Key Points
- Revolut disclosed a separate security incident this month, distinct from the previous breach reported earlier in September.
- The latest incident originates from DriveWealth, a US-based brokerage firm that facilitates American stock trading for Revolut users.
- DriveWealth’s network was compromised through a social engineering attack on September 4 and 5.
- Compromised information includes customer names, email addresses, telephone numbers, physical addresses, and incomplete account identifiers.
- According to Revolut, sensitive data such as passwords, payment card information, and identification documents remained secure.
Revolut users have been impacted by another data incident within the same month. The digital banking platform disclosed this security breach on September 24.
This security event stands apart from a previous incident. The company had previously disclosed an earlier September breach that involved attackers using a fraudulent government email address.
The latest compromise centers on DriveWealth. This American brokerage firm manages stock trading operations for certain Revolut account holders.
Details of the DriveWealth Security Incident
DriveWealth operates as the execution and clearing partner for Revolut members who utilize the platform’s elective American stock trading functionality. The brokerage maintains client information to facilitate transactions and comply with United States financial regulations.
An illegitimate actor gained entry to Revolut customer information housed within DriveWealth’s infrastructure. DriveWealth verified the intrusion occurred during a two-day period on September 4 and 5.
The security compromise stemmed from a social engineering offensive. Such attacks manipulate individuals into disclosing confidential data instead of leveraging technical system vulnerabilities.
DriveWealth initiated direct communication with impacted clients. Revolut subsequently issued supplementary notifications to clarify the circumstances for its users.
Compromised Customer Information
The leaked information encompasses past customer records. This dataset includes full names, email contacts, telephone numbers, and mailing addresses.
Professional details were also compromised. Additional exposed data includes nationality information, age ranges, and gender identification.
Incomplete DriveWealth account identifiers were also accessed. Revolut clarified that complete account credentials were not part of the breach.
Revolut emphasized that its internal infrastructure remained untouched during this incident. Customer capital and investment portfolios continue to be protected, the company confirmed.
Revolut login credentials, security codes, payment card information, or identity verification documents were not compromised in this breach. This distinguishes it from the prior September incident, which did involve identity documentation.
The previous breach impacted approximately 680 users worldwide. Perpetrators had exploited an authentic Italian governmental email domain to deceive Revolut into disclosing information.
Affected Customer Base
The scope of impact differs based on geographic location and the timeline of Revolut’s stock trading infrastructure modifications. These transitions occurred between December 2023 and June 2025 across different jurisdictions.
Users within the European Economic Area, including Ireland, experienced the initial changes. Revolut discontinued data sharing with DriveWealth for these territories following December 2023.
Consequently, EEA-based customers have had no information transmitted to DriveWealth since that cutoff. Only archived records predating the transition are relevant to this breach.
For United States-based users, the incident pertains to those who have engaged with the American stock trading feature. Revolut indicated that customers who did not receive direct notification from DriveWealth remain unaffected.
The security incident extended beyond Revolut. Stake and Hatch, two additional platforms utilizing DriveWealth’s brokerage services, acknowledged comparable data exposure.
Neither Revolut nor DriveWealth has disclosed precise figures regarding affected individuals. Revolut maintains approximately 3.4 million active customers in Ireland exclusively.
Revolut is recommending impacted individuals remain vigilant against phishing schemes. Customers seeking assistance can reach Revolut through verified communication channels.
This represents the second data security incident associated with Revolut within a 30-day period. Both situations originated from external service providers rather than Revolut’s proprietary infrastructure.


