← Blog

Revolut 75M Records Claim: Unverified Dark Web Sale

Share on X

Unverified claim: In late July 2026, a cybercrime-forum listing alleged that roughly 75 million Revolut customer records were for sale. Cybernews examined sample files and quoted Revolut saying it sees no indications of a breach and that sample identifiers did not match genuine Revolut IDs. Catalog this as a claim — not a company-confirmed Revolut data breach.

Canonical record: Revolut 75M sale claim (unverified).

What the Revolut breach claim says happened

Revolut, the London-based neobank with tens of millions of retail customers, became the subject of a high-visibility forum sale post in July 2026. The actor advertised a package allegedly containing about 75 million Revolut records — a figure that matches Revolut’s publicly discussed retail-customer scale and therefore sounds plausible in a headline, which is exactly why unverified listings spread quickly.

Cybernews reported that samples included CSV extracts with partial credit-card data (last four digits, type, expiry, status), emails, full names, phone numbers, addresses, device models and OS details, subscription and KYC-related fields, activity timestamps, and passwords hashed with bcrypt or argon2id. A further sample reportedly contained bank account numbers, user IDs, and SWIFT codes.

Researchers stressed they could not verify the 75 million-record claim and suspected the dataset might combine multiple sources. Newest sample timestamps appeared to reach around May 2025 in Cybernews’s review. That uncertainty is central: a flashy count plus partial samples is not the same as a forensic confirmation that Revolut’s production systems were emptied.

What Revolut said

Revolut told Cybernews it was aware of the post. A spokesperson said the listing itself lacked a substantiated record count, sample, and technical detail in the actor’s initial marketing — and that Revolut saw no indications of any breach. After publication, Revolut reiterated that it still found no breach indications and that checked user and card identifiers from the alleged records did not correspond to valid Revolut identifiers.

Those statements matter for anyone searching “Revolut data breach 2026.” Until Revolut or a regulator confirms otherwise, treat phishing that claims “we detected you in the 75 million Revolut leak — click to secure funds” as a social-engineering attempt.

Revolut has a prior confirmed incident: in 2022, a targeted attack affected on the order of 50,000 customers with contact and partial card-related exposure. That historical Revolut breach is separate from the July 2026 forum claim.

What data types were alleged — and what was not proven

Alleged fields in samples span classic fintech gold: identity, contact, device fingerprinting, partial PAN data, and hashed credentials. Hashed passwords are not plaintext, but weak user-chosen passwords can still fall to offline guessing if hashes and salts are present. Partial card data plus PII is enough for convincing vishing against support channels.

Cybernews could not validate that 75 million unique Revolut customers were present. Row counts on forums are routinely inflated, deduplicated poorly, or stitched from stealer logs and older breaches. Revolut’s statement that sample identifiers failed internal checks further undercuts treating the listing as confirmed production exfiltration.

No public evidence in the Cybernews report showed live card-not-present fraud uniquely tied to this listing. The practical risk today is phishing and account-takeover attempts that abuse the news cycle.

Who is at risk

Current and former Revolut retail customers should assume attackers will send SMS and email lures referencing the alleged sale. Business account admins should brief finance teams on invoice fraud.

People who reused Revolut passwords elsewhere remain exposed if any hash corpus is real and crackable — rotate reused passwords regardless of confirmation status.

Journalists and OSINT researchers should avoid republishing sample rows containing live PII; secondary victimization helps nobody verifying a Revolut hack claim.

Fintech extortion and sale listings in 2026

Neobanks are frequent targets for both confirmed intrusions and opportunistic forum marketing. Listings that name a brand and a round customer total often aim to create negotiating leverage or quick buyers, whether or not the seller holds a fresh crown-jewel extract.

Compare this claim with confirmed fintech incidents in the BreachHistory catalog: verified rows lead with company or regulator attestation; unverified rows — like this Revolut 75 million records claim — lead with actor language and company denials when available.

Cybernews’s skepticism about multi-source mixing is a useful reminder for “was I affected” searches: appearance in a random CSV sample does not prove a fresh bank-side breach.

Action items

  1. Ignore unsolicited links claiming to “check if you are in the Revolut 75M breach.”
  2. Enable Revolut’s strongest available MFA and biometric app locks.
  3. Rotate your Revolut password and any reused passwords on email and other banks.
  4. Watch SMS/email for fake Revolut support; hang up and reopen the official app.
  5. Review linked cards and freeze physical cards if you see unfamiliar authorizations.
  6. Business users: dual-control payments and out-of-band verification for beneficiary changes.
  7. Follow Revolut’s official status/security channels for any future confirmed notice.
  8. If you receive a sample dump containing your email from a “researcher,” treat it as untrusted until corroborated.

Canonical record and sources

Catalog: https://breachhistory.com/revolut/revolut-75m-forum-claim2026. Reporting: Cybernews; additional wire context via Heise.

How to evaluate fintech “75 million records” claims

Start with the company’s statement, then the quality of samples, then independent researcher caveats. Cybernews publicly doubted the round 75 million figure and highlighted identifier mismatches claimed by Revolut. That combination should lower confidence sharply.

Next, ask whether samples show internal consistency: do user IDs, card statuses, and country fields look like a single schema? Mixed schemas often mean aggregator scrapes. Hashed passwords with modern algorithms can still be real without proving a 2026 production breach — stealer logs also carry argon2 and bcrypt strings.

Finally, watch for follow-up: confirmed Revolut incidents typically produce clearer customer emails and regulator notices. Silence plus denial is not proof of innocence forever, but it is strong evidence against treating the July listing as settled fact.

For “Revolut hacked” social posts, demand primary links. Remixes that drop the word “allegedly” are how unverified claims become urban legend.

Phishing playbook attackers will use

Expect SMS messages claiming card freezes, in-app deep links to fake login pages, and WhatsApp “Revolut fraud department” contacts. Attackers may paste a few real-looking last-four digits harvested from unrelated leaks to build trust.

Business customers may see fake supplier invoices referencing Revolut Business payout delays. Dual control and callback verification beat panic clicks.

If you ever typed a password into a suspicious page during this news cycle, rotate credentials immediately and review devices in the official app.

Deep dive: what Cybernews documented about the samples

Cybernews described more than one hundred sample records across multiple CSV files. Alleged columns covered partial card data, identity and contact fields, device metadata, subscription and KYC-like attributes, activity and spend markers, and credential hashes protected with bcrypt or argon2id. A fifth sample allegedly added bank account numbers, user IDs, and SWIFT codes.

Those field names look like a neobank warehouse export, which is why the listing gained traction. Yet researchers explicitly said they could not verify the 75 million-record scale and worried about multi-source blending. Revolut’s follow-up — that sampled identifiers failed internal validity checks — is unusually direct for a company response to a forum rumor.

Timestamps in samples reportedly reached into May 2025. Even if some rows are authentic somewhere, they need not be a July 2026 production exfiltration from Revolut core systems. Stealer logs, older breaches, and scraped KYC dumps regularly get rebranded under famous fintech names.

Heise and other outlets repeated the 75 million figure while pointing back to Cybernews. Secondary amplification without new forensics should not raise your confidence level.

How this differs from the 2022 Revolut breach

In 2022, Revolut publicly discussed a targeted attack affecting on the order of 50,000 customers with contact details and partial card-related exposure. That incident is company-attested history and already lives in the BreachHistory Revolut timeline.

The July 2026 story is a marketplace claim plus journalist sampling plus a company denial of breach indications. Conflating the two produces false “Revolut breached again for 75 million” narratives.

If Revolut later confirms a new incident, BreachHistory will update companyConfirmed and the technicalWriteup. Until then, share hooks and titles keep the CLAIM — UNVERIFIED framing.

Consumer and business response playbooks

Retail customers should open only the official Revolut app or website typed manually — never from SMS. Check security settings, devices, and trusted merchants. Report unfamiliar payees immediately.

High-net-worth and crypto-on-ramp users are priority phishing targets after mega-number headlines. Consider temporary lowered transfer limits if your threat model warrants it.

Revolut Business administrators should remind staff that beneficiary changes require dual approval and phone verification to a known number. Invoice fraud thrives in breach-news fog.

Journalists and influencers should avoid posting raw sample rows. Publishing victims’ emails from an unverified dump creates harm without proving a bank-side breach.

Security teams at other neobanks should watch for copycat listings that reuse Revolut column names — a common tactic to inflate perceived inventory.

Extended FAQ

Did Revolut get hacked for 75 million records? Revolut says it sees no breach indications and that checked sample identifiers are not valid Revolut IDs. Treat the sale post as unverified.

Should I freeze my card? If you see suspicious charges, yes. Otherwise prioritize MFA and phishing resistance first.

Are hashed passwords safe? Modern hashes help, but reused weak passwords can still be cracked offline. Rotate reused secrets.

Will Have I Been Pwned load this? Only if researchers obtain a verified corpus and Revolut/HIBP processes it. Do not assume a HIBP hit equals confirmation of this listing.

Additional context and practical guidance

Neobank customers often hold salary deposits, crypto on-ramps, and multi-currency balances in one app. That concentration makes Revolut data breach rumors uniquely effective bait for fake “account review” flows that harvest one-time passcodes.

When Cybernews published sample field lists, secondary accounts on social media stripped the unverified caveats. If you share the story, keep Revolut’s denial and the researcher doubts in the same breath as the 75 million figure.

Card-status fields such as frozen or blocked — if authentic — help attackers social-engineer support agents by pretending they already know the card state. Support orgs should authenticate callers with out-of-wallet questions not present in common leak schemas.

Argon2id and bcrypt hashes in samples do not prove Revolut’s password vault was copied last week. Malware stealer logs frequently include those algorithm names beside autofill passwords from browsers.

Compliance officers at fintech peers should rehearse media statements that distinguish “we are investigating a forum claim” from “we confirm a breach.” Revolut’s wording is a useful case study in measured denial without over-promising perfection.

People who used Revolut as a travel card should review foreign-transaction alerts and merchant locks. Opportunistic fraudsters time charges to news cycles when victims assume “the bank will auto-refund everything.”

Business API customers must rotate API credentials if their playbooks say so after any high-profile claim involving their processor — even unverified claims — because credential hygiene is asymmetric cheap.

Avoid uploading personal CSVs to random “breach check” websites that trend on the same day as the Revolut 75 million records headline; many are credential harvesters themselves.

If a journalist sends you a row containing your email from the alleged sample, ask them not to publish it and change passwords anyway. Presence in a sample is neither confirmation nor a free pass to ignore password reuse.

Watch for fake Chrome extensions branded as Revolut security helpers. Mega-claims historically correlate with malvertising spikes on brand keywords.

Compare this claim against confirmed 2026 fintech incidents in BreachHistory to calibrate your personal risk response: verified rows deserve credit freezes; unverified rows deserve phishing hypervigilance first.

Keep the canonical unverified claim URL handy when relatives forward WhatsApp forwards that scream “Revolut sold 75 million passports” — the actual alleged fields and company response are more nuanced.

Media literacy for fintech mega-claims

Round numbers that match a company’s marketing footprint — seventy-five million for Revolut — are engineered for virality. Readers should ask three questions every time: Did the company confirm? Did independent researchers validate uniqueness? Do samples survive identifier checks? On the July 2026 Revolut listing, Cybernews raised doubts and Revolut reported failed identifier checks. That is enough to keep the story in the unverified column while still warning customers about phishing.

Corporate security awareness trainers can build a five-minute module around this claim: show a redacted headline, ask employees what they would click, then reveal the company statement. Fintech staff are high-value targets for follow-on business email compromise when consumer brands they use personally appear in breach news.

Stay aligned with primary sources linked in this article, keep MFA enabled on related accounts, and treat unexpected payment or identity requests that cite this news cycle as fraud until verified through official channels you already trust.

Organizations should update threat briefings with the correct verification status, brief support staff on social-engineering scripts, and document decisions for auditors who will ask how the firm responded to widely shared headlines.

Individuals should prefer official apps and bookmarked portals over search ads, refuse remote-support tools offered by cold callers, and record dates of any suspicious contacts for law-enforcement reports if financial loss occurs.

Researchers and journalists can reduce harm by withholding raw PII samples, emphasizing unverified labels, and updating stories promptly if company confirmation or a credible denial with forensic detail arrives.

Bookmark the BreachHistory canonical record for this incident so internal tickets, community posts, and customer replies point to a stable summary rather than a changing chain of screenshots.

Additional protective reminder: verify sender domains carefully, prefer passkeys or phishing-resistant MFA where available, and discuss this incident only through channels your security team has approved for customer or employee communications.