Revolut users' personal information has reportedly leaked, according to an unconfirmed newsflash circulating without a verified date or an identified incident, leaving the central claim, its
Revolut users' personal information has reportedly leaked, according to an unconfirmed newsflash circulating without a verified date or an identified incident, leaving the central claim, its scope and its timing unverified against readable primary reporting at press time on September 12, 2026.
What the report alleges, and what evidence actually confirms
The Revolut data leak claim, as supplied, states only that users' personal information was exposed; it identifies no data fields, no affected-user count, no geography and no exposure mechanism, and the originating tip was deliberately left unfetched because neither its publication date nor a specific incident could be matched to readable sources. For related coverage, see Revolut Launches Euro-Pegged EURR Stablecoin: What It Means.
That gap matters because Revolut has a documented history here: in reporting published September 20, 2022, Revolut spokesperson Michael Bodansky confirmed to TechCrunch that an unauthorized third party accessed some customers' personal details for a short period. The current allegation should not be collapsed into that confirmed 2022 event. For related coverage, see Aavegotchi GHST Honeypot Flag: What On-Chain Data Can Show.
As of now, the leak described in the headline sits in the unverified column; per the underlying research, fetched historical sources establish past unauthorized access, not the public release of any new dataset, and the claim that any such data was published or offered for sale rests on unconfirmed reports alone.
The supplied headline references only "personal information" in the broad sense, with no verified schedule of exposed fields, no user tally, no jurisdictional breakdown and no stated financial impact tied to the new allegation.
The only attributable field-level detail comes from the 2022 incident: Bitdefender reported that Lithuania's State Data Protection Inspectorate identified potentially exposed email addresses, full names, postal addresses, phone numbers, limited payment-card data and account-related information, according to that vendor's write-up. Those categories describe a prior event, not proof of the current claim.
On scope, TechCrunch reported that Revolut's disclosure to Lithuanian authorities counted 50,150 affected customers, including 20,687 in the European Economic Area and 379 Lithuanian citizens, in the September 2022 incident; the regulator page itself could not be read directly in this research.
Revolut · September 2022 incident
50,150
Affected customers in the reported 2022 disclosure
TechCrunch reported that Revolut's disclosure to Lithuanian authorities counted 50,150 affected customers in the September 2022 incident. The regulator filing was not directly readable in this research. This historical count does not verify a new leak or public release of records.
The affected share was described by the spokesperson as 0.16%, a figure TechCrunch explicitly flagged as not reconciling with the roughly 20 million customer total on the company's website at that time, meaning the affected count should not be derived from that percentage.
Account access and financial impact
Personal-data exposure is distinct from credential compromise, unauthorized account access and loss of funds, and the current allegation supports none of the latter three. For the 2022 event, Revolut told TechCrunch that no funds were accessed or stolen, an assurance from the company rather than an independent forensic finding.
That distinction is not academic: TechCrunch identified an unresolved gap between a customer notice saying no card details, PINs or passwords were accessed and the regulatory disclosure describing likely access to partial card-payment data, so no unconditional claim that all card data was untouched can be made even for the historical case. For the newly alleged leak, there is no evidence that funds are either at risk or safe.
Revolut's response and the report's verification status
No Revolut statement, customer notice, regulator communication or independent confirmation tied specifically to the new allegation was obtained in this research; the absence of a supplied statement is not evidence of company silence, and it should not be read that way.
The one on-record company voice available is historical. Bodansky's 2022 comment, given to the outlet that originally reported the breach, reads:
"We immediately identified and isolated the attack to effectively limit its impact and have contacted those customers affected," Michael Bodansky, a Revolut spokesperson, told TechCrunch in September 2022.
For that 2022 incident, Revolut discovered malicious access late on September 11 and isolated the attack by the following morning, according to TechCrunch's corrected account, with Bitdefender corroborating the September 11 timing. Revolut held a Lithuanian banking licence at the time, and both reports cite a breach disclosure to Lithuania's State Data Protection Inspectorate; no fine or final regulatory finding was verified.
What remains conditional for the current headline is nearly everything material: the incident identity, the reporting date, the cause, the extent of any exposure, and whether records were released rather than merely accessed. Revolut's regulatory footprint is expanding, having secured conditional OCC approval for a U.S. national bank charter, which raises the stakes for how any confirmed data event is disclosed and handled.
Precautions Revolut users can take now
These are general precautions, not incident-specific instructions, and none of them implies any given user is affected or that a leak has been confirmed.
Check official notices and account activity
Open the official Revolut app directly, rather than following any link received by message, to review in-app notices and recent transactions; direct app access avoids spoofed pages that mimic breach alerts. Reviewing your own transaction history is the fastest firsthand verification available to any account holder.
Watch for suspicious messages
For the 2022 event, TechCrunch reported that Revolut warned customers about phishing and said it would not call or send SMS messages requesting login data or access codes, a pattern worth applying generally. Avoid unsolicited links and any request for passwords, verification codes or transfers, and route genuinely suspicious account activity to support through the official app rather than a message-supplied channel. These steps reduce phishing exposure but do not reverse any leak, and no phishing wave has been verified in connection with the current claim.
Data-handling failures at consumer platforms are not unique to any one firm; the OpenSea email-provider incident that exposed millions of users and the Coinbase user concerns over subpoenaed data both show how third-party access and disclosure obligations, rather than direct fund theft, often drive the harm.
Revolut data leak FAQ
Has the Revolut data leak been confirmed?
No. No confirming evidence for the current allegation was obtained; readable primary reporting documents a separate, confirmed September 2022 incident, and this answer should be updated only if attributable verification of a new event becomes available.
The supplied context does not identify any data fields for the current claim. The field categories cited above, including email addresses, names and limited card data, come from Bitdefender's account of the 2022 incident, not from verified reporting on a new leak.
How many Revolut users are affected?
No count can be provided for the current allegation without verified supporting evidence. The 50,150 figure belongs to the 2022 disclosure and must not be applied to any new event.
Does the report mean money was stolen?
No. A personal-information leak allegation does not establish theft of funds; even in the 2022 case, the company's no-funds-stolen statement was an assurance, not an independent forensic conclusion.
What to watch next: a dated, attributable disclosure, either a Revolut customer notice or a readable Lithuanian regulator filing, is the concrete trigger that would move this story from unconfirmed allegation to verified incident, and until one appears, treat the leak claim as reported but unproven.
Disclaimer: This article is for informational purposes only and does not constitute financial or investment advice. Cryptocurrency and digital asset markets carry significant risk. Always do your own research before making decisions.
The post Revolut Data Leak: Personal Information Reportedly Exposed was initially published on Coincu.