A new concern about the security of Revolut customer data is sparked by a cybersecurity incident at DriveWealth , the US brokerage firm that acts as a trading partner for US stocks. DriveWealth confirmed that an unauthorized entity gained access to its systems on September 4 and 5, 2026 , resulting in the exposure of historical personal data of some customers.

Revolut itself informed customers who may be affected, clarifying that the incident occurred in DriveWealth's systems and own Revolut's. DriveWealth acts as a clearing broker for Revolut Securities Inc. and Revolut Wealth Inc., as stated in Revolut's relevant agreements.
DriveWealth – How the breach happened
According to information so far, the attack is linked to a social engineering campaign, through which unknown perpetrators managed to gain unauthorized access to the DriveWealth network.
See also: Revolut data: 680 customers targeted after leak
This is particularly important, as it does not necessarily refer to a classic attack based on the exploitation of a technical vulnerability. Instead, social engineering targets people, processes and trust mechanisms, with attackers trying to convince employees to bypass, consciously or not, security controls.
DriveWealth says the access involved personal data previously held on its systems. This data may have remained stored for compliance with legal and regulatory requirements.
What data was exposed?
The scope of information that may have been affected varies depending on the customer. Data includes name, email address, phone number and postal address, as well as information related to the investment profile.
In some cases, the data may include information such as country of citizenship, age, gender, employment details and part of the DriveWealth account number . For customers of other partnered investment platforms, the company has said that even cash balances or total portfolio value may have been exposed .
Importantly, there is no indication passwords or payment details so far that , such as card and bank account numbers, were exposed. At the same time, DriveWealth has reported that no unauthorized transactions, transfers or withdrawals were detected.

Why are Revolut customers affected?
The relationship between the two companies explains why an incident at DriveWealth also involved Revolut users. For specific US stock trading services, customers had a contractual relationship with both Revolut and DriveWealth.
Revolut has since changed this structure for customers in some regions, but DriveWealth retained older data for as long as required by regulatory requirements. This means the report is historical data and not necessarily the current status of an account.
Revolut has also clarified that the information in this particular incident alone is not sufficient to gain access to a user's account and that no unauthorized activity has been detected in the accounts of the customers who were notified.
See also: Revolut: Fake government requests led to customer data leak
The risk of phishing after the leak
One of the biggest concerns following such a breach is the potential exploitation of the data for targeted fraud. The more information a fraudster has about a victim, the easier it can be to craft a convincing phishing email, SMS, or even phone call.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
The timing is also notable, as Revolut faced a different social engineering incident, in which scammers used fake government requests to obtain sensitive customer information. The company confirmed at the time that its internal systems were not compromised.
For users who have been informed about the DriveWealth incident, increased vigilance for suspicious messages is therefore particularly important. No representative from Revolut or DriveWealth should ask for passwords, passcodes, or to transfer funds to another account.
It wasn't just Revolut that was affected
DriveWealth also provides infrastructure and services to other investment platforms. Among the companies that have informed their clients about the incident are Australia's Stake and New Zealand's Hatch. Hatch, for example, said that its own systems were not breached, while client data held at DriveWealth may have been affected.
See also: Revolut: Its value was boosted by Schroders
This development highlights a broader risk for fintech businesses: even when a company's core systems remain secure, a third-party partner or provider can be a separate point of exposure.

What it means for customers
So far, the incident has not been linked to unauthorized transactions on the affected accounts. However, the exposure of personal and investment information could create a long-term risk for phishing, impersonation, and targeted financial fraud.
Users who received a relevant notification should be particularly wary of any message claiming to be from Revolut or DriveWealth and requesting confirmation of details, passwords or money transfers. At the same time, the case reminds us that the security of a financial service does not only depend on the protection of the main application, but on the entire chain of partners and providers that manage customer data.
