Revolut has been investigated by hackers who claim they have sold a database containing sensitive information from over 75 million users. A threat actor has posted what they say is a customer database on a cybercrime forum, allegedly including 75 million records linked to the fintech company. The dataset includes partial card data, email addresses, full names, phone numbers, physical addresses, account identifiers, device information, and hashed user credentials.
Security researchers identified payment card information such as the last four digits, type, expiration dates, and status; alongside personal details including email addresses, names, countries, and registration IPs. Revolut Data Breach Initial findings indicate the records might extend through May 2025.
If confirmed, this new leak of 75 million records would surpass the 2022 incident significantly, greatly increasing the risk of phishing, identity theft, and financial fraud against Revolut’s global user base. The presence of detailed contact information and partial card data on criminal marketplaces makes it easy for attackers to create convincing phishing campaigns targeting Revolut users. Users should be cautious of unsolicited messages referencing Revolut, avoid clicking on embedded links, and only authenticate communications through official channels or in-app notifications.











