Some Revolut customers have been affected by a data breach at DriveWealth, the US brokerage infrastructure provider used to support US stock trading.

DriveWealth says unauthorised access to its systems exposed historical personal information belonging to some customers. Revolut says its own systems and infrastructure were not accessed or compromised, and that customer funds and investments remain safe.

Key takeaways

  • The incident occurred at DriveWealth, not inside Revolut's own infrastructure.
  • Potentially exposed data includes names, email addresses, phone numbers, postal addresses, employment information, citizenship, age, gender and partial DriveWealth account numbers.
  • Revolut says passwords, passcodes, card details and identity documents were not exposed.
  • DriveWealth says payment information such as card and bank-account details was not compromised.

What happened at DriveWealth?

DriveWealth disclosed a security incident involving unauthorised network access and the exfiltration of historical customer information. Public reporting says the access occurred in early September following a social-engineering campaign.

The provider supports brokerage functions for a range of financial-technology companies. Revolut used DriveWealth for US stock trading, meaning some former or current customers whose historical brokerage profiles remained with DriveWealth were included in the affected population.

What Revolut customer data may have been exposed?

According to customer communications and DriveWealth's description of the affected records, potentially exposed information can include:

  • name, email address and phone number;
  • postal address;
  • employment information;
  • country of citizenship, age and gender; and
  • partial DriveWealth account numbers.

The exact data involved can differ by customer, so people who received a notification should rely on the details in their own notice rather than assume every listed field was exposed.

What was not exposed?

Revolut says its own infrastructure was not compromised and that the breach did not expose Revolut passwords, passcodes, card details or identity documents.

DriveWealth has also said that passwords and financial payment information, including card and bank-account details, were not compromised.

Those distinctions matter because this incident is a third-party data exposure rather than evidence that an attacker obtained direct access to Revolut accounts or payment credentials.

Is customers' money at risk?

Revolut says customer funds and investments are safe. Public reporting has not established unauthorised trading, transfers or withdrawals caused by the DriveWealth incident.

However, personal profile information can still be useful to criminals. Names, contact details, employment information and brokerage-related context can make phishing messages more convincing.

What affected customers should do

Be suspicious of tailored phishing

Customers should be cautious of emails, calls or messages that reference stock trading, DriveWealth, Revolut or personal details and then request passwords, one-time codes, remote access or urgent payments.

Use official channels

Open the Revolut app or official website directly rather than following links in unexpected messages. Do the same for any DriveWealth correspondence.

Review account activity

Even though payment credentials were not reported exposed, customers should continue to review account and investment activity and report anything unfamiliar promptly.

Protect reused contact information

If the exposed email address or phone number is used across other sensitive accounts, make sure those accounts have strong, unique passwords and multi-factor authentication where available.

Why third-party risk matters in fintech

Digital financial services depend on networks of specialist providers for brokerage, payments, identity, cloud infrastructure and compliance. A customer may interact with one brand while their data is processed or retained by several other companies behind the scenes.

That is why third-party security and data-retention controls matter even when a consumer-facing app itself is not breached.

FlyingEze recently examined related financial-data and infrastructure issues, including Nigeria's payment-data localisation deadline and Fenergo's role in financial compliance software .

Bottom line

The DriveWealth breach exposed historical personal information belonging to some Revolut customers who used US stock-trading services, but Revolut says its own systems were not compromised and core account credentials, card details and identity documents were not exposed.

Affected customers should focus on phishing risk, account monitoring and official communications while DriveWealth and Revolut continue to clarify the incident's scope.