Revolut is currently facing scrutiny as hackers claim to sell a database purporting to hold the records of over 75 million users. Nevertheless, the company maintains there is no evidence of a new breach at this moment.
Allegations of a Major Data Breach
Reports have surfaced that a threat actor is promoting a Revolut customer database on a cybercrime forum. This database allegedly contains 75 million records linked to the renowned fintech company.
Researchers analyzing provided samples found information such as partial card data, email addresses, full names, phone numbers, physical addresses, account identifiers, device details, and hashed credentials.
Remarkably, the seller is offering this data for approximately $500, a price that raises suspicions considering the purported volume of information.
Security Experts’ Insight
Security professionals who scrutinized the dataset observed the inclusion of payment card details, such as the last four digits, card type, expiration dates, and status. Additionally, personally identifiable information like email addresses, names, countries, and IP addresses used during registration were present.
The dataset appears to incorporate bcrypt or argon2id password hashes alongside metadata detailing device models and operating systems, potentially enabling detailed user profiling.
Preliminary investigations suggest that these records might date up to May 2025. However, they have not been connected to any known incidents concerning Revolut, suggesting the possibility of data aggregation from various sources rather than a singular breach.
Revolut’s Response and Security Measures
Revolut has acknowledged the forum posting but firmly denies that their systems have been breached. According to a CyberWatch post, the company argues that the alleged breach lacks credible record counts, substantial data samples, or technical proof of a new compromise.
The company asserts that its internal security measures and monitoring have not detected any unauthorized access related to this supposed leak. An investigation is currently underway.
In 2022, Revolut disclosed a targeted social engineering attack affecting approximately 50,150 users, equating to 0.16% of its user base at that time. This breach exposed personal data but did not grant access to customer funds.
Potential Risks and User Recommendations
Should the recent claims prove accurate, this breach could eclipse the 2022 incident, significantly increasing risks of phishing, identity theft, and financial fraud against Revolut’s global clientele.
Despite the lack of full verification, the availability of detailed contact information and partial card data on criminal platforms can facilitate effective phishing and social engineering attempts on Revolut users.
Users are advised to exercise caution with unsolicited messages regarding Revolut, refraining from clicking on embedded links, and verifying communications through official channels and app notifications. Enabling multi-factor authentication, regularly updating credentials, and monitoring account activity for unusual transactions are essential precautions. Meanwhile, efforts continue to confirm or refute the hackers’ claims.
