Fintechnews iconFintechnewsSep 25, 2026 ~3 min source read

DriveWealth Network Access Exposed Historic Revolut Customer Records After Social Engineering Attack

DriveWealth confirms unauthorised access on 4–5 September that impacted older Revolut customer records. This is the second time Revolut-related data surfaced in September, following an impersonation scam using a government email domain.

Revolut Data Breach at DriveWealth Follows Impersonation Incident

Share this story

Send the public story page.

Useful takeaways from this story.

DriveWealth reported unauthorised access to its network on 4–5 September and attributed it to social engineering.

This incident follows an earlier September impersonation case where attackers used a legitimate government email domain to request Revolut customer data.

# What happened

DriveWealth, a US brokerage infrastructure provider that supported Revolut's US stock trading, confirmed unauthorised access to its network on 4 and 5 September. DriveWealth said the access was the result of social engineering—an attack technique that manipulates people into handing over credentials or information rather than exploiting software flaws.

Revolut customers are among those affected. Neither DriveWealth nor Revolut has published the total number of Revolut customers involved.

# What types of data were exposed

  • Names and contact details (email addresses, phone numbers, postal addresses)
  • Employment information
  • Citizenship, age and gender
  • Partial DriveWealth account numbers

Related reporting says identity documents and payment details were not compromised in the DriveWealth incident. That distinction matters for the kinds of follow-up actions customers may need to take.

# Which Revolut customers are affected

Reports suggest that records retained after customers closed or migrated accounts can also be included, so affected records may be historical rather than active-account data.

# How this fits with the earlier September impersonation incident

Earlier in September, Revolut disclosed a separate incident in which attackers used a legitimate government email domain to impersonate an authority and request customer data. Revolut blocked the email address used, alerted the agency whose domain was spoofed, contacted police and informed financial regulators.

# What the companies have said publicly

DriveWealth confirmed unauthorised access on 4 and 5 September and characterised the cause as social engineering. Revolut told media outlets that the affected records for the UK, EEA and Australia are older and predate the platform change that ended its sharing of individual customer details with DriveWealth in those regions. Neither company disclosed exact counts of impacted customers.

# Practical next steps for customers

  • Review account and contact details for unexpected changes and monitor email and phone for phishing attempts. Social engineering campaigns sometimes follow data exposures.
  • If you trade US stocks via Revolut, verify whether your account was migrated or closed before December 2023 (EEA) or before the date Revolut stopped sharing details with DriveWealth in your region.
  • Consider tightening account security where possible: enable multi-factor authentication and use unique passwords for financial accounts.

# Bottom line

A social engineering incident at DriveWealth on 4–5 September exposed historic customer-profile records that include some Revolut users. This follows an earlier impersonation-based disclosure involving a government email domain. The companies have issued limited public details: the scope and exact number of Revolut customers affected remain unspecified, and affected records appear mainly to be older profile data rather than current account funds or identity documents.

More context around this story.

Loading more related stories...

Keep reading in the app

Open the app view to save this story, compare related coverage, and continue from the same source.

Open in app