Revolut Users Hit With SMS Phish After Breach

Malwarebytes · Medium sophistication
Last updated September 18, 2026

Days after Revolut disclosed that customer records were shared with an unauthorized party, some customers reported receiving phishing texts that appeared in the same SMS thread as real Revolut messages. The link led to a fake site that asked for camera access to mimic Revolut’s identity “liveness” check and then prompted for a password, an attempt to capture login details and potentially take over accounts.

How the Attack Worked

Shortly after Revolut acknowledged a data breach involving fraudulent information requests, some customers began receiving phishing text messages. At least one of these texts appeared inside the same SMS thread as legitimate Revolut messages, which made the fake message look like it came directly from the bank. The text directed recipients to tap a link that led to a fake verification page.

Once on the page, victims were asked to grant camera access. The site reportedly imitated Revolut's live-video identity check, prompting users to "turn your head" as part of a fake liveness check, before asking them to enter a password. This combination of a familiar-looking SMS thread and a realistic-seeming identity verification flow was designed to lower suspicion at each step.

Why It Succeeded

The attack leaned on trust signals that are easy to overlook. A text landing in an existing conversation thread with real Revolut messages can appear more credible than a message from an unknown number, even though thread placement can be spoofed and should not be treated as proof of legitimacy. The fake liveness check also mimicked a legitimate security step that Revolut customers may already be familiar with, making the camera access request feel like a normal part of account verification rather than a red flag.

If the campaign is connected to the breach, attackers may have had access to personal information that made messages feel more targeted and believable, increasing the odds that a customer would comply with the request.

What to Watch For

  • Unexpected account security or verification texts, even ones that appear in a thread with real messages
  • Links that lead to sites requesting camera access for identity verification
  • Web pages that imitate a "turn your head" or similar liveness check before asking for a password
  • Domains that do not match the official Revolut app or website

Building Resistance

Customers and staff supporting them should treat unsolicited account texts as untrusted regardless of where they appear, and verify any account concern by opening the official Revolut app directly rather than tapping a link. Before entering a password or approving any verification step, check the actual domain in the browser's address bar to confirm it matches what is expected. Because leaked personal data can make scams more convincing, organizations in finance and fintech should reinforce these habits with customer support, fraud and risk teams, and communications staff, and encourage extra account monitoring when a breach has been disclosed. This maps to techniques such as T1566.002 (spearphishing link) and T1204.001 (user execution via malicious link).

Key findings

  • Phishing texts targeting Revolut customers appeared shortly after Revolut acknowledged a data breach involving fraudulent information requests.
  • At least one phishing SMS appeared in the same conversation thread as legitimate Revolut texts, increasing credibility.
  • The phishing link reportedly led to a page requesting camera access and imitating Revolut’s live-video identity check (“turn your head”), then prompting for a password.
  • The phishing domain (93810.app) was first scanned on VirusTotal the same day a customer reported receiving the text.
  • If connected to the breach, exposed personal data combined with captured credentials (or approval of login prompts) could enable account takeover.

Who’s being targeted

  • Commonly targeted roles: All staff (general awareness), Customer Support, Fraud/Risk Operations, Security Operations, Communications/PR.
  • Affected industries: Banking / Fintech, Consumer financial services.
  • Attack channels: smishing, website.
  • Impersonated: Revolut (bank/fintech support).

Red flags to watch for

  • Text appears in an existing SMS thread, which can be spoofed and shouldn’t be trusted as proof of legitimacy
  • Website requests camera access unexpectedly
  • Link domain does not match an official Revolut domain/app flow
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

How did the Revolut phishing texts appear legitimate?

At least one phishing SMS appeared in the same conversation thread as legitimate Revolut texts, which made it look like it came directly from the bank.

What did the fake Revolut website ask victims to do?

The phishing link led to a page that requested camera access to imitate Revolut's live-video identity check, then prompted victims to enter a password.

Is this smishing campaign connected to a Revolut data breach?

The phishing texts appeared shortly after Revolut acknowledged a data breach involving fraudulent information requests, and if connected, exposed data combined with captured credentials could enable account takeover.

How can I tell if a Revolut text is fake?

Check the actual domain in your browser's address bar, avoid tapping links in unsolicited messages, and open the official Revolut app directly if you need to verify account activity.

Read the video transcript

You get a text from Revolut in the same thread as all your real bank alerts… but this one says, “Your account requires verification. Tap to complete the live check.” This is the Revolut smishing wave after their breach. Tap the link and you land on 93810.app, a fake site that asks for camera access, makes you do a “turn your head” selfie check, then asks for your password. Here’s the trap: because the text sits in your existing Revolut thread and mentions a real-seeming live check, it feels legit. But Revolut won’t push you to some random .app domain and then ask for camera plus password in the browser. If you get a Revolut “verification” text, don’t tap the link. Open the official Revolut app yourself and check there, that’s your move every single time.

Similar attacks

Fraudulent Gov Email and Passkey Lures Hit Orgs

Fraudulent Gov Email and Passkey Lures Hit Orgs

The bulletin describes real-world social engineering where staff were tricked into disclosing sensitive data or access. In one case, Revolut employees responded to fraudulent information requests sent from a real government-domain email account, exposing extensive customer records. Separately,…

September 14, 2026
Apollo Breach Tied to IT Support Impersonation

Apollo Breach Tied to IT Support Impersonation

Apollo Global Management disclosed a data breach after attackers used social engineering to gain unauthorized access to certain cloud platforms over several days in July. The attackers obtained sensitive personal data (including Social Security numbers), highlighting how stolen credentials and…

August 25, 2026
Fake T-Mobile Points Expiry Texts Hit Phones

Fake T-Mobile Points Expiry Texts Hit Phones

A large phishing (smishing) campaign is sending messages that claim a T-Mobile customer’s rewards points are about to expire. The texts use urgency, made-up point balances, and lookalike “t-mobile.*.top” links to push people into clicking and entering sensitive information. Malwarebytes observed…

September 17, 2026
FBI Warns of Social Media Reset-Code Scams

FBI Warns of Social Media Reset-Code Scams

The FBI says criminals are using social engineering to take over social media accounts, steal explicit content, and sell or post it online along with victims’ personal information. Reported tactics include pretending to be a social media company representative, spamming victims with password-reset…

August 12, 2026
Fake Fortnite Rewards Lure Epic Login Theft

Fake Fortnite Rewards Lure Epic Login Theft

Scammers are setting up fake Fortnite “rewards,” “locker value,” and “competition” websites that funnel players to a fake Epic Games login page. The sites trick people into signing in so attackers can steal Epic usernames and passwords, then take over accounts for resale, fraud, or further scams. A…

July 31, 2026
Phishers Hijack Meta/Google Ad Accounts for Profit

Phishers Hijack Meta/Google Ad Accounts for Profit

Criminal groups are stealing Meta Business Manager and Google Ads accounts using phishing that arrives through trusted platforms like Salesforce, Google Workspace mail-merge, and SharePoint links. The stolen accounts are valuable not just for the budget inside them, but because older accounts with…

July 29, 2026