DriveWealth Breach Exposes Revolut, Stake and Hatch Client Data
DriveWealth says a September 4–5 social-engineering breach hit client records at Revolut, Stake and Hatch, exposing portfolio, tax and contact data.
Execution notes
- Unauthorised access to DriveWealth systems occurred September 4–5, attributed by the firm to a social-engineering campaign
- Revolut stopped sending new EEA customer data to DriveWealth in December 2023; only earlier records could be exposed, and DriveWealth still clears for Revolut Securities and Revolut Wealth in the US
- Stake and Hatch exposures included tax status, account numbers, portfolio value, cash and buying-power snapshots; DriveWealth reports no unauthorised trades, transfers or withdrawals
Unauthorised parties accessed customer records at DriveWealth, the US brokerage infrastructure provider, on September 4 and 5, exposing personal and in some cases investment-related data belonging to clients of Revolut, Stake and Hatch. DriveWealth attributed the access to a social-engineering campaign, told partners the incident was contained, and said it identified no unauthorised trades, transfers or withdrawals.
The categories of exposed information differed across the three platforms, according to notifications the firms sent to affected customers.
Revolut: historical records, partial account numbers
For Revolut customers, the exposed records may include contact, employment and basic biographical information, together with part of a DriveWealth account number. Identity documents and payment details were not compromised, according to Revolut notifications shared publicly by affected customers.
For customers in the European Economic Area, the exposure relates to data supplied under an earlier operating model. Revolut stopped sending new EEA customer data to DriveWealth in December 2023, so only records provided before that date could have been involved. DriveWealth continues to act as clearing broker for Revolut Securities and Revolut Wealth in the United States, according to Revolut's current disclosures.
That means the incident touches an active operational relationship, not a terminated one. Firms that route US equity business through DriveWealth's API-based infrastructure share customer-profile data with the clearing broker as a condition of account opening and servicing — which is precisely the dataset the attacker reached.
Stake and Hatch: financial snapshots exposed
The exposure at Stake and Hatch extended beyond contact details to financial snapshots held by DriveWealth.
For Hatch customers, affected records may include income and net-asset ranges, cash balances and total portfolio values. For Stake accounts, the compromised information included W-8 or W-9 tax status, country of taxation, DriveWealth account numbers and aggregate snapshots of portfolio value, cash and buying power.
Both platforms stated the incident occurred within DriveWealth's environment and did not affect their own apps or internal systems. That distinction matters for assessing blast radius: the front-end stacks at the three fintechs were not breached, but data downstream at the clearing layer was.
Separate from the earlier Revolut incident
The DriveWealth breach is unrelated to a separate Revolut incident disclosed earlier this month. In that case, attackers used a compromised Italian government email account to submit fraudulent information requests directly to Revolut and reportedly obtained KYC documents and transaction records for roughly 680 customers. The DriveWealth incident occurred inside the broker's own environment; Revolut customers were affected because their information had been supplied to open and service investment accounts there.
What is measured, what is asserted
Two claims deserve separation. DriveWealth asserts the incident is contained and that it found no unauthorised trades, transfers or withdrawals — a statement about activity it has monitored. The three platforms assert a forward risk: exposed contact and account data could support targeted phishing or impersonation attempts. Both warnings appear in the customer notifications.
For desks and fintech operators, the incident is a reminder that custody and clearing relationships extend the data perimeter beyond the firm's own systems. Aggregate portfolio, cash and buying-power snapshots held at a clearing broker are not tradeable credentials, but combined with contact details, tax status and partial account numbers they give attackers a credible script for social engineering against clients — and potentially against support staff verifying caller identity.
DriveWealth has not publicly disclosed the number of affected accounts or the mechanism of the social-engineering campaign. The three platforms have warned affected customers to treat unsolicited contact requests with suspicion, and further detail on scope may follow as notifications continue.
via events.financemagnates.com (Original)
More from Daniel Okafor
Show full bio
Market editor covering industry trends and analytics at Order Flow Brief.
49 articles
Blotter · related prints
Nasdaq Phlx Fines Avatar Securities $100,000
800NinjaTrader and Alpha Part Ways on Futures; FundedNext Adds AI Tools
100CSD BR Mirrors BTG Fund Shares on XRP Ledger in Live Brazil Deployment
900LME Electronic Trading Back Online After Nearly Three-Hour Outage
300Bernstein's Head of Electronic Trading Departs the Firm
200