75 million Revolut records allegedly for sale: here's what our researchers found
Revolut users should watch out for phishing attacks.

Image by Shutterstock.
- A hacker claims to sell 75 million Revolut customer records.
- Researchers found sample data with partial card details, emails, names, phone numbers, addresses, device details, and hashed credentials.
- Researchers could not verify the 75 million-record claim and suspect the data may come from multiple sources.
- If legitimate, the data could help criminals target Revolut users with phishing, social engineering, and identity profiling attacks.
- Revolut said in a statement to Cybernews, that it sees no breach signs.
Key Takeaways by nexos.ai, reviewed by Cybernews staff.
Credit card data, along with other private information allegedly belonging to Revolut customers, is up for sale, attackers claim. Meanwhile, Revolut says the company doesn’t see any indications of a data breach.
A threat actor has just listed a database allegedly containing 75 million records of Revolut customers on a cybercrime forum.
To support their claims, the threat actor posted a data sample that our researchers have investigated. Over 100 sample records provided in 4 .csv files suggest that the following kind of private data may be exposed in the dataset:
- Partial credit card data: last 4 card digits, card type, expiration dates, and card statuses (active, blocked, frozen, etc).
- User credentials: passwords hashed with bcrypt or argon2id algorithms to secure them. Also timestamps when the credentials were rotated.
- User personal data: emails, full names, phone numbers, resident countries, addresses, currency, registration IP address, subscription plans, KYC status, risk score, timestamps of the user's last activity, monthly spend, lifetime top-up, and other identifiers.
- Other sensitive data: device models, operational systems, and timestamps.
The newest records in the samples appear to date back to around May 2025, and our researchers found no evidence linking the dataset to any previously documented breaches.
The sample reviewed by Cybernews appears to contain referral-related flags. These referral indicators suggest the dataset may include information tied to the company's customer referral program, a feature that rewards users for inviting new customers to the platform.
Upon further investigation, the team discovered a fifth sample file containing bank account numbers, user IDs, and SWIFT codes linked to Revolut.
Revolut is “looking into it”
We have reached out to Revolut for comment. The company’s spokesperson said they are aware of the claims. However, they “see no indications of any breach.”
“We're aware of the post and, as it notes itself, the listing contains no record count, no sample and no technical detail, nothing that substantiates the claim,” the spokesperson said.
“We're continuing to look into it,” they added.
However, the company has not provided any additional comments on the over 100 sample records listed in the forum.
After the publication went live, Revolut reassured that the review is still ongoing. "We have so far still found no indications of any breach."
"We have checked the user and card identifiers contained in the alleged records against our systems, and none of them correspond to valid or genuine Revolut identifiers," the spokesperson said.
The dataset may be compiled from multiple sources
Cybernews researchers could not verify the claimed number of records and remain skeptical about the claimed scope of the dataset. If the dataset really contains 75 million records, the $500 price tag advertised on the illicit marketplace is unusually low for a leak of that size.
The origin of the data remains unknown. However, our researchers believe that the listing is more likely an aggregation of data collected from multiple sources rather than the result of a newly discovered breach.
The wording of the forum post also suggests that the seller may have compiled the information from multiple sources.
“We're aware of the post and, as it notes itself, the listing contains no record count, no sample and no technical detail, nothing that substantiates the claim,”Revolut spokesperson said.
Revolut users may be targeted by phishing attacks
If the claims prove to be legitimate, the exposed information could pose serious risks to affected individuals.
Criminals could combine names, contact information, device details, and partial financial information to build convincing phishing attacks.
“The impact would be pretty severe for these people. They are at risk of social engineering attacks and identity profiling. Attackers may also attempt to gather full payment method information,” Cybernews researchers warned.
Stay updated with our latest stories and follow us on social media
Be the first to discover new stories, ideas, and updates from our team.
Revolut has been breached before
There is no confirmation yet if the attacker's claims carry any weight. If the data proves to be legitimate, it will not be the first time Revolut users ‘ data has been exposed.
In 2022, a highly targeted cyberattack affected over 50,000 Revolut customers. At the time, Revolut said the card data was secure because it was hashed.
Revolut is a digital financial giant that provides mobile banking, global money transfers, and wealth-building tools through a smartphone app. Since its foundation in 2015, the London-based platform has 75 million retail customers and more than 800,000 business customers worldwide. The company boasts $6 billion in annual revenue.
Updated on July 28th with a statement from Revolut. Also, information was added about one more sample file, which contained Bank account numbers, user IDs, and SWIFT codes allegedly belonging to Revolut users.