DriveWealth breach exposes data of Revolut customers who traded US stocks

A breach at DriveWealth, the US broker behind Revolut’s US stock trading, exposed the personal data of some Revolut customers. DriveWealth and Revolut emailed affected customers on Thursday.

DriveWealth said an unauthorised party got into its network on 4 and 5 September. The access was the result of a social engineering campaign run by unknown third parties, it wrote. The Irish Independent reported on Thursday that the breach reached Revolut customers in Ireland.

“This security incident involved unauthorized access to historic personal data we held about you when you directly contracted with us in the past,” DriveWealth wrote.

What was taken

The data may include names, email addresses, phone numbers, postal addresses and employment details, DriveWealth said. It also covers country of citizenship, age, gender and a partial DriveWealth account number. The attackers did not get passwords or payment details such as card or bank account numbers, the broker said. It has reported the incident to the data protection authority in Lithuania.

Revolut customers who used its trading service signed two contracts, one with Revolut and one with DriveWealth, Revolut said in its email. Revolut moved EEA customers off that arrangement in December 2023, so the breach can only include data from before then. DriveWealth kept the records to meet its legal and regulatory duties, Revolut said.

In the UK and Australia, Revolut made the same change by June 2025, it told the Irish Independent. In the US, the incident covers customers who have used US stock trading.

“Your account can’t be accessed solely with the information involved in this incident, and we haven’t detected any unauthorised activity on your account,” Revolut wrote.

The breach did not reach Revolut’s own systems, it said, or any Revolut passwords, passcodes, card details or ID documents. Neither company will ask customers for their passcode or tell them to move money to another account, Revolut added.

Other brokers affected

DriveWealth runs US trading for other apps too. Australian broker Stake warned its customers on 21 September. New Zealand’s Hatch followed a day later, 1News reported. For their customers, the exposed data also included portfolio values and cash balances.

DriveWealth’s notice on its website lists about 62,000 affected residents of Rhode Island. It says it has found no unauthorised trading, transfers or withdrawals.

The DriveWealth breach is the second data incident at Revolut this month. On 12 September, Revolut confirmed it had handed over customer passports to scammers who posed as government officials. The company, valued at $115 billion, is planning a dual stock market listing in London and New York.

Original source DriveWealth breach exposes data of Revolut customers who traded US stocks

Back to home