The quantity sounds enormous at first: a database that a cybercriminal is currently offering on the dark web is said to comprise 75 million entries. The data allegedly comes from the neobank Revolut. However, there are indications that this is not an acute new data leak.
On X, "Intel and Breaches" reported on the darknet offer. The data is said to affect more than 75 million users. The entries reportedly include payment card information such as card scheme, status, creation, and other metadata. In addition, there are several CSV datasets with user-related information such as email addresses, names, and phone numbers. The dataset is for sale for 500 US dollars, which would be a low price for such current data. The perpetrator provides an excerpt of 100 entries as a sample. The account „Dark Web Intelligence“ points out on X that the public post contains no specific number of records, no technical details, or attack vectors.
In response to a request from heise online, a spokesperson for Revolut Germany replied: “We have compared the user and card identifiers contained in the sample data of the original post with our systems. None of them correspond to a valid or real Revolut identifier.” The verification of further claims is still ongoing, but so far the neobank has found no indications of a security breach. The spokesperson also points to external analyses, according to which “the dataset is likely a compilation of data from various sources” rather than a new data protection incident. There too, the stated number of records could not be verified.











