Another week, another data breach for Revolut customers
DriveWealth coughs up historic customer info after attackers socially engineer their way inside
Revolut customers endured a second data breach this month when attackers infiltrated US brokerage DriveWealth and obtained historical personal information. DriveWealth, which once held brokerage accounts for Revolut users trading US stocks, revealed the unauthorized access on September 4-5. The intrusion was attributed to a sophisticated social engineering campaign orchestrated by unidentified third parties.
The compromised data, dating back to Revolut's earlier partnership with DriveWealth, comprised names, email addresses, phone numbers, postal addresses, employment details, citizenship, age, gender, and partial account numbers. However, passwords, payment information, and other sensitive data remained untouched. DriveWealth conveyed to affected customers that the stolen information could facilitate identity fraud, impersonation, further social engineering, or unsolicited contact.
Revolut affirmed its systems and customer funds remained secure, with no Revolut passwords, passcodes, card details, or identity documents exposed. The fintech ceased sharing customer data with DriveWealth following migrations between December 2023 and June 2025. The breach transpired during a challenging period for Revolut, as it simultaneously disclosed a separate incident where sensitive customer information fell into criminal hands after they submitted fraudulent information requests using a government agency's email domain.
The dual incidents involved distinct attackers and distinct pathways to customer data, leaving Revolut customers to grapple with more breach notifications in September than they likely desired.
Written by urgent.news from The Register Science's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.
Also reported by 1 other outlet
- Another week, another data breach for Revolut customers theregister.com