A threat actor is advertising what they claim is a massive database containing records associated with more than 75 million Revolut users, prompting renewed scrutiny of one of Europe’s largest fintech companies. According to researchers who reviewed samples of the advertised data, the dataset allegedly contains customer information ranging from contact details to partial payment card information and hashed credentials. However, there is currently no independent confirmation that Revolut itself suffered a new security breach, and the company says its internal investigation has found no evidence of unauthorized access to its systems.
At the time of writing, this should be treated as an unverified breach claim, not a confirmed compromise. While the advertised dataset is real enough to be marketed on cybercrime forums, its origin, authenticity, completeness, and relationship to Revolut remain under investigation.
What Is Being Claimed?
The alleged dataset surfaced on an underground cybercrime marketplace where a threat actor claimed to possess records belonging to more than 75 million Revolut users. Researchers who examined samples provided by the seller reported finding a mixture of information that appears to include:
- Full names
- Email addresses
- Phone numbers
- Physical addresses
- Country information
- Account identifiers
- Device metadata
- Registration IP information
- Partial payment card information, including the last four digits, card type, expiration date, and card status
- Password hashes reportedly using bcrypt or Argon2id
- Multiple CSV files containing structured customer records
Researchers noted that the seller was reportedly asking approximately $500 for the entire dataset. That unusually low asking price immediately raised questions within the security community because genuinely exclusive databases containing tens of millions of financial-service users would typically command a substantially higher price on underground marketplaces.

Pricing alone does not determine authenticity, but experienced threat intelligence analysts often consider it alongside other indicators such as data quality, uniqueness, freshness, and whether the seller has an established reputation.
Revolut Says There Is No Evidence of a New Breach
Revolut has publicly disputed claims that its infrastructure was compromised.
According to statements referenced by multiple publications, the company said its internal monitoring systems have not detected evidence of unauthorized access associated with the alleged leak. Revolut also stated that the forum post lacked technical evidence proving that the advertised records originated from its systems.
Reports citing Revolut’s response further indicate that the company compared identifiers present in the publicly shared samples against its own systems and did not find matches corresponding to valid Revolut identifiers. The company also pointed to external analysis suggesting that the advertised database may instead represent information aggregated from multiple unrelated sources rather than the result of a single compromise.
As of publication, Revolut continues to investigate the claims, but no official confirmation of a new breach has been issued.
Why Researchers Remain Cautious
The cybersecurity industry sees claims like this on a regular basis. Not every “database for sale” represents a fresh compromise.
Threat actors frequently attempt to increase the perceived value of stolen data by:
- Combining information from several historical breaches.
- Mixing public data with previously leaked credentials.
- Relabeling unrelated datasets using the name of a well-known company.
- Including fabricated records alongside genuine ones.
- Recycling years-old information as a “new” breach.
Researchers examining the Revolut samples reportedly observed that some records appeared to extend only until approximately May 2025, which raises additional questions regarding the data’s origin and freshness. They also noted that the available samples have not yet been linked to any previously documented Revolut security incident, leaving open the possibility that the advertised database is an aggregation rather than evidence of a newly compromised environment.
Without forensic evidence from Revolut’s infrastructure, authenticated database exports, server logs, or cryptographic verification, it is impossible to conclude that a breach of Revolut itself occurred.
Understanding the Alleged Technical Contents
Even though the overall claim remains unverified, the technical characteristics described in the available samples provide useful context.
The reported presence of bcrypt and Argon2id password hashes is notable because these are modern password hashing algorithms specifically designed to resist brute-force attacks. Unlike fast cryptographic hashes such as MD5 or SHA-1, bcrypt and Argon2 deliberately consume computational resources, significantly increasing the cost of password cracking.
However, password hashing does not make credentials immune to attack.
Weak passwords remain vulnerable to offline dictionary attacks, especially if attackers possess the hashes and can repeatedly attempt guesses without interacting with the legitimate authentication system. Strong, unique passwords dramatically reduce this risk.
The reported inclusion of device metadata is also significant. Information such as operating system versions, device models, application versions, or registration IP addresses can be valuable during social engineering campaigns. Criminals frequently use these details to make phishing messages appear legitimate or to convince victims that they are interacting with genuine customer support.
Similarly, partial payment card information does not usually enable direct card fraud by itself because the last four digits, expiration date, and card type cannot authorize transactions. Nevertheless, those details can increase the credibility of phishing attempts. An attacker who already knows a victim’s name, email address, phone number, and the final digits of a payment card can craft highly convincing messages requesting “verification” or urging users to “confirm suspicious activity.”
Why Financial Platforms Are Attractive Targets
Fintech companies represent particularly valuable targets because they combine financial services with extensive identity information.
A typical customer profile may include:
- Government-issued identity verification records.
- Contact information.
- Transaction history.
- Device fingerprints.
- Payment instruments.
- Risk scoring information.
- Authentication metadata.
Even when financial credentials themselves remain protected, combinations of personal information can substantially improve an attacker’s ability to conduct phishing, account takeover attempts, SIM-swapping attacks, identity theft, and business email compromise.
For this reason, alleged breaches involving financial institutions tend to receive immediate attention even before they are independently verified.
Comparing the Claim With Revolut’s 2022 Incident
Revolut has experienced a confirmed security incident before.
In 2022, the company disclosed that a targeted social engineering attack affected approximately 50,150 customers, representing roughly 0.16% of its user base at the time. The exposed information included personal details such as names, email addresses, postal addresses, telephone numbers, and limited payment card information. Revolut stated that customer funds were not directly accessible through that incident.
The newly advertised dataset differs substantially in scale.
If the current claim of more than 75 million records were eventually proven genuine, it would represent an incident several orders of magnitude larger than the confirmed 2022 breach. At present, however, there is no evidence supporting that conclusion, and treating the two events as equivalent would be inaccurate.
What Could Happen if the Data Were Genuine?
If the advertised dataset ultimately proves authentic, the greatest immediate danger would likely stem from secondary attacks rather than direct financial theft.
Attackers could leverage the information to conduct highly targeted phishing campaigns impersonating Revolut support staff. Victims might receive emails, SMS messages, or phone calls referencing genuine-looking account details and urging them to verify transactions, reset passwords, approve fraudulent login requests, or disclose one-time authentication codes.
Credential stuffing is another concern. If any exposed credentials correspond to passwords reused across multiple services, attackers could automatically test those combinations against other banking platforms, cryptocurrency exchanges, email providers, and online accounts.
Identity theft also becomes more practical when multiple pieces of personal information are combined into a single profile, particularly when names, addresses, phone numbers, and historical account information are available together.
These risks exist regardless of whether attackers obtained the information through a new breach or by aggregating historical leaks from multiple unrelated sources.
What Revolut Users Should Do
Although the breach remains unverified, adopting standard account security measures is prudent whenever reports of credential exposure emerge.
Users should ensure multi-factor authentication remains enabled wherever available, use a unique password that is not shared with other online services, review recent account activity for unfamiliar logins or transactions, and treat unsolicited emails, SMS messages, or phone calls claiming to originate from Revolut with skepticism. Sensitive account actions should always be performed directly through the official mobile application or website rather than through links received in messages.
Users should also remember that legitimate financial institutions will not ask customers to reveal one-time verification codes or authentication credentials through unsolicited communications.
Investigation Continues
The reported sale of an alleged Revolut customer database has generated significant attention because of its claimed size and the sensitivity of the information reportedly included in sample files. Nevertheless, there is still no independent evidence demonstrating that Revolut’s infrastructure was compromised, and the company maintains that its security monitoring has detected no signs of a new breach. Investigators have likewise not verified the advertised record count or established that the dataset originated from Revolut rather than multiple unrelated sources.
Until additional technical evidence emerges, the most accurate characterization is that this is an unverified breach claim under active investigation. Users should remain vigilant against phishing and account takeover attempts, but they should also avoid assuming that a compromise has been confirmed when neither investigators nor Revolut have reached that conclusion.









