A threat actor has advertised an alleged Revolut customer database for sale on a cybercrime forum, claiming it contains more than 75 million records tied to the fintech platform. Reported samples include personally identifiable information, account identifiers, device metadata, partial payment card details, and hashed credentials, raising potential risks of phishing, identity theft, and fraud if the data is authentic.
Revolut said it has found no evidence of unauthorized access or a new compromise of its systems, and researchers have not verified the seller’s claims. Early analysis indicates the records may extend to around May 2025, but investigators suspect the dataset could be an aggregation of historical or unrelated leaks rather than proof of a fresh breach; both the company and outside researchers say technical evidence such as authenticated exports or forensic logs is still lacking.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
Researchers reviewed samples from the advertised dataset and found records that reportedly extend to around May 2025, but they did not link the data to any previously documented Revolut incident. Initial analysis suggested the material may be aggregated from multiple sources rather than evidence of a single new breach.
Revolut stated that its internal monitoring and investigation found no evidence of unauthorized access or a new breach of its systems. The company also said the listing lacked verifiable record counts, meaningful samples, and technical proof of compromise.
A threat actor listed an alleged Revolut customer database for sale on a cybercrime forum or marketplace, claiming it contains more than 75 million user records. Reported sample data included personal information, account identifiers, device metadata, partial payment card details, and hashed credentials or password hashes.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.