Second Revolut data incident this month, now through its US broker DriveWealth
Revolut customers in Ireland and across the EEA started getting breach notices on 24 September, and the company whose systems were broken into is one most of them have never dealt with directly. DriveWealth, the US broker that executes and clears Revolut's US stock trades, says an unauthorised party was inside its network on 4 and 5 September after a social engineering campaign by unknown third parties.
The part worth pausing on is who is affected. In the EEA this covers people who used the US stock trading feature before December 2023, when Revolut changed the arrangement. Many of them stopped trading years ago. The broker kept their records anyway, because US regulation told it to.
In short
- Intruders were in DriveWealth's network on 4 and 5 September; the entry point was social engineering, not a software flaw.
- Exposed: names, emails, phone numbers, postal addresses, employment details, citizenship, age, gender, partial account numbers.
- No passwords and no card or bank details were taken, and the broker found no unauthorised trades, transfers or withdrawals.
- For EEA customers it only covers records from before December 2023, because that is when Revolut stopped sending them.
What DriveWealth says happened
In its own notice the broker states that it "discovered unauthorized access to our network occurred between September 4, 2026, and September 5, 2026", and that personal information was exfiltrated. It says production brokerage and trading systems and the client-facing platform were not affected and kept running, that no unauthorised brokerage activity was identified, including trading, transfers, withdrawals and account transfer requests, and that an internal investigation found no persistent threat, a finding it says outside experts validated independently.
The data itself is the ordinary customer file: name, email address, phone number, postal address and employment information, plus country of citizenship, age, gender and a partial DriveWealth account number. No passwords, no card or bank account numbers. DriveWealth has reported the incident to the data protection authority in Lithuania and set up a response line run through TransUnion. Its US filing lists roughly 62,000 affected residents of Rhode Island alone, which gives a sense of scale that none of the European statements do.
Why a broker you never picked had your file
Revolut's US stock trading was never a single relationship. A customer using it signed two agreements, one with Revolut and one with DriveWealth, and the broker held the personal data it needed to open the account, execute and settle trades and satisfy US regulatory requirements. Revolut says its own systems and infrastructure were not accessed, customer funds and investments are safe, and no Revolut passwords, passcodes, card details or ID documents were exposed. All of that is true, and none of it helps, because the file was never at Revolut.
Revolut moved EEA customers off that arrangement in December 2023 and completed the change in other markets by June 2025, after which individual customers' details were no longer shared. The records from before did not disappear, because DriveWealth kept them to meet legal and regulatory duties. This is the ordinary shape of financial data retention, and it means the set of people exposed by a 2026 breach was fixed years earlier by a contract most of them read once.
- Revolut changes its US stock trading model for the EEA; nothing new is sent to the broker after this.
- The same change is completed in the remaining markets.
- An unauthorised party is inside DriveWealth's network after a social engineering campaign.
- A separate Revolut incident becomes public: data handed to people posing as a government agency.
- Stake in Australia and Hatch in New Zealand warn their own customers about the same broker.
- DriveWealth and Revolut email affected customers; Irish media report the scale.
The same breach, different fields, depending on your app
DriveWealth runs US trading for several consumer platforms, and each one is now telling its own users a slightly different story. The Australian broker Stake warned customers on 21 September that for affected accounts the exposed data may include the DriveWealth account number, an aggregate snapshot of portfolio value, and a cash balance and buying power snapshot. Individual holdings, Stake says, were not included. New Zealand's Hatch followed a day later.
So the answer to "what leaked about me" depends on which app sat in front of the same broker. For Revolut's European customers the notices describe contact and identity fields without portfolio figures. Anyone who used more than one of these platforms has to read more than one notice, which is a strange thing to ask of a person who only ever pressed buy on a share.
The other Revolut incident this month
On 12 September, Revolut confirmed something quite different: an unauthorised third party had used an email domain belonging to a real government agency to send fraudulent requests for information, and the company handed over customer data in response, including passport and driving licence copies, dates of birth, home addresses, email addresses and phone numbers. Revolut called it a sophisticated external impersonation scam and said a limited number of people were affected; reports at the time put it at around 700 customers globally, about a dozen of them in Ireland. We wrote about that case when it broke, in the story of the fake government request.
The two have nothing technical in common, and treating them as one story would be wrong. What they share is the direction of the attack. Neither one involved breaking Revolut's encryption or guessing anyone's password. One convinced a broker's staff, the other convinced a bank's process, and both walked out with files.
What this data is actually useful for
No passwords were taken, so nobody is logging into an account with this. What the file does support is a phone call or an email that knows your name, your employer, the last four characters of a brokerage account you had forgotten, and the fact that you once traded US shares through a specific app. That combination is the raw material for a convincing "we have detected suspicious activity on your account" approach, and it does not expire. DriveWealth's own notice spends most of its length on phishing advice for exactly this reason. Regulators elsewhere have started fining suppliers over this pattern, as Sweden did over a leak at an HR contractor serving most of the country's municipalities. The practical side of living through one of these is the same everywhere, which we went through when a Latvian repair chain lost customer records including device unlock codes.
- Read the actual notice from the broker and from your app; they list different fields, and only the notice tells you what was in your record
- Treat any call or message about this breach as hostile until you have called back on the number from the official app or website
- Switch account recovery away from SMS to an authenticator app wherever the platform allows it
- Check whether the email address in the leaked file is the one protecting other accounts, and change that password if it is reused
- If you no longer use a trading feature, ask the provider to delete what it is not legally required to keep, and keep the answer
Am I affected if I never used US stock trading?
Was Revolut itself hacked?
Could someone trade or withdraw using this data?
Why does a company still hold data from 2023?
Does a VPN protect against this?
• Cyber-Response notice - DriveWealth Legal Hub
• Irish Revolut customers affected by "third-party" data breach - The Irish Times
• Irish Revolut customers impacted by data breach - RTÉ
• DriveWealth breach exposes data of Revolut customers who traded US stocks - The Next Web
• Irish Revolut customers' data involved in second security breach - TheJournal.ie
• DriveWealth Data Security Incident - Stake