Revolut Customers Hit by Second Data Breach Tied to DriveWealth

1 hour ago 2 sources neutral

Key takeaways:

  • Repeated vendor breaches expose systemic third-party risk, pressuring fintech trust more than crypto-native security.
  • Investors should monitor phishing and account anomalies, since stolen profile data enables targeted social engineering.
  • For crypto investors, this reinforces self-custody appeal amid rising data-breach risks across centralized platforms.

Digital bank Revolut confirmed a second customer data incident this month, this time originating at US brokerage partner DriveWealth rather than Revolut’s own systems. Unauthorized access to DriveWealth’s network took place on September 4 and 5, 2026, through a social engineering attack.

DriveWealth provides execution and clearing services for Revolut users who opted into US stock trading. The exposed records are older customer-profile data and include names, email addresses, phone numbers, postal addresses, employment information, country of citizenship, age, gender, and partial DriveWealth account numbers. Revolut and DriveWealth said passwords, payment card numbers, bank account details, Revolut passcodes, card details, and identity documents were not part of the material taken. Customer funds and investments remain safe, and Revolut’s own systems were not accessed.

The scope varies by region. In the UK, EEA, and Australia, Revolut changed its trading model between December 2023 and June 2025 and stopped sending individual customer details to DriveWealth, meaning only historical records are involved. EEA customers, including Ireland, have not had data shared with DriveWealth since December 2023. In the US, the issue relates to customers who used the US share trading feature. Customers who did not receive a direct email from DriveWealth are generally not affected, though some messages landed in spam folders.

Other platforms relying on DriveWealth, including Stake and Hatch, issued their own notices. The breach is separate from an earlier September Revolut incident in which a compromised government email domain led to release of sensitive records, including identity documents and transaction histories, for roughly 680 customers.

Revolut is advising affected users to watch for phishing and social engineering attempts, check official app communications, and monitor account activity. DriveWealth said production trading platforms were not disrupted and no unauthorized trades, transfers, withdrawals, or account-balance changes were found.

Disclaimer

The content on this website is provided for information purposes only and does not constitute investment advice, an offer, or professional consultation. Crypto assets are high-risk and volatile — you may lose all funds. Some materials may include summaries and links to third-party sources; we are not responsible for their content or accuracy. Any decisions you make are at your own risk. Coinalertnews recommends independently verifying information and consulting with a professional before making any financial decisions based on this content.