Attackers have moved to exploit Revolut's acknowledged data breach with a phishing wave aimed at its customers, according to Malwarebytes, which documented several smishing messages received by Revolut users. One message arrived on 14 September, two days after the firm confirmed the incident, and in at least one case the scam text appeared inside the same conversation thread as genuine Revolut messages on the victim's device, which is the detail that makes this campaign more effective than a generic SMS phish: no unfamiliar sender appears, and the message inherits the credibility of the thread it lands in. The text urged the recipient to follow a link to confirm their identity or face restrictions on access to their account, and a separate customer reported that opening the link led to a page soliciting further information. The pattern is the standard post-disclosure playbook — breach reporting supplies both the target list and the pretext, and the window immediately after disclosure is when recipients are most likely to respond to an identity-verification prompt — and it applies to any financial institution that publishes an incident notice. Customers of a firm that has disclosed a breach should treat identity-verification requests as suspect regardless of which thread they arrive in.
| Attribute | Detail |
|---|---|
| Sector | Financial Services |
| Date | 2026-09-22 |
| Source | Infosecurity Magazine |
| Reliability | Tier 2 |