Following a Revolut data breach, scammers sent text messages that appeared to come from the same message thread as legitimate Revolut texts. The texts pushed victims to click a link for a fake identity “liveness check,” request camera access, and then capture passwords, information that could be used to take over accounts.
How the attack worked
Shortly after a Revolut data breach was acknowledged, customers began receiving smishing texts warning that their accounts would be restricted unless they confirmed their identity through a link. At least one of these messages appeared in the same SMS conversation thread as legitimate Revolut communications, which made the fake message look far more credible than a typical cold text.
Clicking the link led to a page mimicking a live-video identity check. The site requested access to the victim's device camera before prompting them to enter their password. This combination, a fake liveness check followed by a password request, let attackers harvest credentials while also potentially capturing selfie or video footage of the victim.
Why it succeeded
Several factors made this lure effective:
- The message thread spoofing gave the scam text an appearance of legitimacy that standalone smishing rarely achieves.
- The pretext, an urgent account restriction, created time pressure that discourages careful verification.
- Requesting camera access as part of an "identity verification" flow is unusual, but framed as routine KYC/security process, it can seem plausible to users accustomed to identity checks at financial institutions.
- The password request came only after the camera step, so victims who had already engaged with the flow were primed to comply with the final ask.
What to watch for
Defenders and customers should be alert to:
- Unsolicited texts pushing an urgent link and threatening account restriction if action isn't taken immediately.
- Links that lead to pages requesting camera access, which is not a normal part of routine SMS-based account communication.
- Any flow that asks for a password after a supposed "verification" step, since this is a strong indicator of credential harvesting.
- In compliance and legal contexts, unusual formatting or urgency in government data requests, even when they appear to come from an official account, as separate reporting noted fraudulent KYC requests sent via compromised Italian Ministry of the Interior email accounts.
Building resistance
Organizations and individuals can reduce risk by reinforcing a few habits. Customers should avoid following links in unsolicited messages about account issues and instead open the official app or site directly to check for alerts. Any request for camera access tied to an unexpected "identity check" link warrants suspicion rather than compliance. Selfie or video data collected through such a flow should be treated as sensitive, since it may be reused to make future scams more convincing. Compliance and KYC/AML teams handling data requests, particularly cross-border ones, should verify the request through an independent trusted channel rather than relying solely on the appearance of the sender's email address.
Key findings
- Revolut customers received smishing texts shortly after the breach was acknowledged.
- At least one scam text appeared in the same SMS conversation thread as legitimate Revolut messages, increasing trust.
- The lure threatened account restriction unless the recipient confirmed their identity via a link.
- The phishing site requested camera access, mimicked a live-video identity check, then prompted for a password.
- Malwarebytes warned captured selfies/videos could be reused for follow-on fraud and more convincing scams.
- Separately, threat actors allegedly impersonated Italian law enforcement by using compromised government email accounts to submit fraudulent KYC data requests to Revolut.
Who’s being targeted
- Commonly targeted roles: Retail/consumer banking customers, Fraud & risk teams, Customer support, Compliance (KYC/AML), Legal and data privacy teams.
- Affected industries: Digital banking / fintech, Consumer financial services, Cryptocurrency / high-net-worth crypto users.
- Attack channels: smishing, website, email.
- Impersonated: Revolut (bank security/KYC), Italian law enforcement (via Italian Ministry of the Interior email accounts).
Red flags to watch for
- Unsolicited text pushing an urgent link and threatening account restrictions
- Link leads to a site requesting camera access (unusual for SMS link)
- Password requested after a “verification” flow (credential capture)
- Unusual or unexpected urgency/format in a government request
- Requesting sensitive KYC data without normal verification steps
- Sender appears legitimate but could be from a compromised government account
Frequently asked questions
How did the Revolut smishing attack work?
Scammers sent texts, some appearing in the same thread as legitimate Revolut messages, warning that the recipient's account would be restricted unless they confirmed their identity via a link. The link led to a fake identity verification page that requested camera access and then a password.
Why did the fake message thread trick people?
At least one scam text appeared in the same SMS conversation thread as legitimate Revolut messages, which increased trust and made the fake message look more credible.
What should be done with any captured selfies or video?
Malwarebytes warned that captured selfies or video could be reused for follow-on fraud and to make future scams more convincing, so this data should be treated as sensitive.
Was there another type of attack tied to this incident?
Yes, threat actors separately impersonated Italian law enforcement using compromised government email accounts to submit fraudulent KYC data requests to Revolut.
Read the video transcript
You get a Revolut text, same thread as your real alerts, saying: confirm your identity now or your account gets restricted. You tap the link, a fake Revolut page pops up, asks for camera access for a ‘live’ identity check, then quietly asks for your password, now they’ve got your face and your login. Security researchers found scammers reusing those selfies and videos for more fraud, while others even used compromised Italian Ministry email accounts to send fake KYC requests to Revolut. If you get an identity or account-warning text, don’t touch the link, open the Revolut app or website yourself and check for any alerts there.