Security1 publisher2 min readPublished
Revolut phishing page requests camera access before imitating the bank's liveness check
Malwarebytes found smishing texts exploiting Revolut's breach within two days of the bank confirming it. The phishing flow asks for the phone camera and imitates the bank's own video identity check.
The Watch · Security desk

What happened
- Malwarebytes documented smishing texts sent to Revolut customers off the back of the bank's data breach, one of them arriving on September 14, two days after Revolut acknowledged the incident.
- The breach itself ran on fake KYC requests that impersonated Italian law enforcement, sent from Italian Ministry of the Interior email accounts compromised using infostealer logs.
- Several hundred accounts are thought to have been impacted, with high-net-worth crypto users singled out after the actors analyzed blockchain records, according to various reports.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- exposure A password taken alongside a recording of the customer's face reaches the account-recovery path as well as the login screen, and the footage is reusable at any other institution that asks for a selfie.
- constraint A text sitting inside the genuine Revolut thread removes sender identity as a check, leaving the domain in the address bar and opening the app directly as what customers can actually verify.
- contradiction Malwarebytes has not settled whether the texts use breach data or are opportunistic, and that difference decides whether the caller already holds the KYC answers a recovery agent would ask for.
- precedent Any bank treating a live video as a recovery factor now has to assume a browser camera prompt on a lookalike domain can collect equivalent footage from the customer.
Granting a web page access to the phone camera is a browser prompt. The page one Revolut customer reached asked for the camera, then ran what looked like the bank's live-video identity check, then asked for the password [6]. "A convincing fake liveness check followed by a password screen is a common way to lower suspicion and obtain the information attackers need to attempt a real login or account-recovery flow," Malwarebytes wrote [8].
The camera step rests on one customer's account, which Malwarebytes described as reported [6]. The vendor puts the captured footage in the category of material for later use. "It may also allow the scammers to collect a selfie or video that could be used for further social engineering, identity fraud, or to make subsequent scams more convincing," Malwarebytes wrote [7].
The first text Malwarebytes saw landed on September 14, two days after Revolut acknowledged the incident [2]. That puts the acknowledgment on about September 12 [3]. One message appeared in the same conversation thread on the victim's device as genuine Revolut texts [4]. Checking who sent it gets you the wrong answer here. The message told the recipient to follow a link to confirm their identity or have account access restricted [5].
The KYC data left Revolut through a legal-process channel. According to Infosecurity Magazine, the breach appears to have targeted the Lithuanian-regulated entity because it is legally obliged to respond to European Investigation Orders [11]. The actors impersonated Italian law enforcement, sending the fake KYC requests from Italian Ministry of the Interior email accounts compromised using infostealer logs [12]. They claimed around six months of access to those accounts, long enough to submit multiple fraudulent requests without raising suspicion [13]. Several hundred accounts are thought to have been affected, with high-net-worth crypto users singled out after the actors analyzed blockchain records, according to various reports [14].
Malwarebytes left open whether the smishing draws on the stolen KYC records or is opportunistic. It warned that if the campaign is linked to the breach, the hackers could have enough information to hijack accounts [9]. Its advice to customers was to open the app directly, skip links in unsolicited messages, check the domain in the browser address bar, and run up-to-date real-time anti-malware on the device [10].
What to watch
- Confirmation from Revolut or Malwarebytes that the smishing target list comes from the breached KYC records.
- Whether the affected-account count rises above several hundred as more breach detail emerges.
- Other banks reporting fraudulent law-enforcement data requests sent from compromised Italian government mailboxes.