Find notable cyber news and cases, enriched with sources, timelines, and signals.

Revolut's Lithuanian-regulated entity hit by account takeover attack

Incident
First reported
Last updated
Happening score
H score 10
1 unique sources, 1 articles

Summary

Hide ▲

Revolut's Lithuanian-regulated entity suffered a data breach tied to fraudulent KYC requests, putting several hundred accounts at risk of account takeover and identity fraud. The compromise was leveraged through compromised Italian Ministry of the Interior email accounts used to impersonate Italian law enforcement. Follow-on smishing texts and fake liveness checks extended the exposure and helped attackers harvest account credentials.

Related Happenings

Revolut customer smishing and phishing campaign

Campaign
H score30 First: 21.09.2026 12:00 Last: 21.09.2026 12:00 Sources 1

How related: Hackers have seized on a data breach at digital financial firm Revolut to try and harvest more account information from customers, according to Malwarebytes.

About this happening: A smishing campaign is using the Revolut breach to push Revolut customers toward fake identity checks and password theft, raising the risk of account takeover. Mes...

Revolut hit by cyberattack

Incident
H score16 First: 14.09.2026 11:48 Last: 14.09.2026 11:48 Sources 1

About this happening: Revolut disclosed a data breach after a threat actor impersonated a government agency and obtained customer information through email. The exposed data included identi...

Timeline

  1. 21.09.2026 12:00 2 articles · 2h ago

    Revolut customers receive smishing texts after the data breach

    Initial Disclosure

    Malwarebytes identified smishing texts sent to Revolut customers after a data breach, including one received on September 14 that appeared in the same conversation thread as other Revolut messages and urged the recipient to confirm identity or risk account restrictions. A linked web page reportedly requested camera access, mimicked a live-video identity check, and then asked for a password, while the campaign may have been connected to fraudulent KYC requests sent through compromised Italian Ministry of the Interior email accounts.

    Show sources