Banking

The DriveWealth breach reached yesterday’s brokerage data

Historical Revolut brokerage data was exposed at DriveWealth. The firms report no unauthorized trades, but the scope and later misuse remain uncertain.

Conceptual archive drawer with blank folders and a padlock, representing historical brokerage records.
AI-generated editorial illustration created with Codex.
In this article

An investor can stop using a brokerage arrangement and still have data exposed years later. That is the financial-platform lesson from the security incident at DriveWealth, the U.S. broker used for stock trading by some Revolut customers. DriveWealth says an unauthorized party accessed part of its network on September 4–5 and exfiltrated certain personal information. Revolut says its own systems and customers’ funds and investments were not compromised. Both statements can be true: data held by a trading partner can remain at risk after the customer-facing service changes.

The DriveWealth incident notice says it has not identified unauthorized trading, transfers, withdrawals, account transfers or alterations of balances and positions. Production brokerage and trading systems were not affected, according to the firm. This is important reassurance about the account ledger, but it is not an all-clear on personal-data misuse. The company says it is unaware of identity fraud directly resulting from the incident to date; that describes what it has found, not what will necessarily remain true.

The breach crossed a brokerage boundary, not the Revolut app

Many investment apps do not provide every part of brokerage service themselves. A customer may interact with one interface while a partner opens or maintains an underlying securities account and receives information needed for that task. DriveWealth’s privacy policy describes an “introducing firm” model in which individual accounts can be held in customers’ names at DriveWealth. Its incident notice says customers had provided information through an introducing broker, adviser or other financial institution so it could open a brokerage account.

The Irish Times reported that some Revolut customers who used U.S. share trading were affected, citing both company statements and customer notices. Revolut said its systems were not accessed, and its customer funds and investments remained safe. The relevant breach was at DriveWealth. Separating those systems prevents a false conclusion that someone withdrew investments through the Revolut app, while still recognizing that data shared for the brokerage relationship was exposed.

The exact data fields may differ by person. DriveWealth confirms that certain personal information was exfiltrated and says it has no reason to believe passwords or payment information such as card or bank-account details were compromised. RTÉ’s report cites possible profile fields including names, contact and employment information, and possible biographical fields such as citizenship, age and gender. Those are descriptions of information that may have been affected, not a verified inventory for every customer. A global count of affected Revolut users was not confirmed in the reporting.

A changed trading model leaves a data tail

Revolut told the Irish Times that, in the UK, European Economic Area and Australia, the affected information relates to historical records from before changes to its U.S. trading model. Those changes were implemented between December 2023 and June 2025, depending on market. Since the respective changes, Revolut said, individual customer details in those markets were no longer shared with DriveWealth. The precise cut-off therefore varies; it would be wrong to tell every customer that only data from before December 2023 could be involved.

This explains the apparent contradiction in receiving an incident notice from a broker a user may no longer associate with their current app. Historical records can survive a shift in operating model. DriveWealth’s privacy policy says the firm processes customer information for legal and compliance purposes, among others. That does not establish the retention period for any particular affected file, but it shows why a prior commercial relationship can leave a continuing data footprint. The continuing exposure is a cost of the platform’s architecture, even if the current trading path no longer sends the same information.

Exfiltrated profiles can feed impersonation without a stolen balance

Names, contact details and employment information are not the same as passwords. They can nevertheless make a fraudulent message sound specific and credible. An attacker who knows which brokerage relationship a person once used could pose as account support, then try to obtain credentials that were not in the original incident. This is a risk scenario, not a claim that DriveWealth customers have suffered such follow-on theft. The U.S. Securities and Exchange Commission’s investor alert explains how impostor messages and websites can target investment accounts after personal information is exposed.

DriveWealth’s notice advises affected people to watch for phishing and review financial accounts; the SEC alert likewise points investors toward their financial firms and account safeguards. Those recommendations should be understood as responses to uncertainty, not evidence of unauthorized trades. The immediate financial mechanism here is potential identity and social-engineering exposure. The firm has said its production trading systems continued to operate normally and that it found no unauthorized account activity.

The missing numbers are as important as the reassuring ones

The unresolved questions are how many people were affected, which fields were actually taken for each group, how long the exposed records were held, and whether subsequent misuse emerges. RTÉ reported that the companies had not confirmed an affected-customer count for Ireland or elsewhere. A later, narrower file inventory or evidence of attempted account fraud would materially change the risk assessment in opposite directions. So would a fuller explanation of retention and access controls across the broker and introducing firms.

For a platform investor, the lesson is neither that customer assets vanished nor that an unaffected app closes the incident. The confirmed event is data exfiltration at a brokerage partner; the confirmed limitation is that the firms have not identified unauthorized trading or payment-data exposure. The value and trust of an investment platform also depend on how well its older partner relationships protect the records they still hold.

Sources

Information and estimates for educational purposes. They do not constitute personal financial advice. About & methodology →

Continue reading