Back
Revolut customers hit by a second data breach this month
SiTech AI Team2 წთ. საკითხავი

Revolut customers hit by a second data breach this month

Attackers used social engineering to get inside US brokerage DriveWealth and stole historic personal data belonging to Revolut customers who once traded US stocks through the broker.

Revolut customers have been caught up in a second data breach this month after attackers socially engineered their way into US brokerage DriveWealth and stole historic personal information. The unauthorized access took place on September 4 and 5.

What DriveWealth said

DriveWealth clears trades for investment firms and once held brokerage accounts directly for Revolut customers trading US stocks. In an email to affected customers seen by The Register, the broker blamed a "sophisticated social engineering campaign" by unknown third parties. The intruders exfiltrated data retained from the period when those customers held accounts directly with DriveWealth.

The exposed data includes names, email addresses, phone numbers, postal addresses, employment information, citizenship, age, gender, and partial DriveWealth account numbers. Passwords and payment information, including credit card and bank account details, were not compromised. Even so, the broker warned that the stolen details could feed identity fraud, impersonation, further social engineering, or unsolicited contact from strangers, and give scammers material for a convincing phishing message.

What Revolut said

Revolut confirmed to the Irish Examiner that its customers are among those affected and that the records date from its previous arrangement with DriveWealth. The fintech said its systems and infrastructure were not compromised, customer funds and investments remained safe, and no Revolut passwords, passcodes, card details, or identity documents were exposed.

The data dates from the arrangement under which Revolut customers traded US stocks. Revolut moved customers in the UK, the EEA, and Australia away from it between December 2023 and June 2025, and their personal details were no longer shared with DriveWealth after the respective migrations. Both companies notified affected customers, but neither has disclosed how many Revolut customers were affected, and both failed to answer The Register's questions.

An awkward month for Revolut

On September 14, Revolut admitted it had handed sensitive customer information to criminals after they submitted fraudulent requests using an email domain belonging to a legitimate government agency. That incident potentially exposed passports, driver's licenses, verification selfies, dates of birth, addresses, phone numbers, and financial and transaction data. Revolut said it had fallen victim to a "sophisticated external impersonation scam" and that only a limited number of customers were affected.

Two different incidents, two different sets of attackers, and two different routes to customer data. For Revolut customers, September has brought more breach notifications than anyone would want from their banking app.

SSiTech

SiTech — AI-powered web development

We build fast, modern websites and bring AI into real business workflows. Have a project or a question? We'd love to help.