Revolut customers have received convincing text messages days after the company acknowledged disclosing some customer records to an unauthorized party. The link may lead to a fake identity check and password page.
In 60 seconds
- Revolut customers should treat unexpected account texts as possible scams, even when they appear in an existing message thread.
- Check your account by opening the official Revolut app yourself, not by tapping the message link.
- If you entered a password or approved a camera request, contact Revolut through its official app or website.
- Do not grant camera access or enter account details on a page reached from an unsolicited text.
Who should care and what to do now
This matters most to Revolut customers, especially anyone who received a text about an account, identity check, password, or login. People who do not use Revolut can ignore the account-specific advice, but should recognize the same pattern in other banking scams.
To check safely, open the official Revolut app directly. Do not use the link in the text. If you use a browser instead, check the full website address before entering anything.
Do not grant camera access, type a password, or complete an identity check from an unexpected message. If you already did, contact Revolut through its official app or website and explain exactly what you entered or approved.
What Malwarebytes reported
Malwarebytes reported that Revolut had acknowledged disclosing sensitive customer records to an unauthorized party after accepting fraudulent information requests sent from an email address on a legitimate government agency domain. The records reportedly included identity and contact details, copies of passports or driver’s licenses, verification selfies, account statements, and transaction histories.
Revolut said a “limited” or “very limited” number of customers were affected and that it contacted them directly. Malwarebytes reported that one affected customer received a phishing text on September 14, two days after Revolut publicly acknowledged the disclosure.
The text appeared in the same conversation as earlier Revolut messages, which made it look more credible. Malwarebytes also reported that the phishing domain was first scanned that day, according to VirusTotal.
How the fake check can steal more information
In another reported example, tapping the message link opened a page that requested access to the device’s camera. After the user selected Allow, the page reportedly copied Revolut’s live-video identity check, including a request to turn the head, and then asked for a password.
A page that looks like a real identity check can make people less suspicious. It may also collect a selfie or video for later identity fraud or more convincing scams. Malwarebytes said that, if the campaign is connected to the disclosed information, details from the disclosure combined with a password or an approved login request could help criminals take over an account.
Malwarebytes said it is not yet known whether the messages used information from the disclosure or whether unrelated scammers are using the news to target Revolut customers. That uncertainty is why the message itself should not be treated as proof that the sender knows anything specific about you.
A safer way to handle account texts
Treat an unexpected account message as untrusted, even if it appears beside genuine messages. Open the company’s app yourself and look for notices there. If a browser page is involved, read the actual website address rather than relying on the page’s design or logo.
Keep your device and its security tools up to date. Malwarebytes also recommends real-time anti-malware protection with web protection, but the most important first step for this report is not following the unsolicited link.
Do not reply with passwords, identity documents, selfies, or account information. A text that asks for a camera permission followed by a password deserves particular caution.
Does this affect me?
- Who may be affected
- Revolut customers who receive unexpected texts about their account, identity check, password, or login should care. The reported messages may or may not be linked to the customer-record disclosure.
- How to check
- Open the official Revolut app directly and look for an account notice. If using a browser, inspect the complete website address before entering information.
- What to do
- If you clicked the link, entered a password, allowed camera access, or approved a login request, contact Revolut through its official app or website and describe what happened.
- What to avoid
- Do not tap unsolicited links, grant camera access, enter passwords, or complete an identity check from the text message.
Common questions
Does receiving one of these texts prove my Revolut information was disclosed?
No. Malwarebytes said it is not yet known whether the phishing campaign used information from the disclosure or whether unrelated scammers are using the news to target Revolut customers. The text alone does not prove you were among the affected customers.
What if the message appears in my real Revolut text conversation?
That does not make the new message safe. Malwarebytes reported that one phishing text appeared in the same conversation as other Revolut texts. Open the official app yourself instead of tapping the message link.
Why would a scam page ask to use my camera?
The reported page copied a live-video identity check and then requested a password. A fake check can collect a selfie or video and make the page seem genuine, while the password may help criminals attempt a real login or account recovery.
Primary source
This article uses Malwarebytes, “Revolut phishing texts appear days after data breach,” published September 17, 2026: https://www.malwarebytes.com/blog/threat-intel/2026/09/revolut-phishing-texts-appear-days-after-data-breach. See the linked original for complete technical details. No supporting vendor source was used. Read the complete original source.
Get the important updates without the noise
Choose the devices and topics you care about in Cyber Alerts.
Article history: Published Sep 17, 2026 at 10:42 am EDT. Updates and corrections are noted here when material facts change.
