Threat actors are claiming to be selling a database containing records for more than 75 million Revolut users, raising concerns about the potential exposure of customer information.
However, Revolut says it has found no evidence that its systems have been breached and disputes that the forum listing represents a new security incident.
Key takeaways of the alleged Revolut data breach
- Threat actors claim to be selling a database containing more than 75 million alleged Revolut user records.
- Revolut says it has found no evidence of a new breach and continues to investigate the claims.
- Researchers question the dataset’s authenticity, citing its low asking price and indications it may be aggregated from multiple sources.
- If authentic, the data could enable phishing, credential attacks, identity fraud, and account takeover.
What is known about the alleged Revolut data breach
A threat actor recently advertised what they claimed was a Revolut customer database on a cybercrime forum, alleging it contains more than 75 million user records.
Security researchers who analyzed sample data reported seeing partial payment card information, email addresses, full names, phone numbers, physical addresses, account identifiers, device information, and hashed user credentials.
The dataset also reportedly includes bcrypt or argon2id password hashes, along with metadata such as device models, operating systems, and registration IP addresses.
If authentic, the combination of personal, account, and device information could enable spearphishing campaigns, credential attacks, and identity fraud.
Researchers question the dataset’s authenticity
Despite the scope of the alleged dataset, several factors have raised questions about its authenticity.
The threat actor is reportedly offering the records for approximately $500, an unusually low price for data purportedly affecting tens of millions of users.
Researchers also noted that the records appear to extend only through approximately May 2025 and have not been linked to any previously disclosed Revolut security incident.
This has raised the possibility that the data may have been aggregated from multiple sources rather than stolen during a single compromise.
Revolut disputes breach claims
Revolut has disputed that the forum listing represents a new breach of its systems.
The company said its internal monitoring and security controls have not detected unauthorized access related to the alleged dataset and that it continues to investigate the claims.
How users and organizations can reduce Revolut breach risks
While investigators continue to verify the alleged dataset, users should take proactive steps to protect their accounts and reduce the risk of phishing, credential theft, and account compromise.
- Enable multi-factor authentication (MFA) and change passwords if they may have been exposed.
- Verify account activity and communications only through the official Revolut app or website, and be cautious of unsolicited emails, text messages, or phone calls requesting credentials, one-time passcodes, or payment information.
- Monitor accounts, payment cards, and login activity for suspicious behavior, review trusted devices and active sessions, and report suspicious activity through Revolut’s official support channels.
Organizations should prepare for the possibility that the alleged data may be used in phishing, account takeover, and other social engineering campaigns, even if the breach itself remains unconfirmed.
- Continuously monitor for phishing campaigns, brand impersonation, unusual login attempts, and other indicators of account takeover or fraud.
- Strengthen identity security by enforcing phishing-resistant MFA, risk-based authentication, least privilege, and continuous monitoring of privileged accounts.
- Monitor threat intelligence sources and underground forums for emerging indicators related to the alleged dataset and adjust defenses as new information becomes available.
- Increase employee awareness of phishing and social engineering tactics, particularly those impersonating trusted financial institutions or referencing account activity.
- Regularly test incident response plans, fraud response procedures, and customer communication processes.
Collectively, these measures can help both individuals and organizations reduce overall risk.
Bottom line
The bigger lesson is that every alleged breach should be treated as an operational security event, regardless of whether the underlying claims are eventually validated.
Threat actors routinely exploit high-profile security incidents to make phishing and social engineering campaigns more convincing, making identity security, threat intelligence, and incident readiness just as important as determining whether a compromise actually occurred.
As attackers continue to weaponize trusted identities and public security events, Zero Trust has become a foundational strategy for helping to minimize the business impact of identity-driven attacks.





