On 27 July 2026 a seller advertised what they claimed were 75 million Revolut customer records on a cybercrime forum. Researchers at Cybernews reviewed sample data containing names, email addresses, phone numbers, addresses, device details, and some partial card details and hashed credentials. That does not make the breach established — quite the opposite.
Why leaked data keeps resurfacing
A leaked email and phone number don't just sit in one dump — data brokers buy breach data, merge it with public records, and resell it. That's why the spam calls and phishing texts keep coming months later. Deleting your data from the breached company is only the first step; getting it out of the broker network is what actually stops the follow-on damage.
Last updated 28 July 2026. We update this page as the situation develops.