Find notable cyber news and cases, enriched with sources, timelines, and signals.

Revolut customer smishing and phishing campaign

Campaign
First reported
Last updated
Happening score
H score 30
1 unique sources, 1 articles

Summary

Hide ▲

A smishing campaign is using the Revolut breach to push Revolut customers toward fake identity checks and password theft, raising the risk of account takeover. Messages seen on September 14 mimicked legitimate bank communication, including text that appeared in an existing conversation thread. The phishing flow led victims to a camera-permission prompt, a fake live-video identity check, and a password screen.

Related Happenings

Revolut's Lithuanian-regulated entity hit by account takeover attack

Incident
H score10 First: 21.09.2026 12:00 Last: 21.09.2026 12:00 Sources 1

How related: Several hundred accounts are thought to have been impacted, with high-net worth crypto users singled out for targeting after the threat actors analyzed blockchain records, according to various reports.

About this happening: Revolut's Lithuanian-regulated entity suffered a data breach tied to fraudulent KYC requests, putting several hundred accounts at risk of account takeover and iden...

Timeline

  1. 21.09.2026 12:00 2 articles · 2h ago

    Revolut customers receive smishing texts that mimic bank messages

    Victim Impact Update

    Revolut customers received smishing texts that appeared in the same conversation thread as legitimate Revolut messages, including a text seen on September 14, and the lure urged recipients to follow a link or risk account restrictions; the linked page could request camera access, present a fake live-video identity check, and then prompt for a password.

    Show sources
  2. 21.09.2026 12:00 1 articles · 2h ago

    Malwarebytes links the smishing wave to a Revolut data breach

    Campaign Scope Update

    Malwarebytes said attackers leveraged a Revolut data breach to harvest more account information from Revolut customers, and linked the phishing flow to fraudulent KYC requests sent by impersonating Italian law enforcement through compromised Italian Ministry of the Interior email accounts using infostealer logs.

    Show sources