www.malwarebytes.com 17 Sept 2026, 14:07 UTC

Revolut Customers Targeted by Phishing Days After Data Breach Disclosed

Revolut Customers Targeted by Phishing Days After Data Breach Disclosed
CyberSIXT Evidence Panel Source marked as original reporting

REVOLUT customers began receiving phishing texts days after the company acknowledged that sensitive customer records had been disclosed to an unauthorised party. Revolut reportedly accepted fraudulent information requests sent from an email address on a legitimate government agency domain, exposing a limited or very limited number of customers’ identity and contact details, identity-document copies, verification selfies, account statements and transaction histories. The company said it had contacted affected customers directly.

One customer received a message on Monday, 14 September, two days after the breach was publicly acknowledged. The text appeared in the same conversation as genuine Revolut messages, making it look as though it came from the bank. VirusTotal records show that the phishing domain was first scanned that day. In another reported case, the link requested camera access and displayed a fake Revolut “turn your head” live-video identity check before asking for a password.

This could harvest selfies or video for further social engineering or identity fraud, while passwords could support account takeover or recovery attempts.

Malwarebytes said it does not yet know whether the campaign used information from the breach or whether unrelated criminals are exploiting news of the incident. Customers should avoid links in unsolicited messages and open the official Revolut app directly instead. They should also check the actual website domain before entering information.

View full article

Article by CyberSIXT