Key Points
- Revolut disclosed another security incident on September 24, distinct from a previous breach reported earlier this month.
- DriveWealth, a US-based brokerage partner managing stock trading for Revolut users, was targeted in the attack.
- Cybercriminals used social engineering tactics to infiltrate DriveWealth’s systems on September 4-5.
- Compromised information includes customer names, contact details, addresses, and truncated account identifiers.
- Financial credentials, payment card information, and identification documents remained secure.
Revolut users have been impacted by another data incident this month. The digital banking platform disclosed the security event on September 24.
This represents a distinct event from the previous compromise. The company had previously disclosed a security breach in early September linked to fraudulent government email communications.
The latest incident centers on DriveWealth. This American brokerage firm facilitates equity trading capabilities for certain Revolut account holders.
Details of the DriveWealth Attack
DriveWealth serves as the execution and clearing partner for Revolut subscribers utilizing the platform’s optional equity trading functionality. The brokerage maintains client information to facilitate transactions and ensure compliance with US financial regulations.
An unknown threat actor gained unauthorized entry to Revolut customer information housed within DriveWealth’s infrastructure. The brokerage verified the intrusion occurred during a two-day window on September 4-5.
The compromise stemmed from a social engineering campaign. Such attacks manipulate individuals into divulging confidential data instead of leveraging technical vulnerabilities.
DriveWealth initiated direct communication with impacted users. Revolut subsequently distributed supplementary notifications to provide additional context.
Compromised Information Details
The leaked data encompasses past customer records. This comprises full names, email contacts, telephone numbers, and mailing addresses.
Professional details were also compromised. Additional exposed fields include nationality, age demographics, and gender information.
\p dir=”ltr”>Truncated DriveWealth account identifiers were also accessed. Revolut clarified that complete account credentials were not compromised.
Revolut emphasized that its internal infrastructure remained untouched during this incident. Customer assets and investment portfolios continue to be protected, the company stated.
Revolut login credentials, security codes, payment card data, and government-issued identification were not exposed during this event. This distinguishes it from the previous September incident, which did involve identity verification documents.
The earlier security event impacted approximately 680 users worldwide. Attackers had exploited an authentic Italian government email platform to manipulate Revolut into disclosing sensitive information.
Affected User Base
The scope of impact differs based on geographic location and the timing of Revolut’s operational model transition. These modifications were implemented progressively from December 2023 through June 2025 across different territories.
European Economic Area users, including Irish customers, experienced the earliest changes. Revolut discontinued data transfers to DriveWealth for these regions following December 2023.
Consequently, EEA account holders have had no information shared with DriveWealth since that transition. Only archived records predating the operational shift are implicated.
For American users, the incident pertains to those who activated the equity trading functionality. Revolut indicated that customers who did not receive direct notification from DriveWealth remain unaffected.
The security event extended to additional platforms. Stake and Hatch, two separate services leveraging DriveWealth’s technology backbone, acknowledged comparable data exposure.
Neither organization has disclosed precise figures regarding affected individuals. Revolut maintains approximately 3.4 million active users in Ireland exclusively.
Revolut is recommending impacted individuals remain vigilant against social engineering schemes. Users with questions can reach Revolut via verified communication channels.
This constitutes the second security compromise associated with Revolut within a single calendar month. Both incidents originated from external service providers rather than Revolut’s proprietary infrastructure.





