A breach at DriveWealth, the US broker behind Revolut’s US stock trading, exposed the personal data of some Revolut customers. DriveWealth and Revolut emailed affected customers on Thursday.
DriveWealth said an unauthorised party got into its network on 4 and 5 September. The access was the result of a social engineering campaign run by unknown third parties, it wrote. The Irish Independent reported on Thursday that the breach reached Revolut customers in Ireland.
“This security incident involved unauthorized access to historic personal data we held about you when you directly contracted with us in the past,” DriveWealth wrote.
What was taken
The data may include names, email addresses, phone numbers, postal addresses and employment details, DriveWealth said. It also covers country of citizenship, age, gender and a partial DriveWealth account number. The attackers did not get passwords or payment details such as card or bank account numbers, the broker said. It has reported the incident to the data protection authority in Lithuania.
Revolut customers who used its trading service signed two contracts, one with Revolut and one with DriveWealth, Revolut said in its email. Revolut moved EEA customers off that arrangement in December 2023, so the breach can only include data from before then. DriveWealth kept the records to meet its legal and regulatory duties, Revolut said.
In the UK and Australia, Revolut made the same change by June 2025, it told the Irish Independent. In the US, the incident covers customers who have used US stock trading.
“Your account can’t be accessed solely with the information involved in this incident, and we haven’t detected any unauthorised activity on your account,” Revolut wrote.
The breach did not reach Revolut’s own systems, it said, or any Revolut passwords, passcodes, card details or ID documents. Neither company will ask customers for their passcode or tell them to move money to another account, Revolut added.
Other brokers affected
DriveWealth runs US trading for other apps too. Australian broker Stake warned its customers on 21 September. New Zealand’s Hatch followed a day later, 1News reported. For their customers, the exposed data also included portfolio values and cash balances.
DriveWealth’s notice on its website lists about 62,000 affected residents of Rhode Island. It says it has found no unauthorised trading, transfers or withdrawals.
The DriveWealth breach is the second data incident at Revolut this month. On 12 September, Revolut confirmed it had handed over customer passports to scammers who posed as government officials. The company, valued at $115 billion, is planning a dual stock market listing in London and New York.
Get the TNW newsletter
Get the most important tech news in your inbox each week.
Facts Only
* DriveWealth experienced a network breach on 4 and 5 September.
* The breach was caused by a social engineering campaign.
* Exposed data includes names, email addresses, phone numbers, postal addresses, employment details, citizenship, age, gender, and partial account numbers.
* Passwords, payment details, card numbers, and bank account numbers were not accessed.
* Affected parties include Revolut customers in the US, Ireland, UK, and Australia, as well as customers of brokers Stake and Hatch.
* For Stake and Hatch customers, portfolio values and cash balances were also exposed.
* DriveWealth reported the incident to the data protection authority in Lithuania.
* Revolut moved EEA customers away from the DriveWealth contract in December 2023.
* Revolut plans to move UK and Australian customers to a new arrangement by June 2025.
* Approximately 62,000 Rhode Island residents are listed as affected on DriveWealth's website.
* On 12 September, Revolut confirmed the handover of customer passports to scammers posing as government officials.
Executive Summary
A social engineering attack on the US broker DriveWealth has exposed the personal data of customers across multiple fintech platforms, including Revolut, Stake, and Hatch. The breach occurred in early September, compromising historic personal identity markers such as contact information and employment details. While sensitive credentials like passwords and full bank account numbers remained secure, users of Stake and Hatch suffered additional exposure of their financial portfolio values and cash balances.
The impact on Revolut customers varies by region; those in the European Economic Area were largely insulated as they were transitioned off DriveWealth contracts in late 2023, whereas US, UK, and Australian customers remain potentially affected. DriveWealth maintained these records to satisfy legal and regulatory obligations. This event follows a separate security failure on 12 September where Revolut inadvertently provided customer passports to scammers. These incidents occur as Revolut pursues a dual stock market listing in London and New York.
Full Take
The strongest version of this narrative is a cautionary tale of "supply chain" vulnerability in fintech: a primary service provider (Revolut) is only as secure as its third-party infrastructure (DriveWealth). The data highlights a critical tension between regulatory compliance—where DriveWealth is required to keep "historic" data—and security, where that same data becomes a liability.
The pattern here is a "cascading failure." We see a systemic vulnerability where one breach at a mid-stream broker triggers a domino effect across multiple consumer-facing apps (Revolut, Stake, Hatch). Furthermore, the juxtaposition of the DriveWealth breach with the separate passport leak suggests a period of operational instability or "scaling friction" for Revolut as it prepares for a high-stakes dual listing. The assumption is that "historic data" is inert, yet this incident proves that archived data is a live target for social engineering.
The root cause is the persistent reliance on legacy contracting models where user data is fragmented across multiple legal entities, increasing the attack surface. The cost is borne by the end-user, who must now manage the long-term risk of identity theft, while the benefit of these arrangements (rapid market entry for the apps) accrues to the corporations.
Patterns detected: none
Bridge Questions:
1. If regulatory mandates require the retention of data that companies cannot fully secure, who should be legally liable for the breach—the data holder or the regulator?
2. How does the proximity of these breaches to a planned IPO affect the transparency of the disclosures?
3. What specific architectural changes are required to eliminate the "third-party broker" vulnerability in retail trading?
Counterstrike Scan: A coordinated attack would frame these separate incidents as a total systemic collapse of Revolut’s security to crash its valuation ahead of an IPO. The current presentation avoids this by distinguishing between the broker's breach and the company's internal error. Clean.
Sentinel — Human
The text reads like a factual aggregation of reported details from multiple sources concerning a data breach, exhibiting the typical structure and attribution of journalistic reporting.
