Skip to content
Data breachContained

DriveWealth breach exposes data of Revolut, Stake and Hatch brokerage customers

US brokerage DriveWealth said a social-engineering attack exposed historic personal data of fintech customers, including Revolut, Stake and Hatch users who once traded US stocks through it.

Victim
DriveWealth

On 24 September 2026, US brokerage DriveWealth confirmed that a social-engineering attack had exposed historic personal data belonging to customers of fintech platforms that had used its embedded-investing infrastructure โ€” among them Revolut, Australia's Stake, and New Zealand's Hatch. The intrusion into DriveWealth's network took place on 4 and 5 September 2026; the company blamed a "sophisticated social engineering campaign" by unknown third parties rather than a technical exploit.

For Revolut customers, the data potentially at risk included names, email addresses, phone numbers, postal addresses, employment details and part of a DriveWealth account number. DriveWealth said it found no unauthorized trades, transfers, withdrawals or account-balance changes, and that no passwords, passcodes, card details or identity documents were compromised. Neither DriveWealth nor the affected fintechs disclosed a total number of impacted customers.

Historic data caught in the net

Revolut used DriveWealth to support US stock trading for its customers, and the exposed records dated from the period when those customers held accounts directly with the broker โ€” Revolut said it had transitioned users away from DriveWealth between December 2023 and June 2025. DriveWealth said regulatory record-retention requirements obliged it to keep the data even after the business relationship ended, which is why information on former users remained in its systems to be stolen.

Why it matters

The incident was the second data-security episode to hit Revolut customers in September 2026 alone, following an earlier case in which criminals abused a legitimate government agency's email domain to submit fraudulent data requests. Together they illustrate a recurring weakness of the embedded-finance model: a fintech's customers can be exposed through a back-end partner they never chose and may not even know exists. Because the stolen fields are exactly what attackers need for convincing phishing and impersonation, notified customers were urged to treat unexpected messages with caution. With access blocked and no financial loss reported, the incident's status was recorded as contained.

Timeline

  1. Unauthorized access to DriveWealth's network begins, continuing into 5 September.

  2. DriveWealth confirms the breach and affected fintechs, including Revolut, begin notifying customers whose historic data was exposed.

Sources

  1. theregister.comhttps://www.theregister.com/cyber-crime/2026/09/25/another-week-another-data-breach-for-revolut-customers/5299092
  2. financefeeds.comhttps://financefeeds.com/drivewealth-blames-social-engineering-campaign-for-revolut-customer-data-breach/
  3. crowdfundinsider.comhttps://www.crowdfundinsider.com/2026/09/312903-revolut-customers-caught-in-drivewealth-data-breach-after-third-party-security-incident/
  4. thenextweb.comhttps://thenextweb.com/news/drivewealth-breach-revolut-customers-us-stocks

Related incidents