Breaking
Cyber CrimeDeveloping Story

Revolut Phishing Wave Puts KYC Data at Risk

Malwarebytes reports smishing attacks mimicking Revolut's identity checks after a breach of the bank's Lithuanian entity.

··2 hours ago·6 min read
black iphone 5 on yellow textile
Photo by Franck on Unsplash

A text message arrives on a Revolut customer's phone, slipping into the same conversation thread as genuine alerts from the bank. It warns that access to the account will be restricted unless the recipient confirms their identity through a link. According to Malwarebytes, several such messages have been targeting Revolut customers, with one arriving on September 14 — just two days after the digital bank acknowledged a data breach.

A Breach as Phishing Bait

The security vendor said it uncovered multiple examples of smishing messages sent to Revolut users. In one case, the scam text appeared in the same conversation on the victim's device as other legitimate Revolut texts, making it blend in with real bank communications.

The message urged recipients to follow a link to confirm their identity or risk having account access restricted. A separate customer reported that opening the link led to a webpage requesting access to their device camera. Clicking allow reportedly initiated what appeared to be the bank's live-video identity check, before prompting the user to enter their password.

Malwarebytes wrote that this approach makes the phishing page appear more authentic and may allow scammers to collect a selfie or video for further social engineering, identity fraud, or to make later scams more convincing. The vendor also noted that a convincing fake liveness check followed by a password screen is a common way to lower suspicion and obtain the information attackers need to attempt a real login or account-recovery flow.

This makes the phishing page appear more authentic. It may also allow the scammers to collect a selfie or video that could be used for further social engineering, identity fraud, or to make subsequent scams more convincing.

— Malwarebytes

The security vendor warned that if the campaign is linked to the breach itself, rather than simply an opportunistic effort to steal account info, it could give the hackers enough information to hijack victims' accounts.

Inside the Revolut Breach

Details about the underlying breach continue to emerge. According to various reports, the incident targeted the bank's Lithuanian-regulated entity because it is legally obliged to respond to European Investigation Orders.

To send Revolut the fake requests for KYC information, the threat actors impersonated Italian law enforcement by compromising Italian Ministry of the Interior email accounts using infostealer logs. They claimed to have had access to these accounts for around six months, allowing them to submit multiple fraudulent data requests without raising suspicion.

Several hundred accounts are thought to have been impacted, with high-net worth crypto users singled out for targeting after the threat actors analyzed blockchain records, according to those reports.

What Customers Are Being Told

Malwarebytes encouraged Revolut customers to take several precautions in response to the phishing wave. The vendor's advice includes:

  • Do not follow links in unsolicited messages, and go directly to the app if notified about an account issue.
  • Check the domain in the browser address bar to verify it is legitimate.
  • Use an up-to-date, real-time anti-malware solution on the device.

The phishing messages described by Malwarebytes rely on a sense of urgency — warning of restricted access — to push recipients into clicking without verifying the sender. The fact that some of these texts appear alongside genuine Revolut communications on a victim's device makes that verification harder for the recipient.

The scammers' use of a fake live-video identity check adds another layer to the deception. By requesting camera access, the page mimics a process that Revolut customers may already associate with account security. The prompt for a password after the apparent liveness check follows a pattern that Malwarebytes said is designed to lower suspicion and gather login credentials or account-recovery information.

A Breach Built on Impersonation

The breach itself, as described in reports, involved impersonating Italian law enforcement to send fraudulent requests for KYC information to Revolut's Lithuanian entity. That entity is legally obliged to respond to European Investigation Orders, which the attackers exploited by compromising Italian Ministry of the Interior email accounts through infostealer logs.

The threat actors claimed to have maintained access to these email accounts for around six months. That window allowed them to submit multiple fraudulent data requests without raising suspicion. Several hundred accounts are thought to have been impacted.

The targeting of high-net worth crypto users came after the threat actors analyzed blockchain records, according to the reports. Those reports indicate that the attackers used that analysis to single out particular accounts for attention.

How the Phishing Pages Work

The phishing pages described by Malwarebytes begin with a link in a text message. Once opened, the page requests access to the device camera. If the user clicks allow, what appears to be the bank's live-video identity check begins. The page then prompts the user to enter their password.

Malwarebytes wrote that a convincing fake liveness check followed by a password screen is a common way to lower suspicion and obtain the information attackers need to attempt a real login or account-recovery flow. The vendor also noted that the camera access could yield a selfie or video for use in further social engineering, identity fraud, or to make subsequent scams more convincing.

The phishing messages themselves are designed to look like they belong in the same conversation thread as other Revolut texts. One message arrived on September 14, two days after the bank acknowledged the incident. The message urged the recipient to follow a link to confirm their identity or else have access to their account restricted.

What Malwarebytes Says About the Risks

Malwarebytes warned that if the campaign is linked to the breach itself, rather than simply an opportunistic effort to steal account info, it could give the hackers enough information to hijack victims' accounts.

The vendor's recommendations focus on three areas: avoiding links in unsolicited messages and going directly to the app, checking the domain in the browser address bar, and using an up-to-date, real-time anti-malware solution on the device.

For Revolut customers, the immediate concern is distinguishing between genuine bank communications and phishing attempts that mimic them. The smishing messages described by Malwarebytes appear to be designed to make that distinction difficult, particularly when they arrive in the same thread as legitimate texts.

The Broader Picture

The incident at Revolut's Lithuanian entity shows how regulatory obligations can be turned into an attack vector. European Investigation Orders require the entity to respond to requests for information. The threat actors impersonated Italian law enforcement and compromised Italian Ministry of the Interior email accounts to send fraudulent KYC requests.

The six-month access window the attackers claimed allowed them to submit multiple fraudulent data requests without raising suspicion. Several hundred accounts are thought to have been impacted, with high-net worth crypto users singled out after blockchain records were analyzed, according to various reports.

The phishing wave that followed the breach, as reported by Malwarebytes, relies on the trust customers place in messages that appear alongside legitimate bank communications. The vendor's advice to go directly to the app rather than following links is intended to break that pattern of trust.

What This Means for Customers and Banks

For Revolut customers, the phishing messages described by Malwarebytes highlight the difficulty of telling a real bank communication from a fake one when both appear in the same text thread. The vendor's guidance — avoid links in unsolicited messages, go directly to the app, check the browser address bar, and use real-time anti-malware — is aimed at reducing that risk.

For financial institutions, the breach at Revolut's Lithuanian entity illustrates how legal obligations to respond to European Investigation Orders can be exploited when attackers gain access to the email accounts of the authorities making those requests. The compromise of Italian Ministry of the Interior email accounts using infostealer logs allowed fraudulent KYC requests to be sent for around six months before suspicion was raised, according to reports.

The connection between the breach and the phishing wave may become clearer as more details emerge. For now, Malwarebytes has warned that if the campaign is linked to the breach, it could give the hackers enough information to hijack victims' accounts. The vendor's advice remains focused on customer vigilance and direct verification through the Revolut app.

#revolut#phishing#data breach#smishing#kyc#malwarebytes

Sources

Iliyas

Founder & Editor, Xploitwire

This article was written and reviewed against the sources listed above before publication, under editorial policies set by Iliyas. Read our Editorial Policy →

← Back to all stories