An unauthorised intrusion into DriveWealth's systems occurred on 4 and 5 September, compromising personal information belonging to Revolut customers who had traded US stocks through the platform. For European Revolut users, the exposure is limited to records held prior to December 2023. Both DriveWealth and Revolut notified impacted customers via email on Thursday.
The breach stemmed from a social engineering campaign orchestrated by unknown attackers who gained network access to the US broker. DriveWealth, which operates the trading infrastructure behind Revolut's US stock offering, disclosed the incident and has since reported it to Lithuania's data protection authority.
This security incident involved unauthorized access to historic personal data we held about you when you directly contracted with us in the past
DriveWealth
What was taken
The compromised dataset potentially includes names, email addresses, phone numbers, postal addresses and employment information. Additional exposed fields encompass country of citizenship, age, gender and a partial DriveWealth account number. Crucially, the attackers did not obtain passwords or financial payment details including card or bank account numbers.
Revolut explained that customers using its trading service maintained separate contractual relationships with both Revolut and DriveWealth. The fintech firm transitioned European Economic Area customers away from this arrangement in December 2023, meaning the breach can only encompass data predating that transition. DriveWealth retained these records to satisfy legal and regulatory obligations, according to Revolut's communication.
The UK and Australia saw identical changes implemented by June 2025, Revolut disclosed to the Irish Independent. Within the United States, the incident touches customers who have engaged with the US stock trading feature.
Your account can't be accessed solely with the information involved in this incident, and we haven't detected any unauthorised activity on your account
Revolut
Revolut's own infrastructure remained uncompromised by the breach, the company stated, with no exposure to Revolut passwords, passcodes, card details or identity documents. Both organisations cautioned customers that they will never request passcodes or instruct account holders to transfer funds elsewhere.
Other brokers affected
DriveWealth provides US trading capabilities to multiple financial applications beyond Revolut. Australian brokerage Stake alerted its user base on 21 September, with New Zealand's Hatch following suit the next day, according to 1News. For these platforms' customers, the breach additionally exposed portfolio values and cash balances.
DriveWealth's public notice identifies approximately 62,000 affected residents of Rhode Island. The company has confirmed no unauthorised trading, transfers or withdrawals have been detected.
This marks the second data security incident involving Revolut within a single month. On 12 September, Revolut acknowledged that customer passports had been delivered to fraudsters impersonating government representatives. The company, currently valued at $115 billion, is preparing a dual listing on stock exchanges in London and New York.
Source: The Next Web



