Revolut Smishing Uses Fake Identity Check

Infosecurity Magazine · High sophistication
Last updated September 21, 2026

Following a Revolut data breach, scammers sent text messages that appeared to come from the same message thread as legitimate Revolut texts. The texts pushed victims to click a link for a fake identity “liveness check,” request camera access, and then capture passwords, information that could be used to take over accounts.

How the attack worked

Shortly after a Revolut data breach was acknowledged, customers began receiving smishing texts warning that their accounts would be restricted unless they confirmed their identity through a link. At least one of these messages appeared in the same SMS conversation thread as legitimate Revolut communications, which made the fake message look far more credible than a typical cold text.

Clicking the link led to a page mimicking a live-video identity check. The site requested access to the victim's device camera before prompting them to enter their password. This combination, a fake liveness check followed by a password request, let attackers harvest credentials while also potentially capturing selfie or video footage of the victim.

Why it succeeded

Several factors made this lure effective:

  • The message thread spoofing gave the scam text an appearance of legitimacy that standalone smishing rarely achieves.
  • The pretext, an urgent account restriction, created time pressure that discourages careful verification.
  • Requesting camera access as part of an "identity verification" flow is unusual, but framed as routine KYC/security process, it can seem plausible to users accustomed to identity checks at financial institutions.
  • The password request came only after the camera step, so victims who had already engaged with the flow were primed to comply with the final ask.

What to watch for

Defenders and customers should be alert to:

  • Unsolicited texts pushing an urgent link and threatening account restriction if action isn't taken immediately.
  • Links that lead to pages requesting camera access, which is not a normal part of routine SMS-based account communication.
  • Any flow that asks for a password after a supposed "verification" step, since this is a strong indicator of credential harvesting.
  • In compliance and legal contexts, unusual formatting or urgency in government data requests, even when they appear to come from an official account, as separate reporting noted fraudulent KYC requests sent via compromised Italian Ministry of the Interior email accounts.

Building resistance

Organizations and individuals can reduce risk by reinforcing a few habits. Customers should avoid following links in unsolicited messages about account issues and instead open the official app or site directly to check for alerts. Any request for camera access tied to an unexpected "identity check" link warrants suspicion rather than compliance. Selfie or video data collected through such a flow should be treated as sensitive, since it may be reused to make future scams more convincing. Compliance and KYC/AML teams handling data requests, particularly cross-border ones, should verify the request through an independent trusted channel rather than relying solely on the appearance of the sender's email address.

Key findings

  • Revolut customers received smishing texts shortly after the breach was acknowledged.
  • At least one scam text appeared in the same SMS conversation thread as legitimate Revolut messages, increasing trust.
  • The lure threatened account restriction unless the recipient confirmed their identity via a link.
  • The phishing site requested camera access, mimicked a live-video identity check, then prompted for a password.
  • Malwarebytes warned captured selfies/videos could be reused for follow-on fraud and more convincing scams.
  • Separately, threat actors allegedly impersonated Italian law enforcement by using compromised government email accounts to submit fraudulent KYC data requests to Revolut.

Who’s being targeted

  • Commonly targeted roles: Retail/consumer banking customers, Fraud & risk teams, Customer support, Compliance (KYC/AML), Legal and data privacy teams.
  • Affected industries: Digital banking / fintech, Consumer financial services, Cryptocurrency / high-net-worth crypto users.
  • Attack channels: smishing, website, email.
  • Impersonated: Revolut (bank security/KYC), Italian law enforcement (via Italian Ministry of the Interior email accounts).

Red flags to watch for

  • Unsolicited text pushing an urgent link and threatening account restrictions
  • Link leads to a site requesting camera access (unusual for SMS link)
  • Password requested after a “verification” flow (credential capture)
  • Unusual or unexpected urgency/format in a government request
  • Requesting sensitive KYC data without normal verification steps
  • Sender appears legitimate but could be from a compromised government account
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

How did the Revolut smishing attack work?

Scammers sent texts, some appearing in the same thread as legitimate Revolut messages, warning that the recipient's account would be restricted unless they confirmed their identity via a link. The link led to a fake identity verification page that requested camera access and then a password.

Why did the fake message thread trick people?

At least one scam text appeared in the same SMS conversation thread as legitimate Revolut messages, which increased trust and made the fake message look more credible.

What should be done with any captured selfies or video?

Malwarebytes warned that captured selfies or video could be reused for follow-on fraud and to make future scams more convincing, so this data should be treated as sensitive.

Was there another type of attack tied to this incident?

Yes, threat actors separately impersonated Italian law enforcement using compromised government email accounts to submit fraudulent KYC data requests to Revolut.

Read the video transcript

You get a Revolut text, same thread as your real alerts, saying: confirm your identity now or your account gets restricted. You tap the link, a fake Revolut page pops up, asks for camera access for a ‘live’ identity check, then quietly asks for your password, now they’ve got your face and your login. Security researchers found scammers reusing those selfies and videos for more fraud, while others even used compromised Italian Ministry email accounts to send fake KYC requests to Revolut. If you get an identity or account-warning text, don’t touch the link, open the Revolut app or website yourself and check for any alerts there.

Similar attacks

Revolut Users Hit With SMS Phish After Breach

Revolut Users Hit With SMS Phish After Breach

Days after Revolut disclosed that customer records were shared with an unauthorized party, some customers reported receiving phishing texts that appeared in the same SMS thread as real Revolut messages. The link led to a fake site that asked for camera access to mimic Revolut’s identity “liveness”…

September 17, 2026
Revolut Fooled by Govt Impersonation Email

Revolut Fooled by Govt Impersonation Email

A person posing as a government agency used an email address on that agency’s real domain to obtain sensitive customer records from Revolut. The same weekly roundup also describes a fake antivirus renewal web page impersonating Avast, telling victims their subscription renewed for €129.99 and…

September 20, 2026
Fraudulent Gov Email and Passkey Lures Hit Orgs

Fraudulent Gov Email and Passkey Lures Hit Orgs

The bulletin describes real-world social engineering where staff were tricked into disclosing sensitive data or access. In one case, Revolut employees responded to fraudulent information requests sent from a real government-domain email account, exposing extensive customer records. Separately,…

September 14, 2026
Fake T-Mobile Points Expiry Texts Hit Phones

Fake T-Mobile Points Expiry Texts Hit Phones

A large phishing (smishing) campaign is sending messages that claim a T-Mobile customer’s rewards points are about to expire. The texts use urgency, made-up point balances, and lookalike “t-mobile.*.top” links to push people into clicking and entering sensitive information. Malwarebytes observed…

September 17, 2026
Fake Fortnite Rewards Lure Epic Login Theft

Fake Fortnite Rewards Lure Epic Login Theft

Scammers are setting up fake Fortnite “rewards,” “locker value,” and “competition” websites that funnel players to a fake Epic Games login page. The sites trick people into signing in so attackers can steal Epic usernames and passwords, then take over accounts for resale, fraud, or further scams. A…

July 31, 2026
RatHat Lures Users to Install Fake Android Apps

RatHat Lures Users to Install Fake Android Apps

Researchers describe RatHat, an Android trojan linked to China-based operators, that spreads via smishing, malvertising, and fake app stores to trick people into installing a malicious APK. Once installed, it pushes for Accessibility permissions and then uses that access to take deep control of the…

September 18, 2026