Skip to main content
Emerging ThreatsMalware & Ransomware

Revolut Phishing Attacks Surge After Data Breach

Person looks concerned at smartphone with laptop nearby, text message conversation visible.

“This makes the phishing page appear more authentic. It may also allow the scammers to collect a selfie or video that could be used for further social engineering, identity fraud, or to make subsequent scams more convincing,” wrote Malwarebytes.

Malwarebytes uncovers a fresh smishing wave

Security vendor Malwarebytes reported that hackers have seized on a data breach at digital financial firm Revolut to try and harvest more account information from customers. The vendor said it had uncovered several examples of Revolut customers receiving smishing messages by text. One of those scam texts arrived on September 14, just two days after the bank acknowledged the incident.

In at least one example the scam message appeared in the same conversation on the victim's device as other Revolut texts, increasing its apparent legitimacy. The message urged the recipient to follow a link in order to confirm their identity, or else have access to their account restricted.

Fake liveness checks: camera access and password prompts

Malwarebytes detailed a reported sequence that illustrates how the campaign sought to lower victims’ defenses. A separate customer said that opening the link took them to a web page that requested access to their device camera. Clicking “allow” reportedly initiated what appeared to be the bank’s live-video identity check, before prompting the user to enter their password.

Malwarebytes explained why that sequence is effective: “A convincing fake liveness check followed by a password screen is a common way to lower suspicion and obtain the information attackers need to attempt a real login or account-recovery flow.” The vendor added that the camera step “may also allow the scammers to collect a selfie or video that could be used for further social engineering, identity fraud, or to make subsequent scams more convincing.”

Attack chain centered on Revolut’s Lithuanian-regulated entity and compromised Italian emails

Details released about the underlying breach point to a targeted approach. It appears the incident targeted Revolut’s Lithuanian-regulated entity because that unit is legally obliged to respond to European Investigation Orders. To send Revolut the fake requests for KYC information, the threat actors impersonated Italian law enforcement by compromising Italian Ministry of the Interior email accounts using infostealer logs.

According to the reporting, the threat actors claimed to have had access to those ministry accounts for around six months, allowing them to submit multiple fraudulent data requests without raising suspicion. Malwarebytes warned that if the smishing campaign is linked to the breach itself, rather than simply an opportunistic effort to steal account information, it could give the hackers enough info to hijack victims’ accounts.

Scale and targeting: several hundred accounts and high-net-worth crypto users

Reports say several hundred accounts are thought to have been impacted. Investigators also noted the threat actors singled out high-net-worth crypto users for targeting after they analyzed blockchain records. Those details come from various reports referenced by the security vendor.

Revolut customers urged to remain cautious

While investigations continue, Malwarebytes encouraged Revolut customers to take specific steps to protect themselves:

  • Not follow links in unsolicited messages, and go directly to the app if notified about an account issue
  • Check the domain in the browser address bar to check it’s legitimate
  • Use an up-to-date, real-time anti-malware solution on device

Malwarebytes’ findings stitch together a multi-part campaign: a breach that leverages regulatory pathways, compromised government emails used to request KYC data, and follow-on smishing that attempts to harvest camera-captured liveness evidence and passwords. The combination, the vendor warns, raises the risk that attackers could assemble the data needed to attempt real logins or account-recovery flows.

For readers tracking the story: investigators report months-long access to Italian Ministry of the Interior mailboxes, targeting of Revolut’s Lithuanian-regulated entity, and a second-stage smishing campaign observed within days of public acknowledgement of the incident. Customers affected or worried about potential compromise should follow the precautions Malwarebytes recommends and monitor communications carefully.

Original story