Data breach
The Revel Collective
- Records
- 3,289,441
- Breach date
- 21 August 2026Estimated
- Added
- 7 September 2026
What was exposed
5 types of data
- Email addresses3,289,441
- Names1,851,232
- Phone numbers915,273
- Dates of birth227,728
- Street addresses42,811
About this breach
The Revel Collective, a UK hospitality company operating a portfolio of bars and social venues, has been listed as a victim by the direwolf ransomware group. According to our investigation team, the listing points to an estimated attack date of August 21, 2026, and the breach database added for this incident contains roughly 3.29 million records. The claim originates from the group's leak site, which is an extortion claim rather than a confirmation from the company or a regulator. As of September 25, 2026, The Revel Collective has not publicly confirmed an incident or notified customers through a statement that we could locate.
Limited public reporting: As of September 25, 2026, detailed company notices or major news coverage for this listing were limited in sources reviewed. The facts below rely primarily on the indexed fields plus any secondary sources cited.
Breach Timeline
August 21, 2026: The direwolf ransomware group listed The Revel Collective on its leak site, a claim recorded by Ransomware.live trackers and Recent Breaches.
August 22, 2026: Breachsense recorded the incident, citing a leak size of 700GB tied to the company's website.
What Information Was Compromised?
Our analysis found the following data types in this breach: email addresses across the full set of roughly 3.29 million records, names in about 1.85 million records, phone numbers in about 915,000 records, birthdays in about 228,000 records, and street addresses in about 43,000 records. These figures come from the investigation team, which indexes the leaked dataset. The leak site listing itself did not itemise data types, and no company notice listing additional fields was available when we reviewed the material.
Not every individual is affected by every type of data listed here.
What Are the Potential Risks for Affected Individuals?
Contact details paired with names and birthdays give criminals the raw material for targeted phishing. A message that references your birthday or a booking can look far more convincing than generic spam. Phone numbers open the door to smishing, fraudulent texts that impersonate brands, delivery services, or banks.
Where an email address is linked to an online account, attackers may attempt account takeover, particularly if the same password was reused elsewhere. Street addresses and birthdays can also support identity fraud attempts and convincing social engineering calls. Because the company has not confirmed what was taken, treat these as possible risks rather than certainties.
What Should You Do If You Were Affected?
If you booked with or worked for The Revel Collective or its venues, take these steps:
Change passwords on any accounts tied to an email address you used with the company, and enable multi-factor authentication where it is offered.
Be sceptical of unexpected emails, texts, or calls that mention bookings, refunds, or account problems. Reach companies through their official website or app instead of links in messages.
Watch bank and card statements for charges you do not recognise, and consider asking your card issuer for alerts or a replacement card if anything looks wrong.
Keep records of suspicious contact that names the company, in case a formal investigation follows.
If The Revel Collective publishes a confirmation or a customer notice, follow any specific guidance it provides.
In the news
- Recent Breaches, The Revel Collective Ransomware Claim (2026)recentbreaches.com (opens in a new tab)
- Data Breach Watch, The Revel Collective listingdatabreach.watch (opens in a new tab)
- CYBERCRIME.works, direwolf ransomware group trackercybercrime.works (opens in a new tab)
- Breachsense, The Revel Collective data breach reportbreachsense.com (opens in a new tab)
