Security News

Scammers Exploit Revolut Data Breach with Fake Identity-Check Texts

Infosecurity Magazine · 21 Sept 2026
Key Takeaway Never grant camera access or enter passwords via links in unsolicited texts; always verify identity requests directly through the official Revolut app or website.

Security firm Malwarebytes has identified a wave of phishing text messages targeting Revolut customers in the days following the company's disclosure of a data breach. The messages appear alongside genuine Revolut texts on victims' phones, making them look legitimate, and urge recipients to click a link to confirm their identity or risk losing account access.

One victim reported that clicking the link led to a fake page requesting camera access, which then simulated Revolut's real live-video identity check before asking for a password. Malwarebytes warned this tactic makes the scam more convincing and could also let attackers capture photos or video for future fraud attempts. If this campaign is connected to the original breach, it could give criminals enough information to take over customer accounts entirely.

Details on the underlying breach continue to surface. Investigators believe attackers compromised Italian Ministry of the Interior email accounts, using stolen credentials from infostealer malware logs, to impersonate law enforcement and submit fraudulent data requests to Revolut's Lithuanian entity over roughly six months.

Summarised by CISO AI from Infosecurity Magazine. We link back to every original so you can read it yourself.