Invest2 publishers2 min readPublished
DriveWealth's September intrusion exposes customer data at Stake in Australia and Hatch in New Zealand
DriveWealth's systems were accessed on 4 and 5 September, exposing contact details and account balances of Stake and Hatch customers, the brokers say. Stake says DriveWealth serves several Australian platforms, so one intrusion reaches customers of competing apps.
The Investor · Invest desk

What happened
- DriveWealth provides execution, custody and clearing for Stake Wall St and holds the personal details Stake passes to it when a customer opens an account.
- DriveWealth investigated with independent cybersecurity experts, found no ongoing threat and has strengthened its controls, according to Hatch.
- Stake says login credentials, tax file numbers, bank details and identity documents were not accessed, and Hatch gives a similar list covering IRD numbers.
- The exposed fields differ by broker: Stake lists tax status, account numbers and buying power, while Hatch lists income and net asset ranges.
- Stake notified privacy regulators in Australia and New Zealand, and Hatch told New Zealand Police and the National Cyber Security Centre.
Compiled by The InvestorSomething wrong?How this is made
Why it matters
- constraint A customer who closes a Stake or Hatch account leaves the record behind at DriveWealth, where US retention rules keep it within reach of any later intrusion.
- exposure With contact details and balances in the same records, scammers can pick out the customers holding the most money, and that risk lasts after DriveWealth's fixes.
- decision What an app sends DriveWealth at onboarding appears to set what its customers can lose, so how much data to share is a choice each local broker controls.
- cost Stake is paying outside legal and cyber security advisers to handle an incident that happened inside a partner's environment.
Both brokers say the breach happened outside their own systems. Stake says the incident took place within DriveWealth's environment and that its systems, app and website were not affected [6]. Hatch says its systems were not accessed [4]. Trading carried on throughout. Stake says customers can trade, deposit and withdraw as normal [7], and Hatch passes on DriveWealth's confidence that no unauthorised transactions were made and holdings were not affected [8].
So the shared backend failed at the customer file. Contact details sitting next to a cash balance tell a fraudster which customers to call first. Hatch wrote that the information "could be used to make fraudulent emails, text messages or phone calls more convincing" [13]. When it answers the insurance question, Hatch points to SIPC and FDIC cover for investments and cash held with DriveWealth [20], and those are the assets the notices say came through intact [8].
The local brand owns the customer relationship and files the regulatory notices, but the investigation belongs to DriveWealth. Stake's page is dated 21 September [5], 16 days after the last day of access Hatch reports [22]. It says DriveWealth's investigation is continuing and that "we are working with them to obtain answers to key questions on behalf of our customers" [18]. Neither broker gives a count of affected customers. Stake says only that not every customer is affected and that it cannot give individual detail on its page [21].
From here the story can go one of three ways. If Stake's monitoring for misuse stays quiet [19] and the field lists hold, the damage stops at what the notices already list. If scams built on those records start to succeed, the cost arrives later and lands on customers of several apps at once [1]. None of that cost would show up as an unauthorised trade. The third route is DriveWealth's continuing investigation widening the lists [18].
I think the first path is the likelier one on the evidence so far, since Stake is watching for misuse and has not reported any [19]. The case against is that a contact list sorted by balance stays valuable to whoever holds it long after the intrusion is closed. Stake has said it will post on its page if its position on misuse changes [19], and such a post would count against this view.
What to watch
- A Stake update reporting misuse of the exposed data, which it has said it will post if its position changes.
- Notices from the other Australian platforms that use DriveWealth, and whether their field lists match Stake's or Hatch's.
- Any view from the Australian Information Commissioner or New Zealand's Privacy Commissioner on local brokers' duties for data held by an offshore partner.