Revolut phishing texts appear days after data breach
Brief
Only days after Revolut acknowledged that it disclosed sensitive customer records to an unauthorized party, affected customers are receiving phishing texts. However, we don’t know yet if the phishing texts are linked to the breach.
The company had accepted fraudulent information requests sent from an email address on a legitimate government agency domain.
Through this social engineering attack, rather than by gaining access to Revolut’s systems, the criminals obtained the following types of information about customers:
- Identity and contact information such as dates of birth, postal addresses, email addresses, and phone numbers
- Copies of IDs such as passports and driver’s licenses
- Verification selfies
- Account statements and transaction histories
Revolut has said only that a “limited” or “very limited” number of customers were affected, and that it contacted them directly.
