Second Revolut data incident this month, now through its US broker DriveWealth

24.09.2026 8 min 22

Revolut customers in Ireland and across the EEA started getting breach notices on 24 September, and the company whose systems were broken into is one most of them have never dealt with directly. DriveWealth, the US broker that executes and clears Revolut's US stock trades, says an unauthorised party was inside its network on 4 and 5 September after a social engineering campaign by unknown third parties.

The part worth pausing on is who is affected. In the EEA this covers people who used the US stock trading feature before December 2023, when Revolut changed the arrangement. Many of them stopped trading years ago. The broker kept their records anyway, because US regulation told it to.

In short

  • Intruders were in DriveWealth's network on 4 and 5 September; the entry point was social engineering, not a software flaw.
  • Exposed: names, emails, phone numbers, postal addresses, employment details, citizenship, age, gender, partial account numbers.
  • No passwords and no card or bank details were taken, and the broker found no unauthorised trades, transfers or withdrawals.
  • For EEA customers it only covers records from before December 2023, because that is when Revolut stopped sending them.

What DriveWealth says happened

In its own notice the broker states that it "discovered unauthorized access to our network occurred between September 4, 2026, and September 5, 2026", and that personal information was exfiltrated. It says production brokerage and trading systems and the client-facing platform were not affected and kept running, that no unauthorised brokerage activity was identified, including trading, transfers, withdrawals and account transfer requests, and that an internal investigation found no persistent threat, a finding it says outside experts validated independently.

The data itself is the ordinary customer file: name, email address, phone number, postal address and employment information, plus country of citizenship, age, gender and a partial DriveWealth account number. No passwords, no card or bank account numbers. DriveWealth has reported the incident to the data protection authority in Lithuania and set up a response line run through TransUnion. Its US filing lists roughly 62,000 affected residents of Rhode Island alone, which gives a sense of scale that none of the European statements do.

2 daysthe window of unauthorised access, 4 to 5 September
62 000affected residents of Rhode Island in the US filing
2contracts a trading customer signed: with Revolut and with the broker
2nddata incident around Revolut this month

Why a broker you never picked had your file

Revolut's US stock trading was never a single relationship. A customer using it signed two agreements, one with Revolut and one with DriveWealth, and the broker held the personal data it needed to open the account, execute and settle trades and satisfy US regulatory requirements. Revolut says its own systems and infrastructure were not accessed, customer funds and investments are safe, and no Revolut passwords, passcodes, card details or ID documents were exposed. All of that is true, and none of it helps, because the file was never at Revolut.

Revolut moved EEA customers off that arrangement in December 2023 and completed the change in other markets by June 2025, after which individual customers' details were no longer shared. The records from before did not disappear, because DriveWealth kept them to meet legal and regulatory duties. This is the ordinary shape of financial data retention, and it means the set of people exposed by a 2026 breach was fixed years earlier by a contract most of them read once.

  1. Revolut changes its US stock trading model for the EEA; nothing new is sent to the broker after this.
  2. The same change is completed in the remaining markets.
  3. An unauthorised party is inside DriveWealth's network after a social engineering campaign.
  4. A separate Revolut incident becomes public: data handed to people posing as a government agency.
  5. Stake in Australia and Hatch in New Zealand warn their own customers about the same broker.
  6. DriveWealth and Revolut email affected customers; Irish media report the scale.
Not disclosed: how many people are affected in Ireland, in the EEA, or in total. Revolut says DriveWealth is best placed to answer that and is still confirming the exact scope. The only concrete number in the open is the Rhode Island filing.

The same breach, different fields, depending on your app

DriveWealth runs US trading for several consumer platforms, and each one is now telling its own users a slightly different story. The Australian broker Stake warned customers on 21 September that for affected accounts the exposed data may include the DriveWealth account number, an aggregate snapshot of portfolio value, and a cash balance and buying power snapshot. Individual holdings, Stake says, were not included. New Zealand's Hatch followed a day later.

So the answer to "what leaked about me" depends on which app sat in front of the same broker. For Revolut's European customers the notices describe contact and identity fields without portfolio figures. Anyone who used more than one of these platforms has to read more than one notice, which is a strange thing to ask of a person who only ever pressed buy on a share.

The other Revolut incident this month

On 12 September, Revolut confirmed something quite different: an unauthorised third party had used an email domain belonging to a real government agency to send fraudulent requests for information, and the company handed over customer data in response, including passport and driving licence copies, dates of birth, home addresses, email addresses and phone numbers. Revolut called it a sophisticated external impersonation scam and said a limited number of people were affected; reports at the time put it at around 700 customers globally, about a dozen of them in Ireland. We wrote about that case when it broke, in the story of the fake government request.

The two have nothing technical in common, and treating them as one story would be wrong. What they share is the direction of the attack. Neither one involved breaking Revolut's encryption or guessing anyone's password. One convinced a broker's staff, the other convinced a bank's process, and both walked out with files.

What this data is actually useful for

No passwords were taken, so nobody is logging into an account with this. What the file does support is a phone call or an email that knows your name, your employer, the last four characters of a brokerage account you had forgotten, and the fact that you once traded US shares through a specific app. That combination is the raw material for a convincing "we have detected suspicious activity on your account" approach, and it does not expire. DriveWealth's own notice spends most of its length on phishing advice for exactly this reason. Regulators elsewhere have started fining suppliers over this pattern, as Sweden did over a leak at an HR contractor serving most of the country's municipalities. The practical side of living through one of these is the same everywhere, which we went through when a Latvian repair chain lost customer records including device unlock codes.

  • Read the actual notice from the broker and from your app; they list different fields, and only the notice tells you what was in your record
  • Treat any call or message about this breach as hostile until you have called back on the number from the official app or website
  • Switch account recovery away from SMS to an authenticator app wherever the platform allows it
  • Check whether the email address in the leaked file is the one protecting other accounts, and change that password if it is reused
  • If you no longer use a trading feature, ask the provider to delete what it is not legally required to keep, and keep the answer
Am I affected if I never used US stock trading?
No. The incident covers records DriveWealth held for people who used that feature. Both companies contacted affected customers directly, and Revolut says that if you did not receive an email, you are not affected.
Was Revolut itself hacked?
No. The intrusion was in DriveWealth's network. Revolut says its systems and infrastructure were not accessed and that no Revolut passwords, passcodes, card details or ID documents were exposed.
Could someone trade or withdraw using this data?
The broker says it identified no unauthorised trading, transfers, withdrawals or account transfer requests, and that no passwords or payment details were taken. The realistic risk is targeted fraud by phone and email.
Why does a company still hold data from 2023?
Because financial regulation requires brokers to retain account records for years after the relationship ends. Deleting them on request is often not an option for the company, which is why the exposed group includes people who left long ago.
Does a VPN protect against this?
No. The data was taken from a broker's internal systems, not from anyone's connection. A VPN protects traffic in transit and has no effect on records a regulated company is obliged to keep about you.

revolutdrivewealthdata breachpersonal dataphishingdata protectionprivacyirelandcybersecurityidentity theft

Read also