← DriveWealth

2026 DriveWealth — social-engineering access Sep 4–5; Revolut/Stake/Hatch customer data

2026 62.0K records affected Share on X

Data compromised

Per DriveWealth/Revolut notices: names, emails, phones, postal addresses, employment details, citizenship, age, gender, partial DriveWealth account numbers. Passwords and payment card/bank details stated not involved. Stake/Hatch: also aggregate portfolio/cash snapshots and some tax-status fields. Rhode Island notice cites ~62,000 affected RI residents (partial geography; global census unpublished). Reported to Lithuanian DPA.

Technical writeup

Verified DriveWealth partner notices and Revolut/Stake/Hatch customer emails — September 2026. DriveWealth said unauthorized parties accessed its network September 4–5 via social engineering; contained with no detected unauthorized trades/transfers/withdrawals. Revolut: own systems not compromised; EEA exposure limited to historical records from before Dec 2023 broker-model change (UK/AU by June 2025); U.S. stock-trading customers may be in scope; no Revolut passwords/passcodes/cards/ID docs exposed. Stake and Hatch disclosed additional investment-profile fields (portfolio/cash snapshots; Stake W-8/W-9 tax status). DriveWealth Rhode Island notice lists ~62,000 affected RI residents — used as best published partial count; worldwide total unpublished. Distinct from Revolut’s earlier September fake-government-request incident. recordsAffected 62000 (RI-reported subset); companyConfirmed true.

Root cause

Unauthorized network access on September 4–5, 2026 via social-engineering campaign (DriveWealth / partner notices)

References