DriveWealth Data Breach Exposed Revolut User Records

A social engineering attack compromised historical customer data, prompting credit monitoring offers.

Updated on Oct. 2, 2026 in Cybersecurity

Bold flat-color editorial illustration showing a rigid server rack, representing data security vulnerabilities and digital storage infrastructure.
DriveWealth confirmed a September 2026 data breach that exposed historical records of Revolut customers following a successful social engineering attack. AI Illustration. Upload story photo >

Live Poll

Do you still trust financial platforms after they experience data breaches via third-party partners?

An unauthorized party gained access to DriveWealth systems on September 4 and 5, 2026, exposing historical records belonging to Revolut customers. The firm completed its investigation into the incident on September 28.

Why it matters

The breach highlights the security risks posed by retaining legacy customer data to satisfy regulatory record-keeping obligations. This incident remains distinct from a separate, smaller breach involving Revolut customer information that occurred on September 14.

The compromised dataset included names, contact information, employment details, and partial account numbers. Neither passwords nor payment credentials were accessed, and Revolut core infrastructure remained secure.

The players

DriveWealth

A financial infrastructure firm that provides API-driven brokerage and trading services to various fintech partners.

Revolut

A global fintech company providing banking, currency exchange, and stock trading features via its mobile app.

The details

The unauthorized party utilized a social engineering campaign—a method involving the manipulation of individuals into divulging sensitive information or bypassing security protocols—to infiltrate the DriveWealth network. DriveWealth maintained the exposed information because of long-standing legal and regulatory document retention requirements. While the system was compromised for two days, the company contained the breach on September 5.

Timeline

  1. September 4, 2026: Unauthorized party accessed DriveWealth network.

  2. September 14, 2026: Separate Revolut data breach reported.

  3. September 28, 2026: DriveWealth completed investigation.

  4. September 30, 2026: Breach disclosed to California Attorney General.

  5. October 1, 2026: DriveWealth and Revolut contacted affected customers.

The Tech Race

This breach follows a pattern of targeted social engineering campaigns against fintech infrastructure providers. It mirrors security challenges seen in previous incidents, such as the 2022 Revolut social engineering attack.

Affected customers have 90 days to enroll in the 12 months of complimentary credit monitoring services provided by the firm. Users should monitor their accounts for suspicious activity, as the exposed data included personal and employment information.

The takeaway

Legacy data retention policies remain a primary target for attackers seeking to exploit historical information. Impacted users should prioritize enrolling in identity monitoring services within the 90-day window provided by the company.

Further reading

For broader trends in financial system security, visit our Cybersecurity section.

Source note: This article includes information reported by Beinsure: Insurance & InsurTech Media Market Intelligence Platform.

Live Poll

Do you still trust financial platforms after they experience data breaches via third-party partners?