AI & TechBigTech CompaniesCybersecurityFintechNewswire

New Phishing Attacks Target Revolut Customers

▼ Summary

– Hackers are exploiting a recent Revolut data breach to send smishing messages targeting customers with fake identity verification requests.
– The malicious links direct users to counterfeit pages that mimic live-video checks to harvest passwords and device camera access for further fraud.
– Malwarebytes warns that these sophisticated scams aim to hijack accounts by lowering victim suspicion through realistic-looking security protocols.
– The original breach involved threat actors impersonating Italian law enforcement via compromised email accounts to issue fraudulent data requests.
– Several hundred high-net-worth crypto users were specifically targeted after attackers analyzed blockchain records to identify valuable targets.

Cybercriminals are launching sophisticated phishing campaigns against Revolut users, exploiting a recent security incident to steal sensitive account credentials. According to the cybersecurity firm Malwarebytes, attackers have begun sending deceptive text messages, known as smishing, to customers shortly after the fintech giant confirmed a data breach. The first observed attack arrived on September 14, merely two days after Revolut publicly acknowledged the compromise.

These malicious messages are designed to blend seamlessly into existing communication threads. In one notable instance, the scam appeared within an ongoing chat window containing other legitimate messages from Revolut, making it difficult for recipients to distinguish the fraud from official bank communications. The text pressured victims to click a provided link to verify their identity, warning that failure to do so would result in restricted access to their accounts.

Advanced Social Engineering Tactics

The deception goes beyond simple credential harvesting. One customer reported that clicking the malicious link redirected them to a webpage demanding permission to access their device’s camera. Upon granting this permission, the interface mimicked the bank’s live-video identity verification process. Once the video feed was active, the page prompted the user to enter their password.

“This makes the phishing page appear more authentic. It may also allow the scammers to collect a selfie or video that could be used for further social engineering, identity fraud, or to make subsequent scams more convincing,” wrote Malwarebytes.

“A convincing fake liveness check followed by a password screen is a common way to lower suspicion and obtain the information attackers need to attempt a real login or account-recovery flow.”

Security experts warn that if these attacks are directly tied to the initial breach rather than being opportunistic, hackers may possess enough stolen data to fully hijack victim accounts. The combination of verified identity footage and passwords creates a powerful toolkit for unauthorized access.

Origins of the Breach

Details regarding how the original breach occurred continue to surface. The attack targeted Revolut’s Lithuanian-regulated entity because local laws require compliance with European Investigation Orders. Threat actors exploited this legal framework by impersonating Italian law enforcement. They compromised email accounts belonging to the Italian Ministry of the Interior using infostealer logs obtained over approximately six months.

This prolonged access allowed the criminals to submit multiple fraudulent requests for Know Your Customer (KYC) information without raising immediate suspicion. Reports indicate that several hundred accounts were impacted. Notably, high-net-worth cryptocurrency users were specifically targeted after attackers analyzed blockchain records to identify valuable assets.

Safety Recommendations

In light of these developments, Malwarebytes has issued urgent guidance for Revolut customers to protect themselves from similar attacks. Users are advised to exercise extreme caution when receiving unsolicited communications. If a message claims there is an issue with your account, do not follow any embedded links. Instead, open the official Revolut app directly to verify the status of your account.

Additionally, users should carefully inspect the domain name in their browser’s address bar to ensure it matches the legitimate Revolut website. Finally, ensuring that your device is protected by an up-to-date, real-time anti-malware solution can help detect and block these malicious attempts before they succeed.

(Source: Infosecurity Magazine)

Topics

cybersecurity breach 95% social engineering 90% identity fraud 85% financial security 80% threat actor tactics 75%
Show More