# When 75% of Your Town's Scam Calls Target One App, That's Not Coincidence
Jersey's four-week Revolut crisis is a clinic in how fraudsters pick a target and run a campaign — not a random crime wave.
---
## The Number That Should Alarm You
Seventy-five percent. That's the share of all scam crime reports Jersey Police received over a single four-week period that involved Revolut accounts. The island lost £180,000. In a jurisdiction with roughly 110,000 residents.
That concentration figure is the real story here. Fraud campaigns don't produce numbers like that by accident. When three-quarters of your incoming scam reports point to a single financial platform, you're not looking at opportunistic criminals dialing random numbers and hoping for the best. You're looking at a coordinated operation — one with a target list, a script, and enough success rate to keep running.
Jersey police issued their warning in August, but the pattern fits squarely into a broader campaign mode that fraud analysts have tracked against neo-banks for the better part of three years.
---
## Why Revolut, Specifically
Revolut has roughly 50 million customers globally and has become a default bank account for a large slice of the UK and European market, particularly among younger, mobile-first users. That scale makes it a useful brand to impersonate. But the more interesting question isn't why criminals use the Revolut name — it's why attacks against Revolut users keep producing such high success rates.
A few structural factors are worth naming directly.
Speed is the feature that becomes the vulnerability. Revolut's core value proposition is instant money movement — pay a friend, convert currency, transfer funds. That same speed works against users when a fraudster on the phone is walking them through an "account protection" transfer. Money moved inside a neo-bank app can clear in seconds. Traditional banks have friction built in. That friction, which every fintech startup spent the last decade trying to eliminate, is also a fraud buffer.
The customer support gap. Revolut, like most neo-banks, routes support through in-app chat and email rather than phone. This creates a specific opening for vishing: because there is no official inbound phone number to call for help, users have no mental model of what a real Revolut call looks like. A scammer calling from a spoofed number claiming to be Revolut security is working in a vacuum. The target has no comparison point.
Customer demographics. Neo-bank users skew younger and more comfortable moving money on phones quickly and without second-guessing. That's a feature to a product manager. It's also a feature to a social engineer.
None of this is unique to Revolut. Monzo, Starling, Cash App, and Chime have all appeared in similar fraud complaint clusters over the past two years. But Revolut's European reach makes it the dominant target in markets like Jersey.
---
## Jersey as a Campaign Test Bed
The Channel Islands might seem like an unusual focal point for a fraud campaign, but there's logic to it.
Jersey is small, relatively affluent, and has high Revolut penetration. For criminals running a phone-based vishing campaign, a small, high-income community offers excellent signal: high success rate on individual calls translates to high average take per victim, without the noise of running operations in a city of millions where local police attention is diffused.
The £180,000 figure across four weeks averages to roughly £2,400 per victim assuming a typical conversion rate. That's consistent with "account freezing" or "fraud protection" social engineering scripts, where victims are convinced to move savings to a "safe" account the fraudster controls. These aren't grab-and-run card-skimming schemes. These are conversations — often twenty minutes or longer — where a convincing voice guides someone through their own app.
Jersey police have advised residents to hang up and call back using verified numbers. That's the right advice. It's also advice that a significant slice of the population won't follow in the moment because the caller sounds authoritative and the scenario sounds urgent.
---
## What Defenders — and Users — Should Actually Do
For individuals:
For Revolut and other neo-banks, the product question is harder but unavoidable: can you build friction that slows down fraud-initiated transfers without destroying the user experience that differentiates your product? Some platforms have begun experimenting with cooling-off periods on large first-time transfers to new payees, along with in-app warnings during active calls. That's the right direction.
---
## HackWire Analysis
The 75% concentration figure is the most important data point in this story and most coverage has treated it as a curiosity rather than evidence of campaign structure.
Fraud gangs — particularly those operating out of eastern Europe and parts of southeast Asia — have become increasingly methodical about target selection. They don't hit every bank randomly. They build lists by platform, by region, and by likely victim profile, then run structured campaigns with scripts that evolve based on what produces conversions. A 75% market share in a small jurisdiction's scam reports suggests a single operation, not multiple independent actors who all happened to choose Revolut.
The Jersey wave should be read as a canary. If fraudsters are running a disciplined campaign against a small, high-income island and producing results at that rate, the same playbook is almost certainly being tested or deployed in larger UK and EU markets simultaneously. Jersey's size just makes the statistical footprint visible. In London or Dublin, the same campaign would show up as a modest uptick in Revolut fraud complaints across a much noisier baseline.
The deeper problem is structural: neo-banks built distribution by eliminating friction, and regulators have been slow to require them to maintain the same fraud friction controls that traditional banks have developed over decades. The UK's Payment Systems Regulator has pushed for mandatory reimbursement of authorized push payment fraud, which shifted some liability onto banks — but the better intervention is upstream, at the point where the call is happening, not downstream in the reimbursement queue.
Until the product design catches up, users of any app-native bank should treat any unsolicited financial call as hostile by default, regardless of what caller ID says.
— HackWire Editorial
---
## Related Coverage