HomeIntelligenceBrief
BREACH BRIEF 🟠 High Breach

Revolut Data Breach Leads to Targeted Phishing Texts Exploiting Exposed Customer Records

Revolut confirmed that an unauthorized party accessed sensitive customer data, and days later customers received convincing phishing texts that mimicked official messages. The episode stresses the need for robust identity‑verification controls and a documented security‑awareness program for audit readiness.

Verisq™ Intelligence · 📅 September 18, 2026 · 📰 malwarebytes.com
🟠
Severity
High
BR
Type
Breach
🎯
Confidence
High
🏢
Affected
2 sector(s)
Actions
3 recommended
📰
Source
malwarebytes.com

Revolut Data Breach Leads to Targeted Phishing Texts Exploiting Exposed Customer Records

What Happened — Revolut disclosed that an unauthorized party accessed sensitive customer records, including IDs, selfies, and transaction histories. Days later, affected customers began receiving sophisticated phishing texts that mimicked official Revolut messages and attempted to harvest additional credentials.

Why It Matters for Trust & Control Assurance

  • The incident highlights the need for continuous verification of identity‑and‑access controls, especially around account‑recovery flows that can be abused after a data breach.
  • It underscores the importance of a documented security‑awareness program that can quickly educate users and provide evidence of due‑diligence for auditors.

Who Is Affected — Financial‑services firms, digital‑banking platforms, and any organization that handles personal identification data.

Recommended Actions

  • Review and harden account‑recovery and liveness‑check processes; enforce multi‑factor authentication for sensitive actions.
  • Deploy a security‑awareness campaign focused on phishing detection and safe handling of unsolicited messages.
  • Capture evidence of policy updates, training completion, and incident‑response drills for audit readiness.

Technical Notes — The breach stemmed from a social‑engineering attack that tricked Revolut staff into accepting fraudulent information requests from a government‑domain email address. The subsequent phishing texts used a spoofed Revolut sender ID and a malicious domain that prompted device‑camera access for a fake liveness check. Source: Malwarebytes Labs

📰 Original Source
https://www.malwarebytes.com/blog/threat-intel/2026/09/revolut-phishing-texts-appear-days-after-data-breach

This Verisq Intelligence Brief is an independent analysis. Read the original reporting at the link above.

Third-party risk

Does this breach reach you?

Verisq continuously monitors your vendors for breach and ransomware activity, so the question stops being whether it happened and becomes whether it reaches you.

See a live Trust Center →