Revolut Data Breach Claim Allegedly Exposes Data of 75 Million Users

A threat actor has allegedly listed a massive dataset for sale, claiming it contains sensitive information associated with more than 75 million Revolut users.

The claim surfaced on an underground forum, where the seller advertised multiple data files purportedly extracted from Revolut systems.

According to the threat actor, the dataset is organized into multiple CSV files, including “cards.csv,” “credentials.csv,” “devices.csv,” “users.csv,” and “accounts.csv.”

Revolut Data Breach

The exposed data may include a wide range of sensitive user information. Allegedly compromised records include payment card details, user credentials, device metadata, account-related information, and detailed user profiles.

The credentials dataset appears to reference authentication-related fields, including password hashes, passcodes, MFA status, and biometric indicators.

Revolut Data Breach  (Source: CyberWatch05)
Revolut Data Breach (Source: CyberWatch05)

Meanwhile, the devices dataset reportedly includes device IDs, operating system details, IP addresses, and timestamps of user activity.

The user profile data may contain personally identifiable information (PII), including names, email addresses, geographic locations, and account status indicators.

If validated, the scale and nature of the alleged leak could pose significant security risks. Exposure of financial and authentication data could enable threat actors to conduct account takeover attacks, payment fraud, and credential stuffing campaigns.

Additionally, the availability of structured CSV datasets increases the likelihood of automated exploitation and large-scale abuse.

Cybersecurity experts warn that even unverified breach claims can still pose indirect threats. Threat actors often reuse previously leaked or aggregated datasets, repackaging them as new breaches to gain attention or financial profit.

In some cases, such datasets may include a combination of old breaches, scraped data, or synthetic entries designed to appear legitimate.

The threat actor is reportedly offering the dataset for sale at a relatively low price, further raising questions about its authenticity and origin. Low-cost listings are often associated with recycled or low-quality data dumps, though this does not eliminate the potential risk to affected users.

Users are strongly advised to take precautionary measures in light of the claim. Recommended actions include enabling multi-factor authentication (MFA), using unique and strong passwords for financial services, and closely monitoring account activity.

Users should also remain cautious of phishing attempts, as threat actors may leverage breach-related news to craft convincing social engineering campaigns.

Organizations, including financial institutions, should proactively monitor for signs of credential abuse, unusual login activity, and patterns of fraud.

Implementing adaptive authentication controls and threat intelligence monitoring can help mitigate potential exploitation if the dataset proves to be valid.

Cut SOC investigation blind spots and contain threats earlier to reduce response costs and business disruption with ANY.RUN. 

Tamilselvan
Tamilselvanhttps://cyberpress.org/
Tamilselvan is an Investigative cybersecurity journalist dedicated to breaking stories on ransomware cartels, data breaches, and state-sponsored espionage.

Trending News

Related Stories