Revolut customers targeted by phishing texts and fake liveness-check page days after social-engineering data breach
Revolut customers targeted by phishing texts and fake (TL-2026-2839), also tracked as Revolut data breach September 2026, is a high-severity phishing campaign, first published 2026-10-02. It has no confirmed attribution, affects Revolut Revolut customer accounts (KYC data, SMS channel), maps to 9 MITRE ATT&CK techniques (T1078, T1204.001, T1566.002), and is covered by 9 detection rules and 6 indicators of compromise.
Key facts for TL-2026-2839
- Threat ID
- TL-2026-2839
- Also known as
- Revolut data breach September 2026, Revolut smishing liveness-check campaign
- Severity
- HIGH
- Status
- ACTIVE
- Category
- PHISHING
- First published
- 2026-10-02
- Last reviewed
- 2026-10-02
- Attribution confidence
- LOW
- Motivation
- FINANCIAL
- Target sectors
- finance, fintech, cryptocurrency, consumer
- Target regions
- Europe, united kingdom
- Detection rules
- 9
- Indicators of compromise
- 6
Revolut acknowledged on 2026-09-12 that a social-engineering attack, using fraudulent information requests from a spoofed Italian government email address, exposed identity documents, verification selfies and transaction histories of a limited number of customers (~650-700 reported). From 2026-09-14 a customer received a smishing text inside the genuine Revolut SMS thread linking to 93810.app, a page that requested camera access, mimicked Revolut's 'turn your head' liveness check, then asked for a password. Whether the phishing is tied to the breach is unconfirmed.
How Revolut customers targeted by phishing texts and fake works
On 2026-09-12 Revolut publicly acknowledged that a social-engineering attack had exposed data of a limited number of customers. Per multiple reports, the attacker sent fraudulent information requests from an email address on a legitimate government domain (reported as an Italian government/regulator or law-enforcement address; The National and Euronews describe an Italian regulator / the Reggio Calabria prefecture mailbox, and a PEC sender on pec.interno.it was reported). The request reportedly passed SPF, DKIM and DMARC because it originated from a genuine government domain. No Revolut systems were breached: Revolut staff supplied the data in response to the fake request. Exposed data reportedly included identity and contact details, ID copies (passports, driving licences), verification selfies, account statements, transaction histories, IBANs and Bitcoin/wallet references. Revolut states customer funds and systems were unaffected, that it blocked the sender address and alerted authorities and regulators. Reported victim counts differ by outlet: Revolut confirmed about 680 European customers (Euronews); The National cites ~650; the extortionists claim at least 680 accounts, selected by blockchain analysis for large crypto holdings.
On 2026-09-17 a group calling itself 'iamnotavillain' posted a ransom demand of 6,000 XMR (about $3 million / EUR 2.61 million) with a 24-hour public countdown, threatening to sell the data otherwise, and claiming 147 GB taken from Italian law-enforcement systems (the law-enforcement compromise is an unverified claim). Reggio Calabria prosecutors reportedly opened an investigation. Infosecurity Magazine additionally reports the group used infostealer-log credentials to compromise Italian Ministry of Interior mailboxes with access held for ~6 months; this appears in a single outlet and is treated as unconfirmed.
The phishing campaign: from 2026-09-14 (two days after Revolut's acknowledgement) a customer received an SMS that appeared in the same conversation thread as genuine Revolut texts, urging the recipient to follow a link to confirm their identity or face account restrictions. The linked page, hosted on 93810.app (first scanned on VirusTotal 2026-09-14), requested device camera access, mimicked Revolut's 'turn your head' live-video identity check, and then prompted for the account password. This captures credentials and potentially selfie/video usable for identity fraud, account takeover or recovery-flow abuse. Malwarebytes (Pieter Arntz) stated it is unclear whether the phishing is connected to the breach or is opportunistic scamming exploiting the publicity. Inclusion in a genuine SMS thread suggests sender-ID spoofing, but the sources do not state the mechanism. No attribution of the phishing to the extortion group exists in the sources.
MITRE ATT&CK techniques used in TL-2026-2839
Initial Access
T1078 Valid Accounts; T1566.002 Spearphishing Link
Execution
Resource Development
T1583.001 Domains; T1586.002 Email Accounts
Reconnaissance
T1589 Gather Victim Identity Information; T1598.003 Spearphishing Link
Impact
Stealth
Affected products and versions in Revolut customers targeted by phishing texts and fake
- Revolut — Revolut customer accounts (KYC data, SMS channel)
Vulnerable versions: Customers whose KYC data was released (~650-700 reported); any customer receiving the smishing text
Remediation for Revolut customers targeted by phishing texts and fake
Immediate actions
- Do not follow links in unsolicited SMS/email claiming to be Revolut; open the official Revolut app directly
- Block/report 93810.app at web proxies, DNS filtering and mobile threat defense
- Verify the domain in the browser address bar before granting camera access or entering credentials
- Revolut customers who entered a password or completed a fake liveness check should change the password, review active sessions/devices and contact Revolut support in-app
Workarounds
- Use up-to-date anti-malware with web protection on mobile devices
- Treat any page that requests camera access plus a password as suspicious
Longer-term hardening
- Financial institutions: require out-of-band verification (callback to a published channel) for government/regulator data requests, even when the sender domain is authentic and passes SPF/DKIM/DMARC
- Restrict bulk release of KYC documents, selfies and transaction history to a dual-approval compliance workflow
- Customers with large crypto balances should expect targeted social engineering and enable all available account protections
Timeline of Revolut customers targeted by phishing texts and fake
- Revolut acknowledges a social-engineering attack in which fraudulent information requests from a spoofed government-agency email address led to disclosure of a limited number of customers' ID copies, selfies, contact details and transaction histories.
- Phishing domain 93810.app is first scanned on VirusTotal; the page requests camera access, mimics Revolut's 'turn your head' liveness check, then asks for a password.
- A Revolut customer receives a phishing text in the same SMS thread as genuine Revolut messages, urging identity confirmation to avoid account restriction.
- Malwarebytes publishes analysis of the Revolut smishing and fake liveness-check page, noting the link to the breach is unconfirmed.
- Group 'iamnotavillain' posts a 6,000 XMR (~$3M) ransom demand with a 24-hour public countdown, claiming ~680 targeted accounts and 147 GB from Italian law enforcement; Reggio Calabria prosecutors reportedly open an investigation.
- Hackread reports the phishing campaign, adding exposed IBANs, wallet references and Bitcoin transaction details and that biometric facial telemetry was not compromised.
- The National (~650 users affected, Revolut says it blocked the sender and alerted authorities) and Infosecurity Magazine (infostealer-credential and six-month-access claims, single source) publish further coverage.
Sources cited for Revolut customers targeted by phishing texts and fake
- Revolut phishing texts appear days after data breach (Malwarebytes, Pieter Arntz)
- Revolut Customers Targeted by Phishing Campaign After Data Breach (Hackread)
- Revolut Customers Targeted with New Wave of Phishing Attacks (Infosecurity Magazine)
- Revolut customers' sensitive data exposed in phishing attack that fooled email security checks (Crypto Briefing)
- Revolut faces $3M Monero ransom demand following customer data compromise (Parameter)
- Revolut hack: criminals steal data of 700 European clients, demand $3M ransom (Euronews)
- Revolut hack / data breach cyber (The National)
- Revolut hacker claims 147 GB stolen from Italian law enforcement (Pasquale Pillitteri)
More in phishing
- Free Mobile phishing emails (unpaid €9.99 invoice lure) follow earlier Free Mobile data breach
- Milk Dragon (NaiLong) AiTM Phishing-as-a-Service Kit Targeting Social Media Shoppers and Bank MFA
- ScreenConnect Client Abused by Attackers via Mejuri-Themed Payment Receipt Phishing
- CSuite Phishing Operation Steals Microsoft 365 Sessions via Device-Code Phishing and Deploys ScreenConnect/Action1 RMM Tools Against US and EU Organizations
- Former US Air Force Members Odimegwu and Mogaji Sentenced Over Phishing-Driven BEC Fraud Ring Targeting 15+ Organizations
Detection coverage for TL-2026-2839
As of 2026-10-02, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2839 across Splunk SPL, Microsoft KQL and Sigma, covering 6 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.