Revolut Phishing SMS Campaign Follows Social-Engineering Data Breach Exposing 680 Customers' KYC Data
Revolut Phishing SMS Campaign Follows Social-Engineering (TL-2026-2550), also tracked as Revolut KYC Data Breach 2026, is a high-severity phishing campaign, first published 2026-09-17. It has no confirmed attribution, affects Revolut Revolut customer lawful-disclosure / KYC data-request process, maps to 11 MITRE ATT&CK techniques (T1056.003, T1204.001, T1583.001), and is covered by 9 detection rules and 9 indicators of compromise.
Key facts for TL-2026-2550
- Threat ID
- TL-2026-2550
- Also known as
- Revolut KYC Data Breach 2026, iamnotavillain Extortion, Revolut Smilik
- Severity
- HIGH
- Status
- ACTIVE
- Category
- PHISHING
- First published
- 2026-09-17
- Last reviewed
- 2026-09-17
- Attribution confidence
- LOW
- Motivation
- FINANCIAL
- Target sectors
- financial services, fintech, banking, cryptocurrency
- Target regions
- united kingdom, Europe, Global
- Detection rules
- 9
- Indicators of compromise
- 9
Revolut disclosed on 2026-09-12 that a threat actor impersonating a government agency used an authenticated email account on that agency's real domain to trick Revolut into disclosing KYC data (passports, selfies, addresses, account statements, crypto transaction history) for roughly 680 customers. Two days later, a targeted SMS phishing campaign began, injecting fraudulent messages into victims' existing Revolut conversation threads and linking to fake identity-verification pages that request camera access to simulate Revolut's liveness check before harvesting passwords.
How Revolut Phishing SMS Campaign Follows Social-Engineering works
On 2026-09-12, Revolut publicly acknowledged what it called 'a sophisticated external impersonation scam': an unauthorized third party submitted fraudulent customer-data requests from an email account operating on a legitimate government agency's domain. Because the requests carried valid domain-authentication signals (the account passed SPF/DKIM/DMARC checks against the genuine agency domain), Revolut's standard lawful-disclosure process treated the requests as authentic and released customer files before any secondary verification occurred. Revolut has not disclosed which government agency's domain or mailbox was involved, but has stated the request was directed at the email address courtorders@revolut.com, its channel for handling law-enforcement and regulatory data demands.
Approximately 680 customers were affected, a small fraction of Revolut's 80M+ user base, and open-source reporting (including analysis by crypto investigator ZachXBT) suggests the targeting was selective rather than mass-scale, focused on high-net-worth individuals with significant crypto holdings. Exposed data included passports and driver's licenses, account-opening/verification selfies, dates of birth, postal and email addresses, phone numbers, account statements with IBANs, and complete fiat and cryptocurrency transaction histories; biometric facial-recognition telemetry was reportedly not included.
On 2026-09-13, a Telegram-based actor operating under the handle 'iamnotavillain' began publishing customer dossiers and threatening daily leaks unless a 10,000 BTC ransom was paid. Independent OSINT analysis (KELA) traced the extortion site to a static page hosted on GitHub Pages (repository btres9kijob[.]github.io) with DNS through GoDaddy, assembled in roughly 6.5 hours from a default Claude-generated HTML template; the public repository exposed commit history and recoverable deleted files. A payment subdomain routed through GoDaddy Payments, a platform that typically requires full KYC and a US bank account to use — a potentially significant operational-security misstep for the extortionist. A second, seemingly competing Telegram channel calling itself 'Revolut Smilik' also claimed responsibility; reporting suggests this second actor may be an opportunistic impersonator who obtained a data sample from the original actor rather than the original breach operator.
Starting 2026-09-14, a separate SMS phishing (smishing) campaign began targeting affected and prospective Revolut customers. Messages were delivered so that they appeared inside the recipient's existing, legitimate Revolut SMS conversation thread — a thread-injection effect enabled by inconsistencies in how legacy email-to-SMS gateways and mobile messaging clients map sender identity, allowing a spoofed message to inherit the trust context of a genuine prior conversation rather than arriving as a new, suspicious sender. The messages link to a fake identity-verification page hosted at 93810[.]app (first observed on VirusTotal 2026-09-14) that requests camera access and simulates Revolut's 'turn your head' liveness-check flow before prompting the victim to enter their account password, harvesting credentials (and potentially biometric video) under the guise of routine re-verification.
As of publication, it remains unconfirmed whether the SMS phishing campaign is being run by the same actor(s) responsible for the breach and extortion using the stolen data to precision-target victims, or by unrelated opportunistic scammers capitalizing on public news of the breach. Either way, the compressed timeline — public breach disclosure to targeted smishing in two days — creates a high-credibility account-takeover path for the affected customer population, who are simultaneously exposed to SIM-swapping and cryptocurrency-focused extortion risk given the leaked transaction and wallet data.
MITRE ATT&CK techniques used in TL-2026-2550
Credential Access
Execution
Resource Development
T1583.001 Domains; T1583.006 Web Services; T1586.002 Email Accounts; T1608 Stage Capabilities
Reconnaissance
T1589 Gather Victim Identity Information; T1598 Phishing for Information
Impact
Initial Access
Defense Evasion
Affected products and versions in Revolut Phishing SMS Campaign Follows Social-Engineering
- Revolut — Revolut customer lawful-disclosure / KYC data-request process (courtorders@revolut.com)
Vulnerable versions: N/A — process and email-authentication trust weakness in the customer-data-request verification workflow, not a software version - Revolut — Revolut customers (SMS/mobile messaging channel)
Vulnerable versions: Approximately 680 customers exposed in the underlying breach; smishing campaign targets affected and prospective Revolut customers generally
Remediation for Revolut Phishing SMS Campaign Follows Social-Engineering
Immediate actions
- Instruct affected and prospective Revolut customers never to follow links in SMS messages referencing Revolut, even when the message appears inside an existing legitimate conversation thread; verify identity requests only inside the official Revolut app
- Report and block the phishing domain 93810.app and its infrastructure at email/web gateways, DNS resolvers, and with mobile carriers
- Force password resets and step-up re-verification for any customer who may have submitted credentials or camera/liveness footage to the fake identity-verification page
- Proactively alert all 680 breach-affected customers to the follow-on smishing campaign and heightened SIM-swap / account-takeover risk
Workarounds
- Disable automatic link previews and restrict camera permissions for SMS/messaging apps until the campaign is confirmed contained
- Open the official Revolut app directly from the home screen rather than tapping any link received via SMS, email, or in-app chat
Longer-term hardening
- Require independent secondary verification (e.g., a callback to a pre-registered official number) before honoring any external law-enforcement or regulatory data request, regardless of email authentication status — authenticated email should be one signal, not the final authorization control
- Work with mobile carriers and messaging platforms to close the email-to-SMS gateway sender-identity mapping gaps that enable conversation thread injection
- Stand up continuous brand-impersonation monitoring for free-hosting platforms (GitHub Pages, GoDaddy-registered domains, similar app/domain TLD patterns) to accelerate takedown of lookalike Revolut phishing and extortion sites
- Extend fraud and account-takeover monitoring, and proactively offer SIM-swap protections, for the affected high-net-worth customer cohort given the leaked transaction and crypto wallet data
Timeline of Revolut Phishing SMS Campaign Follows Social-Engineering
- Revolut sends breach notification emails to affected customers ahead of public disclosure.
- Revolut publicly confirms a 'sophisticated external impersonation scam' in which a fraudulent request from a legitimate government agency email domain was used to obtain KYC data for roughly 680 customers.
- Telegram actor 'iamnotavillain' publishes stolen customer dossiers and demands a 10,000 BTC ransom, threatening daily leaks until paid.
- A second Telegram channel, 'Revolut Smilik,' separately claims responsibility for the breach, appearing to compete with or impersonate the original 'iamnotavillain' actor.
- SMS phishing texts begin appearing inside affected customers' legitimate Revolut conversation threads, linking to the fake liveness-check credential-harvesting page.
- Phishing domain 93810.app is first scanned on VirusTotal, hosting a fake Revolut identity-verification/liveness-check page.
- Reporting settles on approximately 680 affected customers; UK regulators (ICO, FCA) acknowledge receipt of Revolut's breach notification.
- Malwarebytes publishes threat-intel analysis linking the active SMS phishing campaign to the September 12 data-breach disclosure.
Sources cited for Revolut Phishing SMS Campaign Follows Social-Engineering
- Revolut phishing texts appear days after data breach
- Revolut Data Breach: Inside the Extortion Site
- Revolut Data Breach Via Fake Government Requests - What We Know So Far
- Revolut Data Breach: Five Days On, What Do We Actually Know?
- Revolut Customers' Passports, Selfies and Transaction Data Exposed After Fake Government Request
- Revolut Data Breach 2026: 680 Users Hit by Fake Gov Email
- Revolut Reportedly Released Customer Passports And Bitcoin Transaction Logs After Fake Government Email
- SMS Spoofing Via Email: How Thread Injection Works
More in phishing
- Large-Scale Azure-Hosted Tech Support Scam Campaign Targets Japan (13.38M Emails, 240K+ Relay IPs, 33K+ Disposable Azure Blob Storage Sites)
- Phishing Campaign Impersonates ChatGPT Subscription Billing Alerts to Steal OpenAI Credentials via Google API Open-Redirect and nxcli.io Infrastructure
- Global Fake Parcel Delivery Phishing/Smishing Campaign Steals Card and Bank Details
- Fake myGov 'Secure Message' Phishing Scam Targets Australians with Multi-Step Identity Harvesting Flow
- Fake ChatGPT Billing Email Phishing Campaign Abuses Google API Redirect to Steal OpenAI Credentials via nxcli.io
Detection coverage for TL-2026-2550
As of 2026-09-17, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2550 across Splunk SPL, Microsoft KQL and Sigma, covering 9 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.