DriveWealth, LLC is a New York broker-dealer that provides embedded US brokerage, custody and clearing for fintech apps including Revolut, Stake and Hatch. It has confirmed that an unauthorized party accessed its network on September 4 and 5, 2026 and took personal data. A breach report filed with the Texas Attorney General's Office on October 2 says more than 2.5 million Texans were affected and that the exposed data included names, Social Security numbers and financial information. That figure comes from Hoodline's coverage of the filing, which cites the Houston Chronicle. No other source we reviewed gives a total victim count. Through late September, outlets covering the international impact said neither DriveWealth nor its fintech partners had disclosed one (Cyber Breaches). DriveWealth's own notice to the California Attorney General confirms the intrusion window and that data was taken, but the version we reviewed redacts the list of affected data types.
What Happened
DriveWealth's customer notice, filed with the California AG and the strongest source here, gives this timeline:
- September 4–5, 2026: An unauthorized party accessed DriveWealth's network.
- September 5, 2026: DriveWealth says it contained the compromise, working with outside cybersecurity firms. It reports no further unauthorized activity since.
- September 24, 2026: DriveWealth, Revolut, Stake and Hatch began notifying affected customers. Coverage of this wave focused on customers in Ireland, the UK, the EEA, Australia and New Zealand (The Next Web, Irish Times, Finance Magnates).
- September 28, 2026: DriveWealth finished its investigation and document review.
- September 30, 2026: DriveWealth filed a notice with the California AG (Beinsure).
- October 2, 2026: DriveWealth filed its report with the Texas AG, listing 2.5M+ affected Texans (Hoodline, citing the Houston Chronicle).
DriveWealth's cyber-response page, as summarized by Delist.ai and Hoodline, says its production brokerage and trading systems and its client-facing platform were not affected. It says it found no unauthorized trades, transfers, withdrawals, ACAT requests or changes to balances or positions. The company says it is not aware of any identity fraud resulting from the incident. Revolut says its own systems were not accessed (Irish Times, Beinsure).
The breach also reached people who had already left. Many affected records belong to customers who closed their accounts or were moved off DriveWealth. Revolut stopped sending EEA customer data to DriveWealth in December 2023 and finished the same change in the UK and Australia by June 2025. DriveWealth says it kept the older records because of regulatory record-retention rules (The Next Web, Cyber Breaches).
What Was Taken
Sources describe the stolen data differently, and the difference seems to depend on which group of customers is being described:
- Texas filing (US customers): Names, Social Security numbers and financial information, per Hoodline's reporting on the AG filing. We could not independently check the filing, so treat the SSN exposure as reported, not confirmed by a primary source.
- Notices to Revolut customers (mostly international, historical records): Names, email addresses, phone numbers, postal addresses, employment details, country of citizenship, age, gender and partial DriveWealth account numbers (The Next Web, Irish Times, Beinsure). These notices say passwords, card details, bank account numbers and ID documents were not exposed. None of them mention SSNs.
- Stake and Hatch customers: Some records also included total portfolio values, cash balances and investor-profile information (Finance Magnates).
- Primary notice: DriveWealth's California AG letter confirms data was taken, but the list of data types is redacted. It reads as a template that changes per recipient.
The most likely explanation is that US customers, who gave DriveWealth tax and KYC data, lost more sensitive information than international customers whose old profile records were held. The sources do not say this outright. On counts, the only reported number is 2.5M+ for Texas alone. No source gives a national or worldwide total, and it is likely higher.
Why It Matters
- Embedded-finance concentration risk: One infrastructure provider sits behind several consumer brands. Customers of Revolut, Stake and Hatch were exposed by a company many of them had never heard of. Cyber Breaches calls this a recurring structural weakness of the embedded-finance model.
- Required retention means stored data: Regulators require broker-dealers to keep records for years. Every former customer's data stays in storage that can be stolen long after the relationship ends.
- SSNs combined with financial profiles: If the Texas filing is accurate, the data set is enough for identity fraud, account-takeover attempts at other institutions, and targeted investment-fraud phishing aimed at people known to be active investors.
- Repeat targeting of the same customers: This was the second data incident affecting Revolut customers in September 2026. The first involved fraudulent "government" data requests and is a separate incident (Delist.ai, Cyber Breaches).
The Attack Technique
Press reports quoting DriveWealth's customer emails attribute the intrusion to a "sophisticated social engineering campaign" by unknown third parties (The Next Web, Cyber Breaches, Beinsure, and The Register via Hoodline). DriveWealth's public cyber-response page and its California AG notice confirm the intrusion window and the data theft but do not describe how the attackers got in (Delist.ai). No threat actor has been named, no group has claimed the attack, and no technical indicators have been published.
A two-day window with bulk theft of customer records fits help-desk or identity-provider social engineering: vishing to reset credentials or MFA, then access to internal data stores. That pattern has hit several financial and SaaS firms over the past few years. This is our assessment, not something the sources state.
What Organizations Should Do
- Harden help-desk and identity workflows. Require out-of-band callbacks to phone numbers already on file before any password or MFA reset. Add manager approval for resets on privileged accounts, and move to phishing-resistant MFA (FIDO2/passkeys).
- Cut down retained regulated data. Records kept for compliance should be stored separately from production, encrypted with tightly limited key access, and tokenized where possible. Old SSNs should not be reachable from ordinary employee accounts.
- Watch for bulk data access. Alert on unusual query volumes, large exports and newly granted access to customer record stores. In this incident data was taken within a 48-hour window, so detection needs to happen within hours.
- Map fourth-party exposure. Fintechs and introducing brokers should list every customer data element they have ever sent to clearing or custody partners, including data under older contracts, and agree breach-notification timelines with those partners.
- Prepare customer protection in advance. Have credit monitoring, fraud alerts and phishing warnings ready to send. Expect criminals to use this incident as a lure, including fake "DriveWealth" or "Revolut" breach emails.
- Affected individuals should place credit freezes, watch for investment-themed phishing, and treat unexpected contact about their brokerage accounts as suspicious.
Sources: DriveWealth Data Breach Hits 2.5M Texans, SSNs Exposed | PDF DriveWealth Notice of Data Breach Dear Valued Customer | DriveWealth Security Incident Exposes Revolut, Stake and Hatch Cust... | DriveWealth breach exposes data of Revolut customers who traded US... | Revolut customers in Ireland affected by 'third-party' data breach | DriveWealth broker data breach (2026): Revolut / Stake / Hatch US-t... | DriveWealth 2026 data breach: what happened Cyber Breaches | DriveWealth breach exposes data of Revolut trading customers