Press play to start listening
Revolut customers are receiving phishing texts just days after the fintech acknowledged exposing sensitive customer information, although researchers have not established whether the phishing campaign is connected to the breach.
The phishing activity follows a breach in which Revolut staff provided customer records in response to fraudulent information requests sent from an email address on a legitimate government agency domain. Revolut said the incident did not involve unauthorized access to its systems.
The exposed information included identity documents, verification selfies, dates of birth, contact details, account statements and transaction histories. Hackread.com previously reported that the records also contained IBANs, wallet reference numbers and details of Bitcoin transactions, but biometric facial telemetry was not compromised.
Revolut has said only a “limited” number of customers were affected and confirmed that customer funds were not affected. After detecting the activity, Revolut blocked the sending address and notified the relevant government agency, law enforcement, data protection authorities and financial regulators.
Malwarebytes researcher Pieter Arntz said in research shared with Hackread.com that an affected customer received a phishing text on September 14, two days after Revolut publicly acknowledged the breach.
The message appeared in the same conversation thread as genuine Revolut messages, making it look like it had come from the company. VirusTotal records showed the phishing domain was scanned that same day.
In another case, a customer reported that a link opened a page requesting camera access. After permission was granted, the page imitated Revolut’s live-video identity check, including the instruction to turn the user’s head, before asking for a password.
Arntz said a convincing fake liveness check followed by a password request can make a phishing page appear more legitimate and obtain information that could be used in a real login or account-recovery attempt. A captured selfie or video could also be used in further social engineering or identity fraud.
Malwarebytes stressed that it is still unclear whether the phishing campaign is connected to the breach or whether separate scammers are using publicity around the incident to target Revolut customers. It advises customers to avoid links in unexpected messages and open the official Revolut app directly when checking their accounts.
(Photo by Kaysha on Unsplash)
