HACKERS are exploiting Revolut’s recently disclosed data breach in a new wave of smishing attacks, according to Malwarebytes. The security company identified several text messages sent to Revolut customers, including one received on 14 September, two days after the firm acknowledged the incident. At least one message appeared in the same conversation as genuine Revolut texts, making it seem legitimate, and urged the recipient to click a link to confirm their identity or risk account restrictions.
In another reported case, the link opened a page requesting access to the device’s camera. After the user selected “allow”, the site displayed what appeared to be Revolut’s live-video identity check before asking for the account password. Malwarebytes said the fake liveness check could be used to collect a selfie or video for further social engineering, identity fraud or more convincing follow-up scams.
It warned that, if the campaign is connected to the breach, the stolen information could help attackers hijack accounts, although that link has not been confirmed.
Malwarebytes advised customers not to use links in unsolicited messages, instead accessing Revolut directly through its app, and to check website domains carefully. Reports indicate the breach targeted Revolut’s Lithuanian-regulated entity through fraudulent European Investigation Orders. Attackers allegedly impersonated Italian law enforcement after compromising Italian Ministry of the Interior email accounts using infostealer logs, claiming access for around six months. Several hundred accounts are thought to have been affected, with high-net-worth crypto users reportedly singled out after blockchain analysis.