Revolut phishing texts appear days after data breach
Phishing texts impersonating Revolut targeted customers days after the fintech disclosed a social-engineering breach exposing IDs, verification selfies, and statements.
Revolut disclosed that criminals obtained sensitive customer data by sending fraudulent information requests from an email address on a legitimate government agency domain, exposing names, dates of birth, addresses, ID copies, verification selfies, and account statements. Within days, affected customers received smishing texts appearing in the same message thread as genuine Revolut messages, with the phishing domain first scanned on September 14 per VirusTotal. The fake page requests camera access and imitates Revolut's live-video liveness check before prompting for a password, potentially enabling account takeover; a link to the breach data is not yet confirmed.
- Breach stemmed from fraudulent information requests on a legitimate government agency email domain
- Exposed data includes passports, driver's licenses, verification selfies, and transaction histories
- Phishing texts arrived in the same SMS thread as legitimate Revolut messages
- Fake page mimics Revolut's video liveness check, requests camera access, then a password
- Whether the campaign uses breached data remains unconfirmed
Full article511 words · extracted from malwarebytes.com · click to collapse
Only days after Revolut acknowledged that it disclosed sensitive customer records to an unauthorized party, affected customers are receiving phishing texts. However, we don’t know yet if the phishing texts are linked to the breach.
The company had accepted fraudulent information requests sent from an email address on a legitimate government agency domain.
Through this social engineering attack, rather than by gaining access to Revolut’s systems, the criminals obtained the following types of information about customers:
- Identity and contact information such as dates of birth, postal addresses, email addresses, and phone numbers
- Copies of IDs such as passports and driver’s licenses
- Verification selfies
- Account statements and transaction histories
Revolut has said only that a “limited” or “very limited” number of customers were affected, and that it contacted them directly.
One affected customer received a phishing text on Monday, September 14, two days after Revolut publicly acknowledged the data breach. The message appeared in the same conversation as other Revolut texts, making it look as though it had come from the bank.

According to VirusTotal, the phishing domain was first scanned that same day.
In a separate example, another customer said that opening the link took them to a web page that requested access to their device’s camera. If you tap Allow, the page reportedly imitates Revolut’s live-video “turn your head” identity check before prompting you to enter a password.
This makes the phishing page appear more authentic. It may also allow the scammers to collect a selfie or video that could be used for further social engineering, identity fraud, or to make subsequent scams more convincing.
A convincing fake liveness check followed by a password screen is a common way to lower suspicion and obtain the information attackers need to attempt a real login or account-recovery flow.
If the campaign is connected to the breach, the information obtained from Revolut, combined with login details entered by victims or their approval of a login request, could be enough to take over their accounts.
How to stay safe
We don’t yet know whether the phishing campaign is using data exposed in the breach or whether unrelated scammers are exploiting news of the incident to target Revolut customers more broadly.
Either way, treat unexpected messages about your account with caution:
- Don’t follow links in unsolicited messages. If a message concerns your account, open the official Revolut app directly.
- Check the actual domain in your browser’s address bar to see if it corresponds with what you expect.
- Use an up-to-date, real-time anti-malware solution on your device, preferably with a web protection component.
- Malwarebytes Scam Guard can help you determine whether a message is a scam and advise you on what to do next.
Stop threats before they can do any harm.
Malwarebytes Browser Guard blocks phishing pages and malicious sites automatically. Free, one click to install. Add it to your browser →
About the author
Was a Microsoft MVP in consumer security for 12 years running. Can speak four languages. Smells of rich mahogany and leather-bound books.
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.malwarebytes.com/blog/threat-intel/2026/09/revolut-phishing-texts-appear-days-after-data-breach