DriveWealth Data Breach Exposed Revolut User Records
A social engineering attack compromised historical customer data, prompting credit monitoring offers.
Updated on Oct. 2, 2026 in Cybersecurity

Live Poll
Do you still trust financial platforms after they experience data breaches via third-party partners?
An unauthorized party gained access to DriveWealth systems on September 4 and 5, 2026, exposing historical records belonging to Revolut customers. The firm completed its investigation into the incident on September 28.
Why it matters
The breach highlights the security risks posed by retaining legacy customer data to satisfy regulatory record-keeping obligations. This incident remains distinct from a separate, smaller breach involving Revolut customer information that occurred on September 14.
The compromised dataset included names, contact information, employment details, and partial account numbers. Neither passwords nor payment credentials were accessed, and Revolut core infrastructure remained secure.
The players
DriveWealth
A financial infrastructure firm that provides API-driven brokerage and trading services to various fintech partners.
Revolut
A global fintech company providing banking, currency exchange, and stock trading features via its mobile app.
The details
The unauthorized party utilized a social engineering campaign—a method involving the manipulation of individuals into divulging sensitive information or bypassing security protocols—to infiltrate the DriveWealth network. DriveWealth maintained the exposed information because of long-standing legal and regulatory document retention requirements. While the system was compromised for two days, the company contained the breach on September 5.
Timeline
September 4, 2026: Unauthorized party accessed DriveWealth network.
September 14, 2026: Separate Revolut data breach reported.
September 28, 2026: DriveWealth completed investigation.
September 30, 2026: Breach disclosed to California Attorney General.
October 1, 2026: DriveWealth and Revolut contacted affected customers.
The Tech Race
This breach follows a pattern of targeted social engineering campaigns against fintech infrastructure providers. It mirrors security challenges seen in previous incidents, such as the 2022 Revolut social engineering attack.
Affected customers have 90 days to enroll in the 12 months of complimentary credit monitoring services provided by the firm. Users should monitor their accounts for suspicious activity, as the exposed data included personal and employment information.
The takeaway
Legacy data retention policies remain a primary target for attackers seeking to exploit historical information. Impacted users should prioritize enrolling in identity monitoring services within the 90-day window provided by the company.
Further reading
For broader trends in financial system security, visit our Cybersecurity section.
Source note: This article includes information reported by Beinsure: Insurance & InsurTech Media Market Intelligence Platform.
Live Poll
Do you still trust financial platforms after they experience data breaches via third-party partners?






