Smartphone displaying the Revolut name on screen while resting on a wooden surface.
SECURITY

Revolut Customers Hit by Second Data Incident in September After DriveWealth Breach

Image credit: Unsplash

Revolut customers have been affected by a second data incident in September after unauthorized parties accessed systems at U.S. broker DriveWealth. Revolut said its own infrastructure was not compromised and customer funds and investments remain safe. The latest incident involves historical information held by DriveWealth for customers who used Revolut’s U.S. stock trading services.

DriveWealth Network Accessed on Sept. 4 and 5

DriveWealth said unauthorized access to its network occurred on Sept. 4 and Sept. 5 following a social-engineering campaign. The broker found that personal information was taken from certain systems. Potentially affected records include names, email addresses, phone numbers, postal addresses and employment information.

Citizenship, age, gender, and partial DriveWealth account numbers may also have been exposed. DriveWealth said it has no reason to believe passwords, credit card details or bank-account information were compromised.

Revolut Says Its Systems Were Not Breached

Revolut said no passwords, passcodes, card details or identity documents stored within its own systems were exposed. For customers in the UK, European Economic Area and Australia, the affected information relates to historical records from before Revolut migrated those stock-trading services away from its previous DriveWealth arrangement.

Revolut migrated those customers away from the previous DriveWealth setup at different times between December 2023 and June 2025, depending on the market. Affected customers have been contacted directly by DriveWealth, with Revolut sending additional notifications.

Separate September Incident Exposed Identity Data

The DriveWealth breach is separate from another incident disclosed by Revolut earlier this month. In that case, an unauthorized party used an email account on a legitimate government-agency domain to submit fraudulent requests for customer information. Revolut subsequently disclosed data including identity and contact information to the requester.

Potentially exposed records included dates of birth, addresses, identity documents and, for some customers, account statements and transaction histories. Revolut said that incident also did not involve unauthorized access to its systems or customer funds. Neither Revolut nor DriveWealth has publicly disclosed the total number of Revolut customers affected by the latest DriveWealth breach.

More For You

Explore More News