Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Critical Flaw in Joyfill npm Packages Lets Attackers Deploy RAT and Steal Credentials
July 29, 2026
Critical Tor Browser Bug Lets Attackers Hijack Users
July 29, 2026
Russia Charges Telegram CEO Pavel Durov With Aiding Terrorism
July 29, 2026
Home/CyberSecurity News/Revolut Breach Exposes 75 Million Users to Phishing Attacks
CyberSecurity News

Revolut Breach Exposes 75 Million Users to Phishing Attacks

Key Takeaways A threat actor is advertising a dataset purportedly containing records for 75 million Revolut users on a cybercrime forum. The alleged data includes personal information, partial card...

Emy Elsamnoudy
Emy Elsamnoudy
July 29, 2026 3 Min Read
3 0

Key Takeaways

  • A threat actor is advertising a dataset purportedly containing records for 75 million Revolut users on a cybercrime forum.
  • The alleged data includes personal information, partial card details, and hashed credentials.
  • Revolut denies any new breach, stating there is no verifiable evidence to support the claims.
  • The incident, if legitimate, would be significantly larger than a 2022 social engineering attack affecting 50,150 customers.
  • Users are advised to remain vigilant against phishing and enable multi-factor authentication.

Alleged Revolut Breach: Millions of Records Offered on Dark Web

Fintech giant Revolut is currently addressing claims made by a threat actor who purports to be selling a database containing records of over 75 million users. Despite the widespread advertisement of this dataset on a cybercrime forum, Revolut maintains it has found no evidence of a new breach affecting its systems.

Table Of Content

  • Key Takeaways
  • Alleged Revolut Breach: Millions of Records Offered on Dark Web
  • Details of the Alleged Data
  • Revolut’s Response and Investigation
  • Historical Context and Potential Impact
  • What You Should Do

Details of the Alleged Data

The advertised dataset, described by the seller as a Revolut customer database, reportedly includes a comprehensive array of user information. Samples provided to cybersecurity researchers contain partial payment card data (last four digits, card type, expiration dates, and status), full names, email addresses, phone numbers, physical addresses, account identifiers, device information, and hashed user credentials.

Further analysis of the samples indicates the presence of bcrypt or argon2id password hashes, alongside metadata detailing device models and operating systems. Such detailed information could enable sophisticated profiling of targeted individuals, increasing the risk of tailored cyberattacks.

The asking price for this extensive dataset is reportedly around $500, a figure that security experts find unusually low given the claimed volume and sensitivity of the data.

Revolut’s Response and Investigation

Revolut has acknowledged awareness of the forum listing but strongly disputes its authenticity as an actual breach of its infrastructure. According to a CyberWatch post on X, the company asserts that the alleged breach lacks crucial elements such as a verifiable record count, meaningful data samples, or technical indicators of a new compromise.

The company stated that its internal monitoring systems and robust security controls have not detected any unauthorized access correlating with the purported leak. Revolut is conducting an ongoing investigation to thoroughly examine the claims.

Historical Context and Potential Impact

Initial analysis of the samples suggests that the records could extend up to approximately May 2025. Investigators have yet to link these samples to any previously documented security incidents involving Revolut, leading to speculation that the data might be an aggregation from multiple sources rather than a single, fresh compromise.

This incident follows a social engineering attack in 2022 that impacted approximately 50,150 Revolut customers, representing about 0.16% of its then-20 million user base. That breach exposed personal details, including names, addresses, email addresses, phone numbers, and partial card data, but did not grant direct access to customer funds.

Should the current claims of 75 million exposed records prove legitimate, it would signify a significantly larger security event than the 2022 incident. Such a breach would substantially elevate the risk of phishing, identity theft, and financial fraud for a vast segment of Revolut’s global user community.

Even without full verification, the availability of detailed contact information and partial card data on criminal marketplaces inherently facilitates the creation of highly convincing phishing and social engineering campaigns targeting Revolut customers.

What You Should Do

  • Exercise Caution: Treat all unsolicited communications referencing Revolut with extreme skepticism.
  • Avoid Suspicious Links: Do not click on embedded links in emails or messages that seem even slightly unusual.
  • Verify Through Official Channels: Authenticate any important communications directly through the official Revolut app or by contacting customer support via official channels.
  • Enable Multi-Factor Authentication (MFA): Ensure MFA is enabled on your Revolut account and any other financial services.
  • Regularly Update Credentials: Change your Revolut password periodically and use strong, unique passwords.
  • Monitor Account Activity: Regularly review your Revolut account for any suspicious or unauthorized transactions.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackBreachHackerphishingSecurityThreat

Share Article

Emy Elsamnoudy

Emy Elsamnoudy

Emy is a cybersecurity analyst and reporter specializing in threat hunting, defense strategies, and industry trends. With expertise in proactive security measures, Emily covers the tools and techniques organizations use to detect and prevent cyber attacks. She is a regular speaker at security conferences and has contributed to industry reports on threat intelligence and security operations. Emily's reporting focuses on helping organizations improve their security posture through practical, actionable insights.

Previous Post

Critical VMware Flaws Let Attackers Bypass Authentication, Access Systems

Next Post

Russia Charges Telegram CEO Pavel Durov With Aiding Terrorism

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Houston City College Data Breach Exposes 832,000 Student Emails
July 29, 2026
AsyncAPI Malware Steals GitHub, npm, Cloud, and AI API Credentials
July 29, 2026
Fake Recruiters Exploit Bitbucket, npm to Target Web3 Developers
July 29, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Emy Elsamnoudy
Emy Elsamnoudy
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us