Revolut Customers Targeted with New Wave of Phishing Attacks
AI-summarised brief · reviewed before publication
Hackers have exploited a recent Revolut data breach to launch a smishing campaign targeting the fintech firm’s customers, Malwarebytes reported. The phishing texts, first seen on September 14, mimicked legitimate Revolut messages and urged recipients to click a link to “confirm their identity” or face account restrictions. The link directed users to a counterfeit live‑video verification page that requested camera access, then prompted for passwords, allowing attackers to capture selfies or videos for further fraud. Malwarebytes warned that if the campaign is tied to the breach, criminals could obtain enough personal data to hijack accounts. The breach appears to have focused on Revolut’s Lithuanian‑regulated entity, with threat actors impersonating Italian law enforcement to submit fraudulent KYC requests, affecting several hundred accounts, notably high‑net‑worth crypto users.
💡 Why It Matters
- · The fake video‑verification trick turns a routine security step into a weapon, giving scammers biometric data that can bypass traditional authentication methods.