Privora Remove my data
← All tracked breaches
Unverified claim · 2026-07-27

Revolut: is the leaked-data claim real?

On 27 July 2026 a seller advertised what they claimed were 75 million Revolut customer records on a cybercrime forum. Researchers at Cybernews reviewed sample data containing names, email addresses, phone numbers, addresses, device details, and some partial card details and hashed credentials. That does not make the breach established — quite the opposite.

?
This is a claim, not a confirmed breach

Revolut told Cybernews it sees no indication of a breach in its systems. The researchers could not verify the 75 million figure and consider it possible the data was assembled from several older sources. Until that is resolved we treat this explicitly as an unverified claim, not a confirmed breach.

!
Claimed contents
Email addressNamePhone numberPhysical addressPartial card detailsDevice informationHashed credentials

Claimed by the seller: 75.000.000 / 75,000,000

Source: Cybernews ↗

What to do either way

Whether or not the claim holds up, data appearing in a collection like this has usually come from several earlier breaches anyway. Use the free check below to see whether your email address appears in known leaks, and turn on two-factor authentication on Revolut as on any financial account. Expect phishing that references your account convincingly: Revolut will never ask for your PIN, password or a confirmation code by SMS or phone.

Check whether your email is in this or any other breach

Free, no signup. Runs against real breach databases.

What you can demand right now

1
Ask what they hold — GDPR Article 15

You can require the company to tell you exactly what data it has about you, and give you a free copy. It has one month to answer.

2
Demand deletion — GDPR Article 17

You can require them to erase your personal data. Also one month, also free of charge.

3
Complain to your data protection authority

If they ignore you or refuse without valid grounds, you can file a free complaint. Regulators can investigate and fine.

Open the free GDPR letter generator →

Why leaked data keeps resurfacing

A leaked email and phone number don't just sit in one dump — data brokers buy breach data, merge it with public records, and resell it. That's why the spam calls and phishing texts keep coming months later. Deleting your data from the breached company is only the first step; getting it out of the broker network is what actually stops the follow-on damage.

Check your exposure for free

Whatever comes of this claim, you can see right now whether your details already appear in known breaches — no signup, no payment.

Open the free tools →

Last updated 28 July 2026. We update this page as the situation develops.