Fri. Sep 25th, 2026

DriveWealth Breach Notices Reach Revolut Users Years After Some Stopped Using the Broker

ByJohan Shamshad

September 24, 2026 #Revolut
RevolutRevolut

Historical Revolut Trading Data Was Exposed in DriveWealth Breach

Revolut customers are receiving data-breach notifications from DriveWealth after attackers accessed historical customer information at the U.S. brokerage infrastructure provider, with some affected users saying the warnings were filtered into spam folders or sent to email accounts they rarely use.

DriveWealth said unauthorized access to its network occurred between September 4 and September 5, 2026, exposing personal information contained in certain systems. The company said its production brokerage and trading systems were not affected and that it has identified no unauthorized trades, transfers, withdrawals, ACAT requests or changes to customer balances or positions.

For affected Revolut users, potentially exposed records may include names, email addresses, phone numbers, postal addresses, employment information, citizenship, age, gender and partial DriveWealth account numbers.

Revolut said passwords, passcodes, card information and its own systems were not compromised. DriveWealth separately said it has no reason to believe financial payment information such as bank-account or credit-card details was exposed.

The DriveWealth cyber-response notice says the company has not identified identity fraud or misuse of customer information resulting directly from the incident and that outside cybersecurity specialists independently validated its finding that no persistent threat remained in its systems.

Reports based on notices sent through DriveWealth’s brokerage partners have attributed the initial access to a social-engineering or employee-phishing campaign. DriveWealth’s public cyber-response page itself describes the incident as unauthorized network access but does not provide a detailed attack chain.

The breach is broader than Revolut. DriveWealth provides brokerage infrastructure to multiple investing platforms, and customers of firms including New Zealand investment platform Hatch have also been notified that their information may have been accessed. The specific categories of compromised information differ between partner firms.

Some European Users Had Not Dealt With DriveWealth for Years

The Revolut connection is particularly unusual because some of the affected information is historical.

DriveWealth previously provided the underlying U.S. brokerage infrastructure used when Revolut customers in several international markets opened accounts to trade American stocks. Revolut later changed that structure.

For customers in the UK, European Economic Area and Australia, Revolut said it migrated away from the previous model between December 2023 and June 2025, depending on the market. After those migrations, individual customer information in the affected markets was no longer being provided to DriveWealth under the old arrangement.

That means someone can receive a breach notification in 2026 despite no longer thinking of DriveWealth as part of their current Revolut relationship.

The situation is different in the United States, where DriveWealth remains part of Revolut’s brokerage infrastructure. Revolut’s current U.S. documentation identifies DriveWealth as the clearing broker for Revolut Securities and Revolut Wealth.

The historical relationship also helps explain why some customers say they did not immediately recognize the sender. Revolut presented the investing experience through its own application, while DriveWealth operated behind the scenes as brokerage infrastructure.

That kind of layered financial architecture is increasingly common. A customer may see one fintech brand while brokerage, payments, custody, identity verification and other functions are supplied by separate companies underneath it. A recent Revolut account-access incident similarly illustrated how the customer-facing application can represent only one layer of a considerably larger financial technology stack.

Users Say DriveWealth’s Warning Was Easy to Miss

The notification process has now created a second issue.

Multiple Revolut users discussing the incident on September 24 said DriveWealth’s original email was automatically placed in Gmail spam folders. Several said they only discovered the notice after other users told them to check spam, while some reported receiving Revolut’s follow-up message normally even though the earlier DriveWealth email had been filtered.

Other users said the notice reached an older email address associated with their historical brokerage account rather than an address they regularly monitor today.

Those reports come from customers and have not been quantified or confirmed by DriveWealth. There is no evidence that every notification suffered from the same delivery problem.

Still, they expose a difficult weakness in incident response: a legally important notification is only useful if the former customer recognizes the company sending it and actually sees the message.

That challenge becomes larger when a financial product relies on an invisible third party. Some users said they did not initially know what DriveWealth was despite having previously opened a U.S. stock account through Revolut.

A legitimate security email from an unfamiliar financial company arriving unexpectedly — and in some cases landing in spam — has many of the characteristics consumers are normally told to distrust.

DriveWealth Has Not Disclosed How Many Revolut Customers Were Affected

Several important numbers remain missing.

Neither DriveWealth nor Revolut has publicly disclosed the total number of Revolut-linked customers whose records were accessed. Revolut has said affected customers are being contacted directly and that people who did not receive its notification are not considered affected.

DriveWealth has also not published a breach-specific explanation of exactly how long each category of customer data had been retained.

Its current privacy policy says personal information is retained for as long as necessary for the purpose for which it was collected, including legal, accounting, reporting, compliance and litigation requirements. Separate DriveWealth documentation says brokerage-account documents are generally made available for at least seven years.

That does not establish that every piece of data exposed in September had a seven-year retention period. Different brokerage records can be subject to different regulatory obligations.

But it does explain why ending a fintech partnership does not necessarily mean the underlying broker immediately deletes the customer record.

The Real Exposure Is the Data That Remains After the Product Relationship Ends

This is where the breach becomes more interesting than a conventional cybersecurity story.

No customer funds are known to have been stolen. DriveWealth says trading systems kept operating. Revolut says its own infrastructure was untouched.

Yet users who may not have thought about DriveWealth for years are discovering that the broker still possessed information detailed enough to create useful phishing profiles.

A name and email address are relatively ordinary breach material. Combine them with a home address, employer, citizenship, age and knowledge that the person once held a brokerage account, and an attacker has something much more convincing.

The biggest near-term risk may therefore be impersonation rather than direct account theft.

A criminal could pretend to be DriveWealth, Revolut, a regulator or another financial institution and approach someone with accurate historical information before asking for a password, payment or identity document.

This is the same secondary-risk problem that appears after other financial security events. Following the recent Bitget security breach, the immediate asset loss was only one part of the security problem; users also had to distinguish genuine company communications from opportunistic scams exploiting the incident.

Third-Party Infrastructure Creates a Long Tail of Risk

Fintech companies sell simplicity.

The user opens one app and sees banking, cards, stock trading, crypto, transfers and savings in one place.

Behind that interface can sit a surprisingly long list of outside companies.

That architecture is efficient. A fintech does not need to build a U.S. broker-dealer, payment processor, card network and fraud engine from scratch.

But it also means the customer’s security exposure does not necessarily end at the company whose logo appears on the screen.

The same issue has appeared elsewhere in financial infrastructure. When Checkout.com detected a wave of fraudulent Polymarket deposits, the payment processor became a critical security layer in a product customers experienced as Polymarket. The dependency only becomes obvious when something goes wrong.

DriveWealth demonstrates the data version of that problem.

Revolut could change its brokerage model, but historical records held by the former infrastructure provider did not simply disappear with the migration.

The Notification Problem Deserves Almost as Much Attention as the Breach

The spam-folder reports sound minor compared with unauthorized network access.

They are not entirely minor.

Cybersecurity notifications arrive precisely when customers need to become more suspicious of email. If the genuine warning comes from a company they barely remember, reaches an address they rarely use or is classified as spam, the customer may never see it.

Worse, the first message they do see could be the phishing attempt that follows.

That makes partner coordination important. Revolut’s decision to send its own follow-up notification gives customers a second channel for confirming that the DriveWealth email is legitimate.

Financial companies responding to breaches increasingly need to think beyond whether a notification was technically sent. They need to know whether former customers can reasonably recognize and receive it.

Other security incidents have shown how rapidly user confidence can depend on communication quality. Blink’s response to a recent custodial-account breach centered heavily on identifying exactly which users and systems were affected and explaining what remained safe.

DriveWealth now has a similar transparency problem, even though customer assets were apparently untouched.

The next useful disclosures are straightforward: how many people were affected, which partner populations were involved, what exact records were exfiltrated for each group, how long those records had been held and whether notification contact details were validated before the warnings went out.

Until those questions are answered, the DriveWealth incident is a reminder that leaving a financial product does not necessarily mean leaving its data ecosystem.

The brokerage account can disappear from the app long before the brokerage record disappears from the infrastructure underneath it.

Financial Markets Analyst and Journalist at  |  More Posts

Johan Shamshad is a financial markets writer at Dave Finances covering cryptocurrencies, trading platforms, brokers, fintech, financial regulation, and developments across global markets. He previously worked at Gulf News, adding newsroom experience to his coverage of fast-moving financial and digital-asset markets.

His work focuses on identifying market-moving events, company developments, regulatory changes, product launches, and shifts in trading and financial infrastructure.

Johan contributes news and analysis designed to help readers understand not only what happened, but why a development matters and how it may affect the wider financial landscape.

Leave a Reply

Your email address will not be published. Required fields are marked *