Revolut
Incident posture
Timeline
Summary
Revolut customers were targeted by smishing messages that appeared to come from the bank and urged recipients to follow links to confirm their identity or risk restricted account access. Some links led to pages mimicking a live-video identity check, requesting camera access before prompting users for passwords. The broader breach involved fraudulent requests for KYC information sent to the bank’s Lithuanian-regulated entity under European Investigation Orders. Threat actors impersonated Italian law enforcement after compromising Italian Ministry of the Interior email accounts with infostealer logs, reportedly maintaining access for around six months. Several hundred accounts were thought to be impacted, with high-net-worth crypto users singled out after blockchain records were analyzed.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
Revolut acknowledged a data breach involving its Lithuanian-regulated entity, which was legally required to respond to European Investigation Orders. Details described in reports indicated that the attack relied on fraudulent requests for KYC information submitted through apparently official law-enforcement channels. The threat actors impersonated Italian law enforcement after compromising Italian Ministry of the Interior email accounts using infostealer logs. Reports stated that the attackers had access to those accounts for around six months, allowing them to submit multiple fraudulent data requests without immediately raising suspicion. The breach affected several hundred accounts, according to reports. High-net-worth crypto users were singled out after the attackers analyzed blockchain records. The information exposed through the fraudulent requests became the basis for follow-on phishing activity targeting Revolut customers.
Malwarebytes said it uncovered several examples of Revolut customers receiving smishing messages by text after the breach became known. One message arrived on September 14, two days after Revolut acknowledged the incident. In one example, the scam message appeared in the same conversation on the victim’s device as other Revolut texts, making it resemble a legitimate message. The message instructed the recipient to follow a link to confirm their identity and warned that account access would be restricted otherwise. In a separate case, opening the link led to a webpage that requested access to the device camera. After the user clicked “allow,” the page reportedly displayed what appeared to be Revolut’s live-video identity check. The page then prompted the user to enter their password. Malwarebytes described the sequence as a phishing process designed to collect account-login information and identity-related data from Revolut customers. Malwarebytes also warned that the phishing campaign could be connected to the breach or could be an opportunistic effort to steal account information. The incident therefore involved both unauthorized access to customer KYC data through fraudulent official requests and subsequent customer-targeted phishing messages using Revolut-themed lures.
Sources
Sources available to members: 1 source.