DriveWealth confirmed unauthorized network access on 4–5 September 2026. Revolut says its systems, funds and accounts were not affected. EEA data sharing with the broker ended in December 2023.
Revolut customers began receiving emails on 24 September 2026 warning that historic personal data linked to their past US share trading may have been exposed. The incident did not take place inside Revolut. It occurred at DriveWealth, a US brokerage firm that previously cleared Revolut’s US stock trades and still holds older customer records under regulatory retention rules. Revolut says its own systems, customer funds and accounts were not affected.
The notices arrive 12 days after Revolut first disclosed a separate data incident 12 September 2026, meaning customers are now dealing with two unrelated events tied to the same brand in less than two weeks.
What DriveWealth Says Happened
DriveWealth, a New York-based broker-dealer that provides US stock trading infrastructure to fintech apps, said on its official cyber-response page that unauthorized access to its network occurred between 4 September and 5 September 2026 and involved personal data held in certain DriveWealth systems.
The firm said no unauthorized brokerage activity was identified, including trades, transfers, withdrawals, Automated Customer Account Transfer (ACAT) requests or changes to balances and positions. It added that its production brokerage and trading systems, along with its client-facing platform, were not affected and continue to operate normally.
In its email to customers, DriveWealth attributed the access to a sophisticated social engineering campaign carried out by unknown third parties. Social engineering refers to attacks that manipulate people, rather than software, into granting access. DriveWealth also said it is monitoring accounts and is not aware of any identity fraud or misuse of information directly resulting from the incident.
Independent Revolut analyst Max Karpis was among the first to circulate the customer notices publicly. Revolut said it is still confirming the exact scope with DriveWealth. As of late morning UTC on 24 September, Revolut had not posted a numbered statement on its main Revolut account.
What Data Was Exposed
According to the notices, the historic data that may have been accessed includes:
- Customer profile data: name, email address, phone number, postal address and employment information
- Biographical data: country of citizenship, age and gender
- A partial account number
Revolut’s email to customers lists the same categories. Some recipients have reported that their individual notice also named date of birth, which suggests the exact fields may vary from person to person.
Both companies say passwords, payment cards, bank account details, and identity documents were not part of the exposed data, and that no unauthorized trades, withdrawals, or transfers took place.
Why Revolut Customers Are Affected
DriveWealth is named as the clearing broker for Revolut Securities Inc. and Revolut Wealth Inc. on Revolut’s US trading broker agreements page, which still links to the DriveWealth customer account agreement and privacy policy. A clearing broker settles trades and holds customer accounts on behalf of the app a customer uses.
For customers in the European Economic Area (EEA), Revolut said it stopped sending new data to DriveWealth in December 2023. As a result, only records created before that date can be involved for EEA users. Those older files remained with DriveWealth because brokers are required to retain certain records for regulatory purposes, which explains why a former partner can still trigger a breach notice years later.
Revolut has not said how many of its customers are included in the affected dataset, or whether every user who traded US shares before the cutoff is in scope.
Other DriveWealth Partners Report the Same Incident
Revolut is not the only platform affected. Australian investing app Stake published a data security notice on 21 September, saying DriveWealth supports its US trading and wallet functionality and that some customers’ personal information was affected. Stake said its own app was not breached and that no unauthorized trading occurred. Fields exposed for some Stake users may include name, contact details, W-8 or W-9 US tax form status, a DriveWealth account number, and snapshots of cash balance or portfolio value.
New Zealand platform Hatch also told customers in a help centre notice that DriveWealth data accessed on 4 and 5 September may include names, addresses, phone numbers, emails, investor profile ranges such as income and net assets, and cash and portfolio values. Hatch said identity documents, dates of birth, Inland Revenue Department (IRD) numbers and Hatch login details were not exposed.
DriveWealth’s own notice includes state-specific guidance for US residents and states that about 62,000 Rhode Island residents were affected across its wider customer base. That figure covers DriveWealth as a whole and is not a Revolut count.
Separate From Revolut’s Mid-September Incident
The DriveWealth event is unrelated to the case Revolut disclosed earlier this month. In that incident, Revolut staff processed fraudulent information requests sent from a mailbox on a genuine Italian government domain. Customer notices listed passports or driving licence copies, verification selfies, International Bank Account Numbers (IBANs), account statements and Bitcoin (BTC) transaction histories among the data handed over.
The attackers later began leaking customer passports and selfies, and reports put the number of affected customers at about 680, with the UK Information Commissioner’s Office (ICO) opening an assessment. The group behind the leaks subsequently lowered its ransom demand to about $3 million. Revolut has said it received no direct demand.
The two incidents differ in method and scope. The earlier case involved Know Your Customer (KYC) identity files released by Revolut itself in response to a fake official request. The DriveWealth case involves unauthorized access to a former broker’s retained archive of profile data, with no identity documents or banking details involved.
What Is Confirmed and What Remains Unknown
DriveWealth has confirmed the dates of access, the social engineering origin of the attack, and the absence of unauthorized account activity. Revolut has confirmed that its systems and funds were not compromised and that EEA data sharing with DriveWealth ended in December 2023. Stake and Hatch have issued parallel notices.
Still unknown is how many Revolut customers appear in the affected records, whether all pre-cutoff US trading users are included, and whether the stolen dataset has been offered for sale. As of late morning Coordinated Universal Time (UTC) on 24 September, Revolut had not published a standalone press statement on its main channels.
What Affected Customers Should Do
DriveWealth’s guidance asks customers to watch for phishing messages that may use the leaked profile data, forward suspicious emails claiming to be from the broker to accountsecurity@drivewealth.com, enable multi-factor authentication (MFA) and review account statements. Its dedicated response line is 1-844-770-4353. Credit monitoring is recommended for anyone whose individual notice lists a US Social Security number (SSN).
Revolut customers who traded US shares before the 2023 cutoff should rely on their own email or in-app notice to confirm what data is involved. Changing a Revolut password does not affect records already held by DriveWealth. The practical risk is targeted fraud, so customers should treat unexpected calls, texts or emails that reference their address or account details with caution and should never share verification codes or documents with anyone citing this incident.
Until Revolut or DriveWealth publishes a Revolut-specific figure, the scale of exposure for Revolut users remains unclear.
Also Read: Trump Ethics Filing Shows July Buys of Strategy (MSTR) and Coinbase (COIN) Stocks
