Skip to content

Revolut customers face fresh data risk after DriveWealth breach

DriveWealth, the US broker once used for Revolut share trading, says personal data was exfiltrated in a September breach. Revolut is still confirming how many UK customers are affected.

By

Published
An old, worn paper folder sits alone on a shelf inside a locked glass cabinet, with no key in its keyhole.

Revolut customers who once held a share-trading account through DriveWealth, the US broker the app used before its UK trading revamp, are being told that some of their historical personal data may have been exposed in a breach at DriveWealth's own systems. DriveWealth says an unauthorised party accessed its network between 4 and 5 September 2026 and that certain personal information was taken. Revolut says its own systems were not compromised and that customer funds and investments are unaffected.

The breach affects records that predate changes Revolut made to how it offers US share trading in different markets: December 2023 in the European Economic Area, March 2025 in the UK, and June 2025 in Australia. For UK customers, that means the data at risk is historical — tied to an account structure Revolut has already moved away from — rather than information held in Revolut's current systems.

As of 26 September 2026, Revolut was still communicating with DriveWealth to confirm the exact scope of the breach. No total number of affected UK customers, or affected records, had been published. Receipt of an initial notice from DriveWealth or Revolut means a customer may be affected; the companies were still confirming whether, and which, records were involved.

Who in the UK may be affected

Before Revolut changed its UK share-trading arrangement, customers who used the feature had a brokerage account opened directly with DriveWealth LLC, the US broker-dealer Revolut used to provide execution, settlement and clearing for its trading product. That structure meant individual customer details sat on DriveWealth's own systems, separate from Revolut's.

Revolut migrated UK customers away from that direct DriveWealth arrangement in March 2025 — the exact day has not been established in available reporting. From that point, individual UK customer details stopped being shared with DriveWealth under the old model. The customers now being contacted are those whose historical DriveWealth brokerage record, created before that migration, remained on DriveWealth's systems and may have been involved in the breach DriveWealth disclosed.

This is a narrower group than "anyone who has ever used Revolut" or even "anyone who has ever traded shares on Revolut." It concerns people whose earlier trading arrangement included a brokerage account opened directly with DriveWealth, and whose historical record may have remained on DriveWealth's systems at the time of the breach. Revolut has not published a customer count, and DriveWealth is described in reporting as best placed to give a total.

What personal information was taken

DriveWealth's investigation identified the following categories of historical information as potentially exfiltrated:

  • Names
  • Email addresses
  • Telephone numbers
  • Postal addresses
  • Employment information
  • Country of citizenship
  • Age
  • Gender
  • Partial DriveWealth account numbers

This is a list of the categories of data that may have been affected, not a confirmed, field-by-field account of what was taken from every individual customer. Revolut and DriveWealth were still working through that detail as of 26 September 2026.

Why passwords and payment details are not thought to be involved

DriveWealth said it had no reason, as of its notice, to believe that passwords or financial payment information — such as credit card or bank account details — had been compromised. Revolut separately said identity documents were not affected.

The explanation lies in what kind of data DriveWealth held and what its investigation actually found. The exposed records relate to brokerage onboarding information from the historical arrangement, not to Revolut's own login credentials or payment rails. DriveWealth's investigation had not, at the time of its notice, identified passwords or payment details among the affected information. This is an assurance based on the investigation's findings to date, not a guarantee that later findings cannot change it.

Why DriveWealth still held older UK customer records

DriveWealth obtained UK customer data through the former direct brokerage arrangement, under which customers held an account opened directly with DriveWealth. Available reporting does not establish the legal basis or the retention period under which DriveWealth continued to hold each UK record after the UK migration in March 2025. The table below sets out when each market moved away from the arrangement that gave DriveWealth direct visibility of individual customer records.

MarketMigration away from direct DriveWealth arrangement
European Economic AreaDecember 2023
United KingdomMarch 2025
AustraliaJune 2025

These dates matter because they show the exposed records are historical rather than current, and because the EEA cut-off is different from — and earlier than — the UK one. A UK customer should not assume the December 2023 date applies to them; the relevant cut-off for the UK is March 2025.

What remains unconfirmed

Several things had not been established by 26 September 2026:

  • The exact number of affected UK customers or records.
  • Which of the listed data categories applied to any specific individual.
  • The precise day in March 2025 the UK migration took effect.
  • Whether DriveWealth's or Revolut's investigation had concluded.

Revolut's statements that its own systems were not compromised, and that customer funds and investments are safe, are company assurances. No independent forensic or regulatory finding on this incident has been made public.

How this differs from Revolut's earlier September incident

This is not Revolut's first data story this month. On 12 September 2026, Revolut confirmed a separate incident in which it disclosed customer information after fraudulent requests arrived through what appeared to be a legitimate government-agency email domain — an impersonation scam rather than a system intrusion.

The DriveWealth breach is a different event with a different cause. It involves unauthorised access to a third-party broker's network, not a second breach of Revolut's own infrastructure, and not a repeat of the impersonation tactic used in the 12 September incident. Describing the two together as Revolut's "second data incident" is accurate only if it is clear that the second event happened at DriveWealth, a company Revolut used as a service provider, rather than inside Revolut itself.

UK data-protection context and what to watch next

Under UK data-protection rules, an organisation must normally report a notifiable personal data breach to the Information Commissioner's Office without undue delay and, where feasible, within 72 hours of becoming aware of it. That is a general rule about how such breaches are meant to be handled in the UK; it does not by itself confirm whether this incident met the threshold for notification, which company bore that duty, or whether a report has been made to the ICO.

DriveWealth said it had contacted affected customers directly, and Revolut said it followed up with its own emails explaining the incident. Anyone who has received such a notice, or who wants to check DriveWealth's own account of the breach, can consult DriveWealth's published cyber-response notice. Readers who want to understand their rights around a personal data breach, including how notification is supposed to work, can consult the Information Commissioner's Office's published guidance.

The scope Revolut and DriveWealth were still confirming as of 26 September 2026 — including any customer total, the full list of affected fields per individual, and whether UK regulators have been notified — is the detail to watch for next.

Sources

  1. Cyber-Response (opens in a new tab)

    DriveWealth · Accessed

  2. Revolut customers warned after DriveWealth data breach (opens in a new tab)

    Join the Claim · · Accessed

  3. Privacy Policy (opens in a new tab)

    Revolut · Accessed

  4. Personal data breaches: a guide (opens in a new tab)

    Information Commissioner's Office · Accessed

All Companies & Funding coverage