Customers of Monzo and Revolut banks are being targeted in a phishing campaign which aims to steal their account credentials. The attack starts with a fake SMS that claims to be from the bank.
At the start of 2022, 27% of UK adults had an account with one of the digital only challenger banks, and Monzo is one of the leaders in the UK.
To open an Monzo account, you do not need to visit a brand, instead the entire process is completed within the app on your smartphone. Initial access to the account on a new device is granted through a ‘magic link’ which is used to login for the first time – if you have the magic link you can gain control over the bank account – and this is the target of the phishing campaign.
Monzo has warned their customers of the phishing campaign, including with this message thread on Twitter, and advises customers that they never send verification links by SMS.
Research into the phishing campaign has also revealed a number of fake login pages that have been prepared for Revolut bank customers as well as over 30 Monzo branded pages mostly hosted within Russian IP space.
“We were very impressed with the service, I will say, the vulnerability found was one our previous organisation had not picked up, which does make you wonder if anything else was missed.”
Aim Ltd Chief Technology Officer (CTO)