large-scale phishing campaigns, identity theft, and financial fraud.
This alleged incident, if verified, would dwarf a previous security event at Revolut in 2022, where a targeted social engineering attack exposed data for approximately 50,150 customers. That earlier breach involved personal details but did not allow direct access to customer funds.
While Revolut maintains its systems are secure, users are advised to exercise heightened vigilance. This includes treating unsolicited communications with caution, avoiding suspicious links, and verifying any official communications through secure, in-app channels. Implementing multi-factor authentication, regularly updating passwords, and closely monitoring account activity for any unusual transactions are critical protective measures.
The ongoing investigation aims to definitively confirm or refute the threat actor's claims. The potential implications for Revolut's global user base, should the data prove authentic, are significant, underscoring the persistent threat of data exfiltration and sale on underground markets.
This situation highlights the challenges financial technology companies face in safeguarding vast amounts of sensitive customer data against sophisticated threat actors. The low price of the alleged dataset could also indicate a move towards more accessible tools for cybercriminals looking to conduct targeted attacks.