Revolut Breach Exposes 75 Million Users to Phishing Attacks
Key Takeaways A threat actor is advertising a dataset purportedly containing records for 75 million Revolut users on a cybercrime forum. The alleged data includes personal information, partial card...
Key Takeaways
- A threat actor is advertising a dataset purportedly containing records for 75 million Revolut users on a cybercrime forum.
- The alleged data includes personal information, partial card details, and hashed credentials.
- Revolut denies any new breach, stating there is no verifiable evidence to support the claims.
- The incident, if legitimate, would be significantly larger than a 2022 social engineering attack affecting 50,150 customers.
- Users are advised to remain vigilant against phishing and enable multi-factor authentication.
Alleged Revolut Breach: Millions of Records Offered on Dark Web
Fintech giant Revolut is currently addressing claims made by a threat actor who purports to be selling a database containing records of over 75 million users. Despite the widespread advertisement of this dataset on a cybercrime forum, Revolut maintains it has found no evidence of a new breach affecting its systems.
Table Of Content
Details of the Alleged Data
The advertised dataset, described by the seller as a Revolut customer database, reportedly includes a comprehensive array of user information. Samples provided to cybersecurity researchers contain partial payment card data (last four digits, card type, expiration dates, and status), full names, email addresses, phone numbers, physical addresses, account identifiers, device information, and hashed user credentials.
Further analysis of the samples indicates the presence of bcrypt or argon2id password hashes, alongside metadata detailing device models and operating systems. Such detailed information could enable sophisticated profiling of targeted individuals, increasing the risk of tailored cyberattacks.
The asking price for this extensive dataset is reportedly around $500, a figure that security experts find unusually low given the claimed volume and sensitivity of the data.
Revolut’s Response and Investigation
Revolut has acknowledged awareness of the forum listing but strongly disputes its authenticity as an actual breach of its infrastructure. According to a CyberWatch post on X, the company asserts that the alleged breach lacks crucial elements such as a verifiable record count, meaningful data samples, or technical indicators of a new compromise.
The company stated that its internal monitoring systems and robust security controls have not detected any unauthorized access correlating with the purported leak. Revolut is conducting an ongoing investigation to thoroughly examine the claims.
Historical Context and Potential Impact
Initial analysis of the samples suggests that the records could extend up to approximately May 2025. Investigators have yet to link these samples to any previously documented security incidents involving Revolut, leading to speculation that the data might be an aggregation from multiple sources rather than a single, fresh compromise.
This incident follows a social engineering attack in 2022 that impacted approximately 50,150 Revolut customers, representing about 0.16% of its then-20 million user base. That breach exposed personal details, including names, addresses, email addresses, phone numbers, and partial card data, but did not grant direct access to customer funds.
Should the current claims of 75 million exposed records prove legitimate, it would signify a significantly larger security event than the 2022 incident. Such a breach would substantially elevate the risk of phishing, identity theft, and financial fraud for a vast segment of Revolut’s global user community.
Even without full verification, the availability of detailed contact information and partial card data on criminal marketplaces inherently facilitates the creation of highly convincing phishing and social engineering campaigns targeting Revolut customers.
What You Should Do
- Exercise Caution: Treat all unsolicited communications referencing Revolut with extreme skepticism.
- Avoid Suspicious Links: Do not click on embedded links in emails or messages that seem even slightly unusual.
- Verify Through Official Channels: Authenticate any important communications directly through the official Revolut app or by contacting customer support via official channels.
- Enable Multi-Factor Authentication (MFA): Ensure MFA is enabled on your Revolut account and any other financial services.
- Regularly Update Credentials: Change your Revolut password periodically and use strong, unique passwords.
- Monitor Account Activity: Regularly review your Revolut account for any suspicious or unauthorized transactions.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.