Some customers of Revolut, Stake and Hatch have been affected by a security incident at US brokerage infrastructure provider DriveWealth.
An unauthorised party accessed personal and, in some cases, investment-related information on September 4 and 5. The categories of exposed information differed across the three platforms.
According to Revolut notifications shared publicly by affected customers, the records may include contact, employment and basic biographical information, together with part of a DriveWealth account number. Identity documents and payment details were not compromised.
For customers in the European Economic Area, the exposure relates to information provided under an earlier operating model. Revolut stopped sending new EEA customer data to DriveWealth in December 2023, meaning only records provided before then could have been involved.
DriveWealth continues to act as the clearing broker for Revolut Securities and Revolut Wealth in the United States, according to Revolut’s current disclosures.
JUST IN: Revolut is emailing customers about another data incident. This one is at DriveWealth, the US broker that used to handle Revolut’s US share trading.DriveWealth says unauthorised access hit its systems on 4–5 September. The data taken is older customer-profile… pic.twitter.com/xPO7YbOk57
The exposure at Hatch and Stake extended beyond contact details to financial snapshots held by DriveWealth.
For Hatch customers, the affected records may include income and net-asset ranges, cash balances and total portfolio values.
The information associated with Stake accounts included W-8 or W-9 tax status, country of taxation, DriveWealth account numbers and aggregate snapshots of portfolio value, cash and buying power.
Both platforms said the incident occurred within DriveWealth’s environment and did not affect their own apps or internal systems.
Source link







