← Blog

DriveWealth Breach: Revolut, Stake & Hatch Data Exposed

Share on X

DriveWealth, the US brokerage infrastructure firm behind Revolut’s US stock trading and similar rails for Stake and Hatch, confirmed that unknown third parties gained unauthorized access to its network on September 4 and 5, 2026 through a social-engineering campaign. Partner apps emailed customers in late September. The Rhode Island notice lists about 62,000 affected residents in that state alone — a partial geography, not a global headcount.

This is a verified vendor incident, not a rumor from a leak site. DriveWealth said the intrusion was contained and that it found no unauthorized trades, transfers, or withdrawals. It reported the matter to Lithuania’s data protection authority. Revolut, Stake, and Hatch all say their own apps and internal systems were not breached; customer funds and investments were not moved by attackers.

What moved was personal and account-profile data that DriveWealth retained for regulatory reasons — including, for many Revolut users outside the US, historical records from an older broker model. That distinction matters when you decide whether you are in scope and what phishing looks like next.

What happened

DriveWealth’s customer notices describe a short window: unauthorized network access on September 4–5, 2026, attributed to social engineering by unknown actors. The company did not publish a detailed technical autopsy of which help desk, VPN, or identity workflow was abused — only that people, not a publicly named zero-day, opened the door.

Containment followed. DriveWealth told partners it stopped the access, investigated, and checked for misuse of brokerage accounts. Per the notices covered by The Next Web, Finance Magnates, and RTÉ, investigators did not detect unauthorized trading, transfers, or withdrawals.

Partner disclosure staggered across mid-to-late September. Stake warned Australian customers around September 21. Hatch followed around September 22 for New Zealand investors. Revolut and DriveWealth emailed affected Revolut customers on or about September 24, including Irish customers who once used the older US-stock arrangement. DriveWealth’s site notice also addresses Rhode Island residents under state breach law.

Revolut’s message to customers was blunt on one point: if you did not get the email, you are not in the notified set for this incident. Absence of mail is the practical filter while a global census remains unpublished.

What was exposed

Categories differ by partner, but the shared core is customer-profile data DriveWealth held after account opening or migration.

Common profile fields

Across notices, DriveWealth said the accessed historical personal data may include:

  • Names
  • Email addresses
  • Phone numbers
  • Postal addresses
  • Employment information
  • Country of citizenship
  • Age
  • Gender
  • Partial DriveWealth account numbers

That mix is enough for highly convincing BEC-style phishing and account-recovery social engineering. It is not, by itself, enough to log into a Revolut app or move money without additional secrets — and both DriveWealth and Revolut said passwords and payment credentials were outside the incident.

Stake and Hatch: portfolio and tax snapshots

For Stake and Hatch customers, partners disclosed additional investment-related fields held in DriveWealth’s environment.

Finance Magnates reported that Hatch-related records may include income and net-asset ranges, cash balances, and total portfolio values. Stake-related records may include W-8 or W-9 tax status, country of taxation, DriveWealth account numbers, and aggregate snapshots of portfolio value, cash, and buying power.

Those snapshots do not equal live trading access. They do tell a scammer roughly how valuable a target looks and which tax form language to parrot on a fake “DriveWealth compliance” call.

Rhode Island count — and what it is not

DriveWealth’s Rhode Island notice lists roughly 62,000 affected residents of that state. Treat that figure as a state-level disclosure under RI notification rules. It is not a published worldwide total for Revolut, Stake, Hatch, and every other DriveWealth-powered brand. Do not invent a global number from the RI filing alone.

What was not exposed

The notices draw a hard line on several high-value categories. DriveWealth said it had no reason to believe passwords or financial payment information — credit cards or bank account details — were involved. Revolut separately stated that no Revolut passwords, passcodes, card details, or ID documents were exposed in this incident, and that Revolut’s own systems and infrastructure were not accessed.

Revolut also told customers that an account cannot be accessed solely with the information involved, and that it had not detected unauthorized activity on notified accounts. DriveWealth’s parallel claim: no unauthorized trades, transfers, or withdrawals found in its investigation to date.

To be clear: “not used for trading” is not the same as “useless to criminals.” Contact data plus employment and citizenship still fuels spear phishing against the same people a week later.

How the attack worked

Public notices stop at “social engineering.” That usually means attackers manipulated a human process — help desk verification, vendor onboarding, MFA fatigue, or a fake urgent request — rather than announcing a brand-new remote code execution bug. DriveWealth has not published a play-by-play of the lure, the role that was spoofed, or which internal systems the session reached.

What we can say from the partner letters is the outcome: unauthorized access to historic personal (and, for some partners, investment-profile) data during a two-day window, then containment. There is no public claim in these sources that attackers issued trades from customer accounts or drained cash through DriveWealth’s clearing rails.

That pattern fits a data-exfiltration objective more than a market-manipulation smash-and-grab. The follow-on risk for customers is identity misuse and impersonation, not an automatic liquidation of US equities holdings.

Who is at risk

Revolut customers

Revolut customers used dual contracts historically: one with Revolut and one with DriveWealth when DriveWealth cleared US stock trades. Revolut later changed that broker model by market.

For the European Economic Area, Revolut stopped sending new customer data to DriveWealth in December 2023. EEA exposure in this incident is limited to historical records from before that change — data DriveWealth said it kept for legal and regulatory duties. UK and Australia saw the same model change completed by June 2025, per Revolut’s comments to Irish press. In the United States, customers who have used Revolut’s US stock trading remain in the partner relationship DriveWealth still supports for Revolut Securities / Revolut Wealth, and US trading customers are in the described scope.

Irish customers are among those who received notices, per RTÉ and The Next Web. Revolut’s practical rule remains: no email, not affected for this notification wave.

Stake and Hatch customers

Australian Stake users and New Zealand Hatch investors were warned because DriveWealth powers US trading behind those apps. Their notifications add portfolio and cash (and for Stake, tax-status) fields on top of the shared profile categories. Both platforms said the incident sat inside DriveWealth’s environment, not inside their consumer apps.

People who closed or migrated accounts

Finance Magnates noted that affected records include historical data retained after some customers closed or migrated accounts. Leaving an app does not erase a broker’s retention obligations. If you traded US stocks through these partners years ago under the DriveWealth arrangement, assume you may still be in the historic corpus even if you no longer see DriveWealth branding in the product UI.

Distinct from Revolut’s earlier September 2026 KYC incident

This DriveWealth event is the second Revolut-adjacent data story in September 2026 — and it is a different failure mode.

On or about September 12, Revolut confirmed a separate incident in which attackers used a compromised Italian government email account to submit fraudulent information requests, reportedly obtaining KYC documents and related records for about 680 customers. That case was about fake official demands hitting Revolut’s own process. Passports and KYC packages were the story.

The DriveWealth breach is a third-party broker intrusion via social engineering. Revolut’s systems were not the entry point. ID documents and Revolut passcodes were not in the DriveWealth data set described in the September 24 notices. Mixing the two incidents in a single panic email thread is exactly the confusion scammers want.

If you already hardened after the Italian-government-request story — new habits around government-looking emails, out-of-band verification — keep those habits. Add a second rule for this week: anyone claiming to be “DriveWealth security” or “Revolut brokerage compliance” and asking you to move money or read a passcode is lying.

Industry context: white-label brokers as concentrated risk

Fintech apps often outsource US clearing and custody plumbing to a small set of brokers. That is efficient for product teams and regulators who want a known broker-dealer on the hook. It also concentrates customer PII and account metadata in one place that many consumer brands share.

When DriveWealth is hit, Revolut, Stake, and Hatch all have to write letters even though none of them owned the compromised network path. Customers experience it as “my trading app leaked,” which is directionally true for their data and legally nuanced about whose SOC was breached.

Retention makes the blast radius sticky. EEA Revolut users who last touched the old model before December 2023 still appear because DriveWealth kept historic files. Supply-chain privacy risk is not only about live production syncs; it is about what the vendor was required — or chose — to keep.

Social engineering against financial infrastructure also sits in a broader 2026 pattern of human-targeted intrusions at large firms. The lesson for retail traders is narrower: if your brokerage relationship involves a named US clearing partner, that partner’s breach mail is as important as your app’s own security blog.

What the company and regulators said

DriveWealth framed the incident as unauthorized access to historic personal data held about people who had contracted with the firm, attributed to social engineering, contained, with no detected unauthorized brokerage activity of the trade/transfer/withdrawal kind. It reported to Lithuania’s DPA — reflecting where certain processing or entity obligations sit for parts of the business — and published state-facing notice language that includes the Rhode Island resident count.

Revolut emphasized three customer-facing points: its systems were not compromised; funds and investments are safe; and no Revolut passwords, passcodes, cards, or ID documents were exposed. It said it is in direct communication with DriveWealth on exact scope, followed DriveWealth’s customer contact with its own email, and told people that missing the email means they are outside the notified population.

Stake and Hatch disclosures, as summarized in trade press, mirrored the “incident at DriveWealth, not in our app” framing while expanding the data inventory for investment snapshots and, for Stake, tax-status fields.

Authoritative secondary coverage includes The Next Web’s report, Finance Magnates’ partner-by-partner breakdown, and RTÉ’s Ireland-focused summary. Our catalog record for this incident is at https://breachhistory.com/drivewealth/drivewealth-social-eng2026.

What you should do

If you received a DriveWealth, Revolut, Stake, or Hatch email about this incident — or you traded US stocks through those apps under the DriveWealth arrangement — work through the following.

  1. Confirm the notice in-app or on the official domain. Do not trust a forwarded PDF alone. Open the Revolut, Stake, or Hatch app from your home screen (not from a link in mail) and check security or inbox messages. DriveWealth’s cyber-response page is on its legal site; bookmark the domain yourself rather than clicking cold links.
  2. Assume phishing volume will rise. Attackers who have your name, email, phone, address, employer, citizenship, age, gender, and a partial account number can write extremely specific scripts. Expect messages about “forced account migration,” “DriveWealth KYC re-verification,” “tax form W-8 update,” or “unauthorized trade reversal.” Hang up and call only numbers published inside the app.
  3. Never move money because someone asks. Revolut explicitly said neither company will ask for your passcode or tell you to move money to another account as part of this response. Treat any urgency around transfers as fraud.
  4. Rotate passwords you reused. DriveWealth said passwords were not in this incident. Reused passwords from other breaches still matter. Change any credential that matches an email sitting in the exposed set, and turn on MFA everywhere that email is used for banking or brokerage.
  5. Watch for tax and wealth-targeted lures if you are Stake or Hatch. W-8/W-9 status, country of taxation, and portfolio cash snapshots make fake IRS/ATO/IRD or broker “withholding adjustment” emails more believable. Demand official portals; do not upload new tax forms to a stranger’s link.
  6. Freeze credit if your postal address and full identity stack are in the notice and you are in a jurisdiction where freezes are cheap. This incident’s published field list does not include Social Security numbers or passport images, unlike some other 2026 broker and PE social-engineering cases. Still, address-plus-phone packages feed synthetic identity and SIM-swap attempts. A credit freeze is low regret if you already live in the US notification footprint.
  7. Keep the September Revolut KYC incident separate in your head. If you were among the ~680 in the fake Italian government request case, your ID documents may already be burned from that event. This DriveWealth notice does not mean those documents leaked again through DriveWealth — and it does not mean they didn’t leak earlier elsewhere. Track which letter you actually received.
  8. Document what you received. Save the notification email headers and any case or reference numbers. If a later scam references a fake ticket ID, you will have the real one to compare.

Was I affected?

Start with the email rule Revolut published: no company notice, not in this notified set. Then apply market logic. EEA Revolut US-stock history before December 2023 can be in scope even if you later left DriveWealth’s live model. UK and Australia cutovers completed by June 2025. US Revolut stock-trading customers remain relevant to the ongoing DriveWealth relationship described in partner disclosures. Stake (AU) and Hatch (NZ) customers who got partner mail are in the investment-snapshot cohort.

Rhode Island residents should treat the ~62,000 figure as confirmation that DriveWealth’s US notification process is running for that state. Living outside Rhode Island does not prove you are safe; it only means that particular AG-facing number does not describe you.

Canonical record and sources

BreachHistory indexes this as a verified DriveWealth social-engineering incident affecting partner-app customer data retained at the broker. Canonical page: /drivewealth/drivewealth-social-eng2026 (https://breachhistory.com/drivewealth/drivewealth-social-eng2026).

Primary reporting used for this write-up:

If DriveWealth or partners later publish a global census, malware family, or fuller root-cause report, update your personal risk picture from those primary notices — not from forwarded screenshots on social media.