Fake Bank Calls Drain £180k From Revolut Users

Graham Cluley · Medium sophistication
Last updated September 3, 2026

Jersey Police report a surge of scam phone calls where criminals impersonate bank fraud/security teams or Revolut support. Victims are pressured with warnings about “suspicious transactions” and then tricked into handing over security details or moving money, leading to about £180,000 in losses in four weeks.

How the attack worked

Jersey Police reported a cluster of scam calls in which criminals impersonated a bank's fraud or security department, or Revolut's customer support team. The caller would claim that a suspicious transaction had been spotted on the account or that it was at risk of being compromised. That claim created urgency, which the caller then used to push the victim toward one of several outcomes: sharing security details, approving a transaction, transferring funds, or simply granting the caller access to the account. According to the report, 75% of all scam crime reports in the period involved Revolut accounts, and total losses reached about £180,000 in roughly four weeks. Police also noted some compromised accounts where no phone call was involved at all, suggesting the pattern of account takeover isn't limited to a single delivery method.

Why it succeeded

The pretext works because it borrows legitimacy from a trusted source: a bank or a well-known digital banking provider. Combining that impersonation with a manufactured sense of risk, an unexpected call about a "suspicious transaction," creates pressure that short-circuits careful thinking. A well-rehearsed script paired with manufactured panic can push an otherwise careful person into a costly mistake, especially when the caller asks them to act immediately to "protect" their money.

What to watch for

  • Unsolicited calls claiming urgent risk to an account, even if the caller sounds professional or has some account details
  • Any request to share passwords or security information over the phone
  • Instructions to move money to a "safe account" to keep it secure
  • Requests to approve a transaction or grant remote access during the call

How to build resistance

The clearest defense is treating unexpected bank or support calls as untrusted by default. If someone claims to be calling from a bank's fraud team or from Revolut, the safer path is to hang up and reach out independently through a verified channel, such as the official in-app chat, rather than continuing the conversation or using a number the caller supplies. Staff and consumers should also internalize two simple rules drawn from this pattern: banks will never ask a customer to share passwords or security information, and no genuine bank will ever ask a customer to move money to a "safe account" to protect it. Reinforcing these rules across finance teams, customer support staff, and the general public reduces the chance that urgency and impersonation alone are enough to trigger a transfer or a disclosure of sensitive details.

Key findings

  • Jersey Police say that in a four-week period, "75% of all scam crime reports" involved Revolut accounts.
  • Victims lost about "£180,000" in roughly four weeks.
  • The most common pattern is an unexpected phone call from someone claiming to be from a bank’s fraud/security department or "Revolut's customer support team."
  • The caller claims a "suspicious transaction" or risk of compromise to pressure victims into sharing security details, approving transactions, transferring funds, or giving account access.
  • Police also saw some compromised Revolut accounts "that did not involve any phone calls."

Who’s being targeted

  • Commonly targeted roles: Finance, Executives, Customer support (fraud awareness), All staff (general anti-scam training).
  • Affected industries: Finance (digital banking), Retail banking, Wealth management (context: offshore financial centre).
  • Attack channels: vishing.
  • Impersonated: Bank fraud/security department or Revolut customer support.

Red flags to watch for

  • Unsolicited call claiming urgent account risk
  • Request to share "passwords or security information"
  • Request to move money to a "safe account"
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

How did the Revolut scam calls work?

Victims received unexpected calls from people claiming to be from a bank's fraud or security department, or Revolut's customer support team, who claimed a suspicious transaction had occurred and pressured victims into sharing security details or moving money.

How much money was lost in this scam?

Jersey Police reported that victims lost about £180,000 over roughly a four-week period.

What should someone do if they get a suspicious call claiming to be from their bank?

Hang up and contact the bank directly through a known-good channel, such as Revolut's secure in-app chat, rather than continuing the call or calling back a number the caller provides.

Would a real bank ask a customer to transfer money to a 'safe account'?

No. Genuine banks will never ask a customer to move money to a 'safe account' to protect it, and any caller making that request is a scammer.

Read the video transcript

In Jersey, 75% of recent scam reports hit Revolut users, about £180,000 gone in just four weeks, mostly from one fake phone call. You get an unexpected call: “This is your bank’s fraud team, we’ve spotted a suspicious transaction on your Revolut. To protect you, we need you to read out your one-time code and move money to a safe account.” That’s the whole scam. Here’s the aha: real banks and Revolut will never ask for your passwords, security details, or one-time codes, and they will never tell you to move money to a safe account. Any caller who does that is the scam. So if anyone calls about your bank or Revolut, hang up, then you start the conversation: open the official app yourself and use the in-app chat or a number from their website.

Similar attacks

Fake IT Help Desk Calls Hit Private Equity

Fake IT Help Desk Calls Hit Private Equity

Researchers say a threat group tracked as UNC6671 is calling employees and posing as IT help desk staff to steal login credentials and multi-factor authentication (MFA) tokens. After gaining access, the attackers reportedly exfiltrate large amounts of corporate data and then issue extortion…

August 11, 2026
UNC6671 Rebrands, Runs IT Helpdesk Vishing

UNC6671 Rebrands, Runs IT Helpdesk Vishing

Google Threat Intelligence reports that extortion group UNC6671 (formerly branded “BlackFile”) is calling employees while posing as IT helpdesk staff and pushing “urgent security migrations.” Victims are lured to spoofed login pages to capture passwords and MFA tokens, enabling Microsoft 365/Okta…

August 7, 2026
FaceTime Spoof Calls Steal Codes and Money

FaceTime Spoof Calls Steal Codes and Money

Apple warns that scammers are using FaceTime calls, often with spoofed caller ID, to impersonate Apple or banks and pressure people into sharing passwords, security codes, and financial details. The callers use personal information to sound legitimate, then create urgency to keep victims from…

July 17, 2026
BlackFile Vishing Poses as IT Support to Extort Firms

BlackFile Vishing Poses as IT Support to Extort Firms

Researchers say the BlackFile extortion group is actively targeting large financial and other organizations using voice-phishing calls where attackers impersonate IT support to get initial access. Victims are then pressured with multimillion-dollar extortion demands and, in some cases, escalations…

August 17, 2026
WindRelay Scam: Tap Your Card, Lose Your Money

WindRelay Scam: Tap Your Card, Lose Your Money

Researchers say criminals are using a two-part Android malware setup (SpyNote + WindRelay) to trick victims into turning their own phones into NFC “relays” for contactless payment fraud. Victims are lured via phishing/smishing/vishing to install a malicious app, then persuaded on a live call to tap…

August 17, 2026
Fake Bank Calls Trick Victims Into NFC Card Fraud

Fake Bank Calls Trick Victims Into NFC Card Fraud

Researchers described a real scam where criminals called victims pretending to be bank support and convinced them to install a “legitimate” Android app. The app was actually SpyNote malware, giving the attacker remote control of the phone, after which a second tool (WindRelay) was used to relay…

August 14, 2026