Revolut customers targeted by phishing texts and fake liveness-check page days after social-engineering data breach

Revolut customers targeted by phishing texts and fake (TL-2026-2839), also tracked as Revolut data breach September 2026, is a high-severity phishing campaign, first published 2026-10-02. It has no confirmed attribution, affects Revolut Revolut customer accounts (KYC data, SMS channel), maps to 9 MITRE ATT&CK techniques (T1078, T1204.001, T1566.002), and is covered by 9 detection rules and 6 indicators of compromise.

Key facts for TL-2026-2839

Threat ID
TL-2026-2839
Also known as
Revolut data breach September 2026, Revolut smishing liveness-check campaign
Severity
HIGH
Status
ACTIVE
Category
PHISHING
First published
2026-10-02
Last reviewed
2026-10-02
Attribution confidence
LOW
Motivation
FINANCIAL
Target sectors
finance, fintech, cryptocurrency, consumer
Target regions
Europe, united kingdom
Detection rules
9
Indicators of compromise
6

Revolut acknowledged on 2026-09-12 that a social-engineering attack, using fraudulent information requests from a spoofed Italian government email address, exposed identity documents, verification selfies and transaction histories of a limited number of customers (~650-700 reported). From 2026-09-14 a customer received a smishing text inside the genuine Revolut SMS thread linking to 93810.app, a page that requested camera access, mimicked Revolut's 'turn your head' liveness check, then asked for a password. Whether the phishing is tied to the breach is unconfirmed.

How Revolut customers targeted by phishing texts and fake works

On 2026-09-12 Revolut publicly acknowledged that a social-engineering attack had exposed data of a limited number of customers. Per multiple reports, the attacker sent fraudulent information requests from an email address on a legitimate government domain (reported as an Italian government/regulator or law-enforcement address; The National and Euronews describe an Italian regulator / the Reggio Calabria prefecture mailbox, and a PEC sender on pec.interno.it was reported). The request reportedly passed SPF, DKIM and DMARC because it originated from a genuine government domain. No Revolut systems were breached: Revolut staff supplied the data in response to the fake request. Exposed data reportedly included identity and contact details, ID copies (passports, driving licences), verification selfies, account statements, transaction histories, IBANs and Bitcoin/wallet references. Revolut states customer funds and systems were unaffected, that it blocked the sender address and alerted authorities and regulators. Reported victim counts differ by outlet: Revolut confirmed about 680 European customers (Euronews); The National cites ~650; the extortionists claim at least 680 accounts, selected by blockchain analysis for large crypto holdings.

On 2026-09-17 a group calling itself 'iamnotavillain' posted a ransom demand of 6,000 XMR (about $3 million / EUR 2.61 million) with a 24-hour public countdown, threatening to sell the data otherwise, and claiming 147 GB taken from Italian law-enforcement systems (the law-enforcement compromise is an unverified claim). Reggio Calabria prosecutors reportedly opened an investigation. Infosecurity Magazine additionally reports the group used infostealer-log credentials to compromise Italian Ministry of Interior mailboxes with access held for ~6 months; this appears in a single outlet and is treated as unconfirmed.

The phishing campaign: from 2026-09-14 (two days after Revolut's acknowledgement) a customer received an SMS that appeared in the same conversation thread as genuine Revolut texts, urging the recipient to follow a link to confirm their identity or face account restrictions. The linked page, hosted on 93810.app (first scanned on VirusTotal 2026-09-14), requested device camera access, mimicked Revolut's 'turn your head' live-video identity check, and then prompted for the account password. This captures credentials and potentially selfie/video usable for identity fraud, account takeover or recovery-flow abuse. Malwarebytes (Pieter Arntz) stated it is unclear whether the phishing is connected to the breach or is opportunistic scamming exploiting the publicity. Inclusion in a genuine SMS thread suggests sender-ID spoofing, but the sources do not state the mechanism. No attribution of the phishing to the extortion group exists in the sources.

MITRE ATT&CK techniques used in TL-2026-2839

Initial Access

T1078 Valid Accounts; T1566.002 Spearphishing Link

Execution

T1204.001 Malicious Link

Resource Development

T1583.001 Domains; T1586.002 Email Accounts

Reconnaissance

T1589 Gather Victim Identity Information; T1598.003 Spearphishing Link

Impact

T1657 Financial Theft

Stealth

T1684.001 Impersonation

Affected products and versions in Revolut customers targeted by phishing texts and fake

  • Revolut — Revolut customer accounts (KYC data, SMS channel)
    Vulnerable versions: Customers whose KYC data was released (~650-700 reported); any customer receiving the smishing text

Remediation for Revolut customers targeted by phishing texts and fake

Immediate actions

  • Do not follow links in unsolicited SMS/email claiming to be Revolut; open the official Revolut app directly
  • Block/report 93810.app at web proxies, DNS filtering and mobile threat defense
  • Verify the domain in the browser address bar before granting camera access or entering credentials
  • Revolut customers who entered a password or completed a fake liveness check should change the password, review active sessions/devices and contact Revolut support in-app

Workarounds

  • Use up-to-date anti-malware with web protection on mobile devices
  • Treat any page that requests camera access plus a password as suspicious

Longer-term hardening

  • Financial institutions: require out-of-band verification (callback to a published channel) for government/regulator data requests, even when the sender domain is authentic and passes SPF/DKIM/DMARC
  • Restrict bulk release of KYC documents, selfies and transaction history to a dual-approval compliance workflow
  • Customers with large crypto balances should expect targeted social engineering and enable all available account protections

Timeline of Revolut customers targeted by phishing texts and fake

  • Revolut acknowledges a social-engineering attack in which fraudulent information requests from a spoofed government-agency email address led to disclosure of a limited number of customers' ID copies, selfies, contact details and transaction histories.
  • Phishing domain 93810.app is first scanned on VirusTotal; the page requests camera access, mimics Revolut's 'turn your head' liveness check, then asks for a password.
  • A Revolut customer receives a phishing text in the same SMS thread as genuine Revolut messages, urging identity confirmation to avoid account restriction.
  • Malwarebytes publishes analysis of the Revolut smishing and fake liveness-check page, noting the link to the breach is unconfirmed.
  • Group 'iamnotavillain' posts a 6,000 XMR (~$3M) ransom demand with a 24-hour public countdown, claiming ~680 targeted accounts and 147 GB from Italian law enforcement; Reggio Calabria prosecutors reportedly open an investigation.
  • Hackread reports the phishing campaign, adding exposed IBANs, wallet references and Bitcoin transaction details and that biometric facial telemetry was not compromised.
  • The National (~650 users affected, Revolut says it blocked the sender and alerted authorities) and Infosecurity Magazine (infostealer-credential and six-month-access claims, single source) publish further coverage.

Sources cited for Revolut customers targeted by phishing texts and fake

More in phishing

Detection coverage for TL-2026-2839

As of 2026-10-02, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2839 across Splunk SPL, Microsoft KQL and Sigma, covering 6 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat weather, live.

Every square is one real report, mapped to MITRE ATT&CK and shipped with Splunk SPL, Microsoft KQL and Sigma detections you can copy.

Every threat in the corpus, newest first.

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats