Revolut Customers Affected by Data Breach at DriveWealth
DriveWealth reports unauthorized access to customer data following a social engineering attack.
By The Register
Revolut customers have been impacted by a data breach involving DriveWealth, a US brokerage that previously managed accounts for Revolut's US stock trading service. Unauthorized access to DriveWealth's systems occurred on 4 and 5 September 2026, attributed to a sophisticated social engineering campaign by unknown attackers.
In communications with affected customers, DriveWealth confirmed that the breach involved historic personal information retained from the period when customers held accounts directly with them. The data potentially exposed includes names, email addresses, phone numbers, postal addresses, employment information, country of citizenship, age, gender, and partial account numbers. However, DriveWealth stated that passwords and payment information were not compromised.
Revolut has assured its customers that its own systems and infrastructure were not breached, and that customer funds and investments remain secure. The fintech clarified that no Revolut passwords, passcodes, card details, or identity documents were exposed during this incident.
The breach is particularly concerning as it follows a separate incident earlier in September, where Revolut admitted to inadvertently providing sensitive customer information to criminals who posed as representatives of a legitimate government agency. This earlier breach potentially exposed more sensitive data, including identification documents and financial information.
Both DriveWealth and Revolut have reached out to affected customers, but neither company has disclosed the number of Revolut customers impacted by this latest breach. The incident has raised alarms among users, with September proving to be a challenging month for Revolut regarding data security.