Revolut has begun emailing customers about a second data incident in just over a week, this time tied to DriveWealth, the US broker that formerly handled Revolut's US share trading. Max Karpis, an early Revolut investor and independent analyst who tracks the company's operations, first reported the notification on X. DriveWealth confirmed that unauthorized access hit its systems on September 4 and 5.
JUST IN: Revolut is emailing customers about another data incident. This one is at DriveWealth, the US broker that used to handle Revolut’s US share trading.
— Max Karpis (@maxkarpis) September 24, 2026
DriveWealth says unauthorised access hit its systems on 4–5 September. The data taken is older customer-profile… pic.twitter.com/xPO7YbOk57
The exposed data covers older customer-profile information DriveWealth retained for regulatory purposes: name, email, phone number, address, employment details, citizenship, age, gender, and a partial account number. Passwords, card details, bank information, and identity documents were not part of the exposure. Neither company has reported any unauthorized trades or withdrawals connected to the incident.

Why this breach only touches historical Revolut records
Revolut said its own systems, funds, and accounts were not touched by the DriveWealth breach. The company stopped sending new EEA customer data to DriveWealth in December 2023, which means only records predating that cutoff can be implicated in this specific incident. Revolut said it is still working with DriveWealth to determine the exact scope of affected customers.
The December 2023 cutoff points to a broader shift in how Revolut has structured its US equities offering. Fintech companies that want to offer stock trading to customers typically cannot act as a broker-dealer themselves in every jurisdiction without extensive separate licensing, so many route trade execution through a third-party partner broker that already holds the necessary registrations. DriveWealth has served this role for multiple fintech and neobank platforms beyond Revolut, functioning as backend brokerage infrastructure rather than a customer-facing brand most users would recognize. When Revolut moved away from routing new EEA customer data to DriveWealth in December 2023, it likely reflected either a shift toward an alternative brokerage partner or an in-house buildout of trading infrastructure for that customer segment, though the specific reason has not been detailed publicly.
How this differs from last week's separate Revolut incident
This DriveWealth breach is entirely unconnected to a separate incident Revolut disclosed roughly a week earlier, in which scammers used a compromised Italian government email domain to trick staff into handing over KYC files, identification documents, and Bitcoin transaction histories for approximately 680 customers.
The two incidents illustrate genuinely different attack vectors, a distinction worth treating carefully rather than collapsing into a single "Revolut breach" narrative. The Italian government email incident was a social engineering attack, where attackers exploited trust in an authentic government domain to manipulate Revolut employees into voluntarily disclosing sensitive files, a technique that depends on human decision-making rather than a technical system compromise. The DriveWealth incident, by contrast, appears to be a direct unauthorized intrusion into a third-party vendor's systems, a supply-chain style breach where the vulnerability sits entirely outside Revolut's own infrastructure. Conflating the two would misstate what actually went wrong in each case and where the responsibility for remediation lies.
What this reveals about third-party data retention risk
The DriveWealth breach surfaces a structural question that extends well beyond Revolut specifically: how long should customer data persist with a former service provider after a company has moved to a new vendor or brought a function in-house. DriveWealth retained Revolut customer records from before December 2023 for what it describes as regulatory reasons, meaning the data sat in DriveWealth's systems for nearly two years after Revolut had already stopped actively sending new information there.
Financial services regulation frequently requires firms to retain customer records for extended periods, often five to seven years depending on jurisdiction and record type, specifically to support audit trails, dispute resolution, and regulatory examination. This creates an inherent tension for any fintech that changes brokerage or infrastructure partners: the departing vendor cannot simply delete historical records the moment the commercial relationship ends, because doing so could itself violate recordkeeping obligations. That tension means customers can remain exposed to a former partner's security posture long after they believe their relationship with that specific vendor has ended, a risk that is largely invisible to the end user until an incident like this one surfaces it publicly.
The DriveWealth notification is a live, ongoing situation. Revolut has indicated the scope determination with DriveWealth is still underway, and updates on the number of affected customers are expected as that review concludes.

Disclaimer: All materials on this site are for informational purposes only. None of the material should be interpreted as investment advice. Please note that, despite the nature of much of the material created and hosted on this website, HODL FM operates as a media and informational platform, not a provider of financial advisory services. The opinions of authors and other contributors are their own and should not be taken as financial advice. If you require advice, HODL FM strongly recommends contacting a qualified industry professional.





