Alleged Revolut Data Breach — Unverified Threat-Actor Claim of 75M-User Financial Dataset for Sale ($500, Sample Data Disputed as Fabricated) — Threadlinqs Intelligence
As of 2026-08-02, Alleged Revolut Data Breach — Unverified Threat-Actor Claim of 75M-User Financial Dataset for Sale ($500, Sample Data Disputed as Fabricated) is a medium-severity data breach threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 20 indicators of compromise.
Threat ID: TL-2026-1819 · Severity: MEDIUM · Status: TRACKING · Category: DATA_BREACH
A threat actor listed a dataset on an underground cybercrime forum allegedly containing records for more than 75 million Revolut users, spanning payment-card metadata, hashed credentials, device
On 2026-07-25, the X (Twitter) account @CyberWatch05 amplified a claim that Revolut — the UK-founded global neobank/fintech platform — had suffered a data breach exposing more than 75 million user records. OSINT/threat-intel accounts including @IBreaches ('Intel and Breaches') and 'Dark Web Intelligence' subsequently corroborated details of an underground-forum listing: the seller offered a dataset organized into five CSV files — cards.csv, credentials.csv, devices.csv, users.csv, and accounts.csv — allegedly containing partial payment-card data (scheme, status, creation/rotation metadata, last four digits, expiration), hashed credentials (bcrypt or argon2id), passcodes/MFA status and biometric indicators, device IDs/OS/registration IPs/activity timestamps, and names/emails/phone numbers/addresses/geolocation, priced at approximately $500 for the full set, with a 100-entry sample excerpt published to support the claim.
The claim has NOT been independently verified. Reporting on the story is internally inconsistent: GBHackers' own article headline cites '75 million users' while its body text references '757 million,' an order-of-magnitude discrepancy that was never reconciled in the source reporting. On 2026-07-28, Revolut Germany told heise.de that it had compared the user and card identifiers contained in the published sample against its production systems and found that 'none of them correspond to a valid or real Revolut identifier,' and in a same-day update stated the company had 'found no evidence of a security breach and believe it is highly likely that the dataset consists of fabricated data.' By 2026-07-29, Revolut's broader public position (relayed via Cybernews and other outlets) was that its internal monitoring and security controls had not detected unauthorized access, that no verifiable record count or meaningful data sample had been produced, and that the dataset — if genuine at all — is more likely an aggregation of previously leaked, purchased, or infostealer-sourced records than the product of a fresh large-scale intrusion. Independent researchers separately flagged two red flags consistent with a low-effort extortion/attention play rather than a genuine breach: (1) the anomalously low $500 asking price for a claimed 75M-record financial dataset, and (2) no record in the reviewed sample postdates approximately May 2025, suggesting stale or recycled source material rather than a live exfiltration.
This threat is tracked as an UNVERIFIED/likely-fabricated claim rather than a confirmed compromise. It nonetheless carries real downstream risk for defenders and Revolut customers independent of the claim's authenticity: (a) brand-impersonation and breach-themed phishing campaigns frequently follow high-profile breach claims regardless of veracity, (b) any genuinely leaked credential fragments (even if aggregated from older, unrelated leaks) can fuel credential-stuffing and account-takeover attempts against Revolut and other financial accounts where customers reuse passwords, and (c) the forum listing and its CSV structure (cards/credentials/devices/users/accounts) provide a template that other opportunistic actors may reuse to fabricate similar claims against other fintech brands. For historical context, Revolut previously confirmed a genuine, unrelated breach on 2022-09-11 caused by a targeted social-engineering attack against an employee, which exposed personal data (not passwords, PINs, or funds) for 50,150 customers (~0.16% of its then 20-million user base) — a materially smaller and differently-caused incident than the 2026 claim, illustrating why sample-data verification against production systems is the correct first response to breach claims of this kind.
Target sectors: financial services, fintech, banking, payments
Target regions: Europe, united kingdom, Global
Detections & IOCs
As of 2026-08-26, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 20 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
DATA_BREACH, MEDIUM, threat intelligence, cybersecurity, T1589, T1591, T1593, T1597, T1583, T1585, T1588, T1566, T1078, T1110