Intruders used social engineering to gain unauthorized access to US brokerage DriveWealth on September 4 and 5, stealing retained personal data from former direct brokerage accounts held by Revolut customers trading US stocks. It is the second breach notification affecting Revolut customers in September, following a separate September 14 impersonation incident. Password and payment data was not compromised in the DriveWealth event, but names, contact details, and partial account numbers were exposed and could fuel phishing and identity fraud.
How the access happened
DriveWealth provides execution and clearing services for investment firms and previously held brokerage accounts directly for Revolut customers trading US stocks. According to customer notifications, unknown third parties ran what the broker described as a "sophisticated social engineering campaign" to get inside.
The resulting unauthorized access took place on September 4 and 5. The intruders exfiltrated records retained from the period when affected individuals held accounts directly with DriveWealth, records the broker said it was obliged to keep for regulatory requirements.
Revolut customers are among those affected, with the records dating from its previous arrangement with DriveWealth. Revolut stated its own systems and infrastructure were not compromised, and that customer funds and investments remained safe.
What was taken and what was not
DriveWealth said the potentially exposed data includes:
- names
- email addresses
- phone numbers
- postal addresses
- employment information
- country of citizenship
- age
- gender
- partial DriveWealth account numbers
The broker said it had no reason to believe any other personal information was affected. Passwords and payment information, including credit card and bank account details, were not compromised.
Revolut added that no Revolut passwords, passcodes, card details, or identity documents were exposed in this event.
Legacy data link
The exposure stems from Revolut's former arrangement for customers trading US stocks. The fintech moved customers in the UK, EEA, and Australia away from that arrangement between December 2023 and June 2025, with the timing varying by market. Their personal details were no longer shared with DriveWealth after the respective migrations.
DriveWealth contacted affected customers directly, while Revolut sent its own notifications. Neither company has disclosed how many Revolut customers were affected.
Second September incident
On September 14, Revolut separately disclosed that it had handed sensitive customer information to criminals after they submitted fraudulent information requests using an email domain belonging to a legitimate government agency. Revolut described that event as a "sophisticated external impersonation scam" affecting only a limited number of customers.
That separate incident potentially exposed more sensitive categories, including passports, driver's licenses, verification selfies, dates of birth, addresses, phone numbers, email addresses, and financial and transaction data.
Detection and mitigation
DriveWealth warned customers that the stolen information could potentially be used for identity fraud, impersonation, further social engineering, or unsolicited contact from strangers.
Affected users should therefore treat unsolicited messages referencing historic DriveWealth account details, employment information, or Revolut US-stock trading as high-risk for phishing, and verify any contact claiming to be from either company through known official channels. No password or payment-card rotation was indicated as required by either company for this specific event, consistent with their statements that those data types were not compromised.
Technical background — general pattern, not this incident
Social-engineering-led brokerage intrusions typically target help-desk, vendor-access, or identity-verification workflows rather than software flaws: an attacker persuades staff to reset credentials, approve access, or disclose internal processes, then uses that foothold to query retained customer stores. Historic retained records remain attractive because even partial account numbers combined with names, addresses, and phone numbers allow convincing pretexting for follow-on fraud.