DriveWealth Breach Exposes Personal Data of Revolut, Stake, and Hatch Customers
DriveWealth, a US-based broker providing services for Revolut’s US stock trading, experienced a social engineering attack that exposed personal data of some Revolut customers. The breach, which occurred on 4 and 5 September, also impacted customers of other brokers, including Australia’s Stake and New Zealand’s Hatch.
LazyFounders

DriveWealth, a US-based broker providing services for Revolut’s US stock trading, experienced a social engineering attack that exposed personal data of some Revolut customers. The breach, which occurred on 4 and 5 September, also impacted customers of other brokers, including Australia’s Stake and New Zealand’s Hatch.
30 SEC SUMMARY
- DriveWealth, a US broker, suffered a social engineering breach on 4 and 5 September, exposing personal data of Revolut customers who traded US stocks.
- Exposed data includes names, emails, addresses, employment details, and partial account numbers, but no passwords or payment information.
- The breach also affected customers of Australian broker Stake and New Zealand’s Hatch, with additional financial data exposed.
- Revolut confirmed its systems were not compromised, and DriveWealth reported no unauthorized trading or withdrawals.
- This is Revolut’s second data incident this month, following a scam involving customer passports.
TABLE OF CONTENTS
- Breach Details and Impact
- Regional Impact and Response
- Wider Fallout Among Brokers
- Broader Context for Revolut
- What this means
- Key takeaways
- FAQ
- Sources
KEY HIGHLIGHTS
- DriveWealth, a US broker, experienced a social engineering breach on 4 and 5 September.
- Personal data of Revolut customers who traded US stocks was exposed, including names, emails, and addresses.
- No passwords or payment details, such as card or bank account numbers, were compromised.
- Revolut confirmed its systems were not affected, and DriveWealth reported no unauthorized transactions.
- The breach also impacted customers of Australian broker Stake and New Zealand’s Hatch.
Breach Details and Impact
According to The Next Web, DriveWealth, a US-based broker, experienced a data breach on 4 and 5 September after an unauthorized party gained access to its network. The breach resulted from a social engineering attack targeting the company.
The exposed data includes personal information of Revolut customers who traded US stocks. Affected details reportedly cover names, email addresses, phone numbers, postal addresses, employment information, country of citizenship, age, gender, and partial DriveWealth account numbers. No passwords or payment details, such as card or bank account numbers, were compromised.
Regional Impact and Response
Revolut customers in the European Economic Area (EEA) were moved off the DriveWealth platform in December 2023, meaning only data from before that date was exposed. In the UK and Australia, this change was implemented by June 2025. For US-based Revolut customers, the breach affects those who used the platform’s US stock trading service.
DriveWealth reported the incident to the data protection authority in Lithuania, as required by regulatory obligations. The company stated it found no evidence of unauthorized trading, transfers, or withdrawals resulting from the breach.
Revolut confirmed that its own systems were not compromised, and sensitive customer data, such as passwords, passcodes, card details, and ID documents, remained secure. Both companies emphasized that neither will request customers’ passcodes or instruct them to move money to other accounts.
Wider Fallout Among Brokers
The breach also impacted customers of other brokers using DriveWealth’s services. Australian broker Stake warned its customers about the incident on 21 September, followed by New Zealand’s Hatch a day later. For these customers, additional data, including portfolio values and cash balances, was reportedly exposed.
DriveWealth’s public notice indicated that approximately 62,000 residents of Rhode Island were affected by the breach.
Broader Context for Revolut
This incident marks the second data-related issue for Revolut this month. On 12 September, the company confirmed that scammers posing as government officials obtained customer passports. The timing of these events coincides with Revolut’s plans for a dual stock market listing in London and New York.
What this means
LazyFounders analysis — our interpretation, not reported fact.
This breach underscores the risks of third-party dependencies in financial services. Even when a company like Revolut secures its own systems, vulnerabilities in partners—such as brokers or service providers—can expose customer data. For founders and operators, the incident highlights two critical lessons:
First, vendor risk management is non-negotiable. Companies must assess not only their own security posture but also that of their partners, especially when handling sensitive customer data. Contracts should include clear obligations for data protection, breach notification, and remediation.
Second, transparency and communication matter during incidents. Revolut’s swift confirmation that its own systems were unaffected helps maintain customer trust, while DriveWealth’s regulatory reporting demonstrates compliance. However, the fact that customers of multiple brokers were impacted shows how a single breach can ripple across borders and business models.
For fintech startups, this is a reminder that regulatory scrutiny will only intensify as the sector grows. Balancing innovation with compliance—particularly in cross-border operations—is a challenge that requires proactive investment in legal and security teams.
Key takeaways
- DriveWealth, a US-based broker, experienced a social engineering attack on 4 and 5 September, leading to a data breach.
- The breach exposed personal data of Revolut customers who traded US stocks, including names, contact details, and employment information.
- No passwords or payment details, such as card or bank account numbers, were compromised in the incident.
- Revolut’s own systems and sensitive customer data remained secure, but the breach affected customers in multiple regions.
- DriveWealth reported the incident to Lithuania’s data protection authority and found no evidence of unauthorized trading or withdrawals.
FAQ
What data was exposed in the DriveWealth breach?
The breach exposed personal information such as names, email addresses, phone numbers, postal addresses, employment details, country of citizenship, age, gender, and partial DriveWealth account numbers. No passwords or payment details, like card or bank account numbers, were compromised.
Were Revolut’s systems directly affected by the breach?
No. Revolut confirmed that its own systems and sensitive customer data, including passwords, passcodes, and ID documents, were not compromised. The breach occurred within DriveWealth’s network.
How can customers protect themselves after this breach?
Customers should remain vigilant against potential phishing attempts or fraudulent communications. Neither Revolut nor DriveWealth will ask for passcodes or instruct customers to transfer money. Monitoring account activity for unauthorized transactions is also recommended.
Related on LazyFounders
Sources
- The Next Web · 2026-09-24
DriveWealth breach exposes data of Revolut customers who traded US stocks
This story is an original summary and analysis written by LazyFounders from the reporting listed above. Facts are attributed to their original publishers; sections marked as analysis are LazyFounders's opinion. Where a source is in another language, facts were machine-translated and quotations are reported, not reproduced. Read the original coverage via the links.


