Another week, another data breach for Revolut customers
DriveWealth coughs up historic customer info after attackers socially engineer their way inside
Revolut customers have been caught up in a second data breach this month after attackers socially engineered their way into US brokerage DriveWealth and stole historic personal information.
DriveWealth provides execution and clearing services for investment firms and previously held brokerage accounts directly for Revolut customers trading US stocks. It said the unauthorized access occurred on September 4 and 5.
In an email sent to affected customers and seen by The Register, the broker blamed a "sophisticated social engineering campaign" carried out by unknown third parties.
REG AD
The intruders exfiltrated data retained from the period when those customers held accounts directly with DriveWealth. The broker said regulatory requirements obliged it to keep the records.
REG AD
The potentially exposed haul includes names, email addresses, phone numbers, postal addresses, employment information, country of citizenship, age, gender, and partial DriveWealth account numbers.
DriveWealth said it had no reason to believe any other personal information was affected. Passwords and payment information, including credit card and bank account details, were not compromised.
Even so, the exposed details would provide ample material for a convincing phishing message. DriveWealth warned customers that the stolen information could potentially be used for identity fraud, impersonation, further social engineering, or unsolicited contact from strangers.
Revolut customers are among those affected, with the records dating from its previous arrangement with DriveWealth, the company confirmed to the Irish Examiner.
Revolut said its systems and infrastructure were not compromised, and that customer funds and investments remained safe. No Revolut passwords, passcodes, card details, or identity documents were exposed.
The data is a hangover from Revolut's former arrangement for customers trading US stocks. The fintech moved customers in the UK, EEA, and Australia away from that arrangement between December 2023 and June 2025, with the timing varying by market. Their personal details were no longer shared with DriveWealth after the respective migrations.
DriveWealth contacted affected customers directly, while Revolut sent its own notifications. Neither company has disclosed how many Revolut customers were affected, and both failed to answer The Register's questions.
The breach comes at an awkward time for Revolut. On September 14, the fintech admitted it had handed sensitive customer information to criminals after they submitted fraudulent information requests using an email domain belonging to a legitimate government agency.
REG AD
That separate incident potentially exposed more sensitive information, including passports, driver's licenses, verification selfies, dates of birth, addresses, phone numbers, email addresses, and financial and transaction data.
Revolut said at the time that it had fallen victim to a "sophisticated external impersonation scam" and that only a limited number of customers were affected.
Two different incidents, two different sets of attackers, and two different routes to customer data. For Revolut customers, September has provided more breach notifications than anyone would want from their banking app. ®
KioskNews shows a cleaned-up reading view extracted from the publisher’s page — the original always lives on their site, not ours.