The text landed in the same message thread as every other Revolut alert the customer had ever received, which is exactly why it worked. It arrived on Monday, September 14, two days after the bank publicly admitted it had handed sensitive customer records to somebody impersonating a government agency. Malwarebytes, which documented the campaign, is careful to say the two events have not been shown to be connected. That is the open question customers are now living with.
The breach itself did not involve anyone breaking into Revolut's systems. As we reported when the disclosure surfaced, the bank accepted fraudulent information requests sent from an email address on a legitimate government agency domain. What went out the door was the kind of material that makes impersonation easy: dates of birth, postal addresses, email addresses and phone numbers, copies of passports and driving licences, verification selfies, and account statements with transaction histories. Revolut has described the number of affected customers only as limited or very limited, and says it contacted them directly.
A fake identity check that wants your face
The phishing message carried a link to a domain that, according to VirusTotal, had been scanned for the first time that same day. Another customer described what happened after tapping it: the page asked for access to the device camera, and if permission was granted it mimicked Revolut's live video identity check, the one that asks you to turn your head, before prompting for a password.
That sequence is doing two jobs. The liveness check is theatre, and it lowers suspicion by looking like something only the real bank would ask for. It also potentially hands the operators a selfie or a short video of the victim, which is precisely the artifact needed to pass an identity verification step somewhere else, or to make the next approach more convincing. If the campaign is drawing on breach data, a password entered here plus a customer's own approval of a login prompt could be enough for an account takeover.
Treat the aftermath as part of the breach
Whether or not this particular campaign is fed by Revolut's data, the pattern is now routine: a disclosure creates a window in which customers expect to hear from their provider, and criminals fill it. The same thing happened to Trezor customers after a breach at its email provider, and the timing there was just as tight.
The practical advice has not changed. Do not follow links in unsolicited messages, even when they appear inside a legitimate message thread, because sender identifiers on SMS are trivially forged. If a message concerns your account, close it and open the Revolut app directly. If you are already on a web page, read the actual domain in the address bar rather than the branding on the page. And treat any request to film your face as a red flag, because a genuine bank will ask for that inside its own app, not through a link in a text. Malwarebytes has published its write up of the campaign with screenshots of the message.
This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.