# What happened
DriveWealth, a US brokerage infrastructure provider that supported Revolut's US stock trading, confirmed unauthorised access to its network on 4 and 5 September. DriveWealth said the access was the result of social engineering—an attack technique that manipulates people into handing over credentials or information rather than exploiting software flaws.
Revolut customers are among those affected. Neither DriveWealth nor Revolut has published the total number of Revolut customers involved.
# What types of data were exposed
- Names and contact details (email addresses, phone numbers, postal addresses)
- Employment information
- Citizenship, age and gender
- Partial DriveWealth account numbers
Related reporting says identity documents and payment details were not compromised in the DriveWealth incident. That distinction matters for the kinds of follow-up actions customers may need to take.
# Which Revolut customers are affected
Reports suggest that records retained after customers closed or migrated accounts can also be included, so affected records may be historical rather than active-account data.
# How this fits with the earlier September impersonation incident
Earlier in September, Revolut disclosed a separate incident in which attackers used a legitimate government email domain to impersonate an authority and request customer data. Revolut blocked the email address used, alerted the agency whose domain was spoofed, contacted police and informed financial regulators.
# What the companies have said publicly
DriveWealth confirmed unauthorised access on 4 and 5 September and characterised the cause as social engineering. Revolut told media outlets that the affected records for the UK, EEA and Australia are older and predate the platform change that ended its sharing of individual customer details with DriveWealth in those regions. Neither company disclosed exact counts of impacted customers.
# Practical next steps for customers
- Review account and contact details for unexpected changes and monitor email and phone for phishing attempts. Social engineering campaigns sometimes follow data exposures.
- If you trade US stocks via Revolut, verify whether your account was migrated or closed before December 2023 (EEA) or before the date Revolut stopped sharing details with DriveWealth in your region.
- Consider tightening account security where possible: enable multi-factor authentication and use unique passwords for financial accounts.
# Bottom line
A social engineering incident at DriveWealth on 4–5 September exposed historic customer-profile records that include some Revolut users. This follows an earlier impersonation-based disclosure involving a government email domain. The companies have issued limited public details: the scope and exact number of Revolut customers affected remain unspecified, and affected records appear mainly to be older profile data rather than current account funds or identity documents.