Revolut customers were drawn into a second data security incident in September, this time through a third-party provider rather than Revolut’s own systems. The company said the event relates to DriveWealth, the US broker that previously supported stock trading for Revolut users in the United States.
DriveWealth said attackers gained unauthorized access to its network on September 4 and 5 through a social engineering attack. According to the companies, the incident affected historical customer records from before Revolut changed its trading setup, not current data flows.
Attack tied to former trading arrangement
DriveWealth said the breach did not stem from a software vulnerability. Instead, attackers reportedly manipulated individuals into disclosing sensitive information, allowing unauthorized access to the broker’s network.
The exposed records are limited to older customer data from the period before Revolut altered its trading model. In the European Economic Area, including Ireland, that transition took place in December 2023. Revolut said it stopped sharing individual customer details with DriveWealth after that change, which means more recent users were not affected under the companies’ account of the incident.
What information may have been exposed
The companies said the compromised data may include names, email addresses, phone numbers, postal addresses, employment details, and biographical information such as citizenship, age, and gender. Partial DriveWealth account numbers were also among the data types potentially exposed.
At the same time, DriveWealth and Revolut said several categories of more sensitive information were not compromised. Those excluded items include passwords, payment card details, bank information, Revolut passcodes, and identity documents.
Customers contacted as scale remains unclear
A Revolut spokesperson said DriveWealth contacted affected customers directly, while Revolut also followed up through its own emails. Neither company has disclosed how many people were impacted.
The issue is notable for Revolut because it follows another data-related incident earlier in September. In that separate case, a sophisticated impersonation scam using a legitimate Italian government email domain reportedly tricked Revolut into releasing sensitive data, including identity documents, affecting about 680 customers globally.
Broader exposure and next steps
The DriveWealth breach was not limited to Revolut-linked records. Stake and Hatch, two other platforms that rely on DriveWealth infrastructure, also confirmed similar exposure.
Revolut has around 3.4 million customers in Ireland alone, although the number affected by this incident has not been published. The confirmed guidance so far is for impacted users to monitor incoming messages, remain alert to phishing attempts, and contact Revolut through official channels if they have concerns.
Source: beincrypto.com