Skip to content

Invest1 publisher3 min readPublished

DriveWealth's breach reached Revolut customer records up to 33 months after Revolut stopped sending them

DriveWealth's September breach reached records on Revolut's UK, EEA and Australian customers that Revolut stopped sending 15 to 33 months earlier. Revolut's new trading model cut off fresh transfers but left older copies with the broker, where an intrusion could still reach them.

The Investor · Invest desk

Photograph accompanying DriveWealth's breach reached Revolut customer records up to 33 months after Revolut stopped sending them
Photo: irishtimes.com

What happened

  • DriveWealth said intruders accessed its network on 4 and 5 September 2026, and investigators found that some stored personal information was taken.
  • Revolut says the records involved from the UK, EEA and Australia are older ones, from before it stopped sending individual customer details to DriveWealth.
  • The data is mainly names, emails, phone numbers, postal addresses and employment details, possibly with citizenship, age, gender and a partial account number.
  • DriveWealth found no unauthorized trades, transfers, withdrawals or balance changes, and says its production trading platforms were not disrupted.
  • Stake and Hatch, two other platforms that rely on DriveWealth, have issued notices of their own.

Compiled by The InvestorSomething wrong?How this is made

Why it matters

  • constraint A fintech that changes its broker setup limits new exposure only; records the broker already holds stay within reach of its next breach until they are deleted.
  • exposure Revolut customers onboarded in the UK, EEA and Australia before the switch face impersonation risk from profiles the broker kept 15 to 33 months after transfers stopped.
  • exposure One broker's retention policy sets the breach exposure for customers of every introducing app built on it, whatever each app's own security.
  • decision Fintechs moving off a shared broker now have a concrete case for writing deletion of past customer records into the exit terms.

Revolut used DriveWealth to support US stock trading for its customers [4]. It changed its trading model in the UK, EEA and Australia between December 2023 and June 2025, depending on the market [5]. The intrusion came in September 2026 [1]. From June 2025 to September 2026 is 15 months; from December 2023 it is 33 [1]. So the newest records from those markets had been on the broker's systems for at least 15 months when the network was entered, and in the first market to switch, for almost three years [1].

Revolut says accounts opened after the change should not be in the exposed set [7], so the switch capped how many customers a DriveWealth failure could reach. It did not shrink the group already on file. Neither company has published a count of affected Revolut users [8], and Crowdfund Insider's report does not say whether DriveWealth was required to keep the older records or whether Revolut asked for them to be deleted.

The evidence fits more than one reading, and each puts the fault in a different place. If a record-keeping duty kept those files at DriveWealth, the model change was the only lever Revolut held, and the question goes to whoever sets brokers' retention rules. Should it emerge that Revolut could have demanded deletion and did not, the gap is in how fintechs leave a vendor. And if most notified customers turn out to be US users of U.S. share trading [9], the old-records point shrinks to a footnote.

I think the evidence supports the narrow version of the retention case. A change of trading setup limits who can be exposed next and leaves the copies a vendor already holds in place. A count showing few non-US records would weaken that. A disclosure that the files were kept under a legal mandate would move the fault from the vendor to the regulation.

The money in the accounts is the part the companies can vouch for. Revolut says its own systems were not accessed and that customer funds and investments remain safe [14]. Contact details and employment information can be used to craft convincing phishing or impersonation attempts, according to Crowdfund Insider [13]. The legitimate notices also arrive by email, and some of DriveWealth's appear to have landed in spam folders [15]. Customers who received nothing are generally being told they are not in the notified group [15]. DriveWealth has recommended staying alert for unusual financial activity and, where relevant, considering credit monitoring or fraud alerts [16].

Revolut's earlier September incident, in which fraudulent requests from a compromised government email domain led it to release identity documents and transaction histories for a limited group [12], happened at Revolut itself. This one sits with a broker that several consumer apps rely on [11]. DriveWealth's retention practice therefore sets the exposure for their customers too. Revolut says it is still working with DriveWealth to pin down the exact scope [17].

What to watch

  • A count of affected Revolut users split between US share-trading customers and older UK, EEA and Australian records.
  • Any statement from DriveWealth or Revolut on why pre-switch records were still held, and whether deletion was requested or legally barred.
  • Notices from other DriveWealth platforms stating how old their exposed customer records are.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories