Revolut Customers Targeted with New Wave of Phishing Attacks
Phishers target Revolut customers with smishing and fake video identity checks days after a breach enabled by impersonating Italian law enforcement.
Malwarebytes documented smishing texts arriving within days of Revolut's breach acknowledgment, some appearing in the same message thread as genuine bank texts. Phishing pages mimic the bank's live-video identity check, requesting camera access before prompting for passwords, potentially harvesting selfies and videos for identity fraud. The underlying breach targeted Revolut's Lithuanian-regulated entity through fake European Investigation Orders sent from Italian Ministry of the Interior email accounts compromised for about six months via infostealer logs. Several hundred accounts were affected, with high-net-worth crypto users singled out using blockchain analysis.
- Smishing texts arrived two days after Revolut acknowledged the breach
- Fake liveness check requests camera access, then collects passwords
- Attackers impersonated Italian police using Ministry of Interior emails held for six months
- Several hundred accounts hit; high-net-worth crypto users targeted via blockchain analysis
Full article425 words · extracted from infosecurity-magazine.com · click to collapse
Hackers have seized on a data breach at digital financial firm Revolut to try and harvest more account information from customers, according to Malwarebytes.
The security vendor said it had uncovered several examples of Revolut customers receiving smishing messages by text. One arrived on September 14, just two days after the bank acknowledged the incident.
In one example, the scam message apparently appeared in the same conversation on the victim's device as other Revolut texts, making it appear like a legitimate message.
The message urged the recipient to follow a link in order to confirm their identity, or else have access to their account restricted.
Read more on Revolut: Revolut Confirms Data Breach Through Fake Government Requests.
A separate customer said that opening the link took them to a web page that requested access to their device camera. Clicking “allow” reportedly initiated what appeared to be the bank’s live-video identity check, before prompting the user to enter their password.
“This makes the phishing page appear more authentic. It may also allow the scammers to collect a selfie or video that could be used for further social engineering, identity fraud, or to make subsequent scams more convincing,” wrote Malwarebytes.
“A convincing fake liveness check followed by a password screen is a common way to lower suspicion and obtain the information attackers need to attempt a real login or account-recovery flow.”
The security vendor warned that if the campaign is linked to the breach itself, rather than simply an opportunistic effort to steal account info, it could give the hackers enough info to hijack victims’ accounts.
Revolut Customers Urged to Remain Cautious
In the meantime, Malwarebytes encouraged Revolut customers to
- Not follow links in unsolicited messages, and go directly to the app if notified about an account issue
- Check the domain in the browser address bar to check it’s legitimate
- Use an up-to-date, real-time anti-malware solution on device
Details continue to emerge about the breach itself. It appears that it targeted the bank’s Lithuanian-regulated entity because it is legally obliged to respond to European Investigation Orders.
To send Revolut the fake requests for KYC information, the threat actors impersonated Italian law enforcement by compromising Italian Ministry of the Interior email accounts using infostealer logs.
They claimed to have had access to these accounts for around six months, allowing them to submit multiple fraudulent data requests without raising suspicion.
Several hundred accounts are thought to have been impacted, with high-net worth crypto users singled out for targeting after the threat actors analyzed blockchain records, according to various reports.