Revolut phishing texts appear days after data breach

Imported from official source

Cybersecurity Classified by Officially

Only days after Revolut acknowledged that it disclosed sensitive customer records to an unauthorized party, affected customers are receiving phishing texts. However, we don’t know yet if the phishing texts are linked to the breach.

The company had accepted fraudulent information requests sent from an email address on a legitimate government agency domain.

Through this social engineering attack, rather than by gaining access to Revolut’s systems, the criminals obtained the following types of information about customers:

  • Identity and contact information such as dates of birth, postal addresses, email addresses, and phone numbers
  • Copies of IDs such as passports and driver’s licenses
  • Verification selfies
  • Account statements and transaction histories

Revolut has said only that a “limited” or “very limited” number of customers were affected, and that it contacted them directly.

One affected customer received a phishing text on Monday, September 14, two days after Revolut publicly acknowledged the data breach. The message appeared in the same conversation as other Revolut texts, making it look as though it had come from the bank.

Phishing text to a Revolut customer

According to VirusTotal, the phishing domain was first scanned that same day.

In a separate example, another customer said that opening the link took them to a web page that requested access to their device’s camera. If you tap Allow, the page reportedly imitates Revolut’s live-video “turn your head” identity check before prompting you to enter a password.

This makes the phishing page appear more authentic. It may also allow the scammers to collect a selfie or video that could be used for further social engineering, identity fraud, or to make subsequent scams more convincing.

A convincing fake liveness check followed by a password screen is a common way to lower suspicion and obtain the information attackers need to attempt a real login or account-recovery flow.

This is an extract. The publication continues at the source.

Read the original at the source: https://www.malwarebytes.com/blog/threat-intel/2026/09/revolut-phishing-texts-appear-days-after-data-breach

Officially imported this from Malwarebytes’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.

Provenance

Organization
Malwarebytes — imported from official source
Official source
https://www.malwarebytes.com/blog/feed/index.xml RSS
Imported
September 20, 2026 19:52
Versions
1 recorded
Identity
https://www.malwarebytes.com/blog/threat-intel/2026/09/revolut-phishing-texts-appear-da...

Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.