Revolut disclosed sensitive customer information after fraudsters successfully impersonated a government agency, exposing records that included identity documents, contact details, account statements, and transaction histories.
The financial technology company says attackers did not break into its systems. Instead, Revolut responded to fraudulent information requests sent from an email address on a legitimate government-agency domain, believing the requests were authentic.
Only a limited number of customers were affected, according to Revolut, which said it contacted those customers directly. The company has not publicly disclosed an exact number.
Days after the disclosure became public, Malwarebytes reported that some Revolut customers had received phishing texts impersonating the company, though there is currently no evidence confirming that the phishing campaign is connected to the customer data disclosure.
Fraudulent requests exposed sensitive customer records
The information obtained through the fraudulent requests included identity and contact details such as dates of birth, postal addresses, email addresses, and phone numbers, according to Malwarebytes.
The disclosed records also included copies of identity documents such as passports and driver’s licenses, verification selfies, account statements, and transaction histories.
The incident differs from a conventional breach in which attackers exploit a vulnerability or compromise company credentials to gain access to internal systems. In this case, the attackers relied on social engineering: they presented fraudulent requests that appeared legitimate and persuaded Revolut to release the information.
Revolut has said its systems themselves were not compromised.
Although the company has characterized the number of affected customers as limited, the types of information involved could be useful for identity fraud and highly targeted scams. Details such as transaction histories and identity documents can give criminals information that makes an impersonation attempt appear more credible to its intended target.
Malwarebytes reported that one affected Revolut customer received a phishing text on September 14, two days after Revolut publicly acknowledged the disclosure.
The message appeared in the same SMS conversation as legitimate Revolut texts, making it appear as though it had been sent by the company. Revolut has previously warned customers that scammers can make fraudulent messages appear alongside genuine communications.
According to Malwarebytes, the phishing domain used in the message was first scanned by VirusTotal on the same day.
A separate customer reported encountering a more elaborate phishing flow after opening a link in another message. The website requested access to the device’s camera and reportedly imitated Revolut’s live-video identity check, including an instruction to turn the user’s head, before presenting a password prompt.
A liveness check is designed to confirm that a real person is physically present during identity verification rather than someone submitting only a photograph or other static image. By imitating that familiar process, a phishing site can make a fraudulent login flow appear more authentic.
If a user grants camera access, the site may also be able to capture a selfie or video. Malwarebytes said such material could potentially be used for additional social engineering, identity fraud, or later scams.
There is no evidence so far establishing that the phishing texts are being sent using information obtained through the Revolut disclosure.
The campaign could be connected to the incident, but it could also involve unrelated scammers using publicity around the disclosure as an opportunity to target Revolut customers.
The distinction matters because criminals frequently use current events involving well-known companies as a pretext for phishing. An attacker does not necessarily need access to newly exposed customer data to send a convincing message claiming that an account requires attention.
If information from the Revolut disclosure is being used, however, the combination of personal records and additional credentials collected through a phishing page could create a more serious account-security risk. Malwarebytes noted that login details entered by a victim, or approval of a subsequent login request, could potentially be combined with exposed information in an attempt to take over an account.
Customers should avoid links in unexpected texts
Revolut’s current security guidance says it does not send text messages asking customers to provide security information or follow a website link to submit sensitive details. When the company requires information from a customer, it directs them to provide it through the Revolut app.
That means a message appearing alongside legitimate Revolut texts should not by itself be considered proof that the message is authentic.
Customers who receive an unexpected message about their account should open the official Revolut app directly instead of following the supplied link. They should also check the domain shown in a browser’s address bar before entering credentials or other sensitive information.
A request for camera access is similarly not evidence that a website is legitimate. Websites can request permission to access cameras and microphones through standard browser features, allowing phishing pages to imitate interactions normally associated with genuine identity checks.
For customers who believe they have already interacted with a fraudulent site, Revolut recommends stopping communication with the suspected scammer and changing the account passcode if unauthorized access is suspected. Customers can also freeze a potentially compromised card through the app and report fraud through Revolut’s support channels.
The reports don’t establish that the exposed customer records are being actively used in scams, but customers affected by the disclosure should remain cautious about unexpected requests involving account credentials or identity verification, particularly when those requests arrive through links in text messages.

Leave a Reply