MalwareBytes

Revolut phishing texts appear days after data breach


Only days after Revolut acknowledged that it disclosed sensitive customer records to an unauthorized party, affected customers are receiving phishing texts. However, we don’t know yet if the phishing texts are linked to the breach.

The company had accepted fraudulent information requests sent from an email address on a legitimate government agency domain.

Through this social engineering attack, rather than by gaining access to Revolut’s systems, the criminals obtained the following types of information about customers:

  • Identity and contact information such as dates of birth, postal addresses, email addresses, and phone numbers
  • Copies of IDs such as passports and driver’s licenses
  • Verification selfies
  • Account statements and transaction histories

Revolut has said only that a “limited” or “very limited” number of customers were affected, and that it contacted them directly.

One affected customer received a phishing text on Monday, September 14, two days after Revolut publicly acknowledged the data breach. The message appeared in the same conversation as other Revolut texts, making it look as though it had come from the bank.

Phishing text to a Revolut customer

According to VirusTotal, the phishing domain was first scanned that same day.

In a separate example, another customer said that opening the link took them to a web page that requested access to their device’s camera. If you tap Allow, the page reportedly imitates Revolut’s live-video “turn your head” identity check before prompting you to enter a password.

This makes the phishing page appear more authentic. It may also allow the scammers to collect a selfie or video that could be used for further social engineering, identity fraud, or to make subsequent scams more convincing.

A convincing fake liveness check followed by a password screen is a common way to lower suspicion and obtain the information attackers need to attempt a real login or account-recovery flow.

If the campaign is connected to the breach, the information obtained from Revolut, combined with login details entered by victims or their approval of a login request, could be enough to take over their accounts.

How to stay safe

We don’t yet know whether the phishing campaign is using data exposed in the breach or whether unrelated scammers are exploiting news of the incident to target Revolut customers more broadly.

Either way, treat unexpected messages about your account with caution:

  • Don’t follow links in unsolicited messages. If a message concerns your account, open the official Revolut app directly.
  • Check the actual domain in your browser’s address bar to see if it corresponds with what you expect.
  • Use an up-to-date, real-time anti-malware solution on your device, preferably with a web protection component.
  • Malwarebytes Scam Guard can help you determine whether a message is a scam and advise you on what to do next.

Stop threats before they can do any harm.

Malwarebytes Browser Guard blocks phishing pages and malicious sites automatically. Free, one click to install. Add it to your browser →



Source link