2026 DriveWealth — social-engineering access Sep 4–5; Revolut/Stake/Hatch customer data
Data compromised
Per DriveWealth/Revolut notices: names, emails, phones, postal addresses, employment details, citizenship, age, gender, partial DriveWealth account numbers. Passwords and payment card/bank details stated not involved. Stake/Hatch: also aggregate portfolio/cash snapshots and some tax-status fields. Rhode Island notice cites ~62,000 affected RI residents (partial geography; global census unpublished). Reported to Lithuanian DPA.
Technical writeup
Verified DriveWealth partner notices and Revolut/Stake/Hatch customer emails — September 2026. DriveWealth said unauthorized parties accessed its network September 4–5 via social engineering; contained with no detected unauthorized trades/transfers/withdrawals. Revolut: own systems not compromised; EEA exposure limited to historical records from before Dec 2023 broker-model change (UK/AU by June 2025); U.S. stock-trading customers may be in scope; no Revolut passwords/passcodes/cards/ID docs exposed. Stake and Hatch disclosed additional investment-profile fields (portfolio/cash snapshots; Stake W-8/W-9 tax status). DriveWealth Rhode Island notice lists ~62,000 affected RI residents — used as best published partial count; worldwide total unpublished. Distinct from Revolut’s earlier September fake-government-request incident. recordsAffected 62000 (RI-reported subset); companyConfirmed true.
Root cause
Unauthorized network access on September 4–5, 2026 via social-engineering campaign (DriveWealth / partner notices)
References
- https://thenextweb.com/news/drivewealth-breach-revolut-customers-us-stocks
- https://www.financemagnates.com/fintech/drivewealth-security-incident-exposes-revolut-stake-and-hatch-customer-data/
- https://www.rte.ie/news/business/2026/0924/1592820-revolut-data/
- https://protos.com/revolut-reveals-customer-data-breached-twice-this-month/