DriveWealth Social Engineering Attack Exposes Personal Data of Revolut, Stake and Hatch Customers

Fintech News

DriveWealth Social Engineering Attack Exposes Personal Data of Revolut, Stake and Hatch Customers #

A social engineering attack on US brokerage infrastructure provider DriveWealth exposed personal data belonging to customers of Revolut, Australian broker Stake and New Zealand platform Hatch. It is the second data security incident linked to Revolut in a single month.

DriveWealth confirmed that unknown third parties accessed its network on 4 and 5 September 2026 through a social engineering campaign. The company told affected partners the incident has been contained and that investigators found no evidence of unauthorised trades, transfers or withdrawals on any customer account.

The categories of data exposed varied by platform. For Revolut customers, information potentially at risk includes names, email addresses, phone numbers, postal addresses, employment details and part of a DriveWealth account number. Revolut said its own systems were not affected and that no passwords, passcodes, card details or identity documents were compromised. Stake customers may additionally have had portfolio values and cash balances accessed, along with W-8 or W-9 US tax form status. Hatch issued a similar warning, adding that dates of birth, IRD numbers and Hatch login credentials were not among the exposed fields.

Revolut customers in the European Economic Area were affected only because DriveWealth retained historical data for legal and regulatory purposes. The neobank migrated EEA users off the DriveWealth arrangement in December 2023, so only records predating that cutoff could have been involved. The same transition was completed in the UK and Australia at around the same time. DriveWealth continues to act as the clearing broker for Revolut Securities and Revolut Wealth in other markets.

DriveWealth’s public breach notification listed roughly 62,000 affected residents of the state of Rhode Island. The company has established a dedicated response line and recommends credit monitoring for any individual whose notice references a US Social Security number. All three platforms warned customers that exposed contact and account data could be used in follow-on phishing or impersonation attempts, and urged users to remain alert to unsolicited messages.

The DriveWealth incident is unrelated to a separate Revolut breach disclosed on 12 September, in which attackers used a compromised Italian government email account to submit fraudulent data requests to the company, reportedly obtaining KYC documents and transaction records for around 680 high-net-worth customers. The two incidents have drawn scrutiny of the $115 billion-valued fintech’s data-handling practices. Revolut is also pursuing a dual stock market listing in London and New York.

Source: Finance Magnates