2026 Revolut — 75M customer records sale claim (unverified)
Data compromised
Actor sample allegedly showed partial card data, emails, names, phones, addresses, device details, hashed credentials, and some bank identifiers — Cybernews could not verify the 75M claim; Revolut disputed sample identifiers
Technical writeup
Unverified forum / extortion-style sale claim — late July 2026. A threat actor listed an alleged Revolut customer database said to contain about 75 million records. Cybernews reviewed sample CSVs citing partial card digits, bcrypt/argon2id password hashes, PII, device metadata, and additional bank/SWIFT fields in a fifth sample, but researchers could not verify the 75 million-record claim and suspected possible multi-source mixing. Revolut told Cybernews it was aware of the post, saw no indications of a breach, and said checked user/card identifiers in the alleged samples did not correspond to valid Revolut identifiers. Catalogued as an unverified claim; distinct from the verified 2022 Revolut incident (~50k customers).
Root cause
Unverified cybercrime-forum listing claiming ~75M Revolut customer records for sale; Revolut says it sees no breach indications