Digital bank Revolut has become entangled in another customer-data scare after a security incident at US brokerage partner DriveWealth. The event is separate from an earlier September episode at Revolut itself. This time, the exposure occurred on DriveWealth’s systems, not inside Revolut’s own infrastructure.
DriveWealth said unauthorized access to its network took place on 4 and 5 September 2026.
Investigators later concluded that some personal information stored on certain systems was taken.
The firm has said production trading platforms were not disrupted and that it found no unauthorized trades, transfers, withdrawals, or account-balance changes.
Outside cybersecurity specialists were brought in to review the response.
Revolut used DriveWealth to support US stock trading for customers. After the broker notified partners, Revolut contacted people it identified as potentially affected.
For users in the United States, the issue involves those who used U.S. share trading.
In the United Kingdom, the European Economic Area, and Australia, Revolut says the records are older.
The company changed its trading model between December 2023 and June 2025, depending on the market.
After those changes, it stopped sending individual customer details in those regions to DriveWealth, so later accounts should not be in the exposed set.
The information that may have been involved is mainly profile and contact data. Notices describe names, email addresses, phone numbers, postal addresses, and employment details.
Biographical fields such as citizenship, age, and gender, plus a partial DriveWealth account number, may also have been included.
DriveWealth and Revolut have said passwords, payment card numbers, bank-account details, Revolut passcodes, and identity documents were not part of the material taken.
Revolut has also said its own systems were not accessed and that customer funds and investments remain safe.
Neither company has published a full count of affected Revolut users. DriveWealth has contacted people it believes were involved, and Revolut has sent follow-up messages.
Customers who have not received those emails are generally being told they are not in the notified group, though some DriveWealth messages appear to have landed in spam folders.
Other introducing platforms that rely on DriveWealth, including Stake and Hatch, have issued their own notices, underlining that the incident sits with a shared third-party broker rather than a single consumer app.
The timing is awkward for Revolut.
Earlier in September the firm disclosed a different incident in which fraudulent requests sent from a compromised government email domain led it to release sensitive records for a limited group of customers.
That case involved identity documents and transaction histories.
The DriveWealth event is a distinct partner-side failure, but together the two episodes have intensified scrutiny of how digital banks handle vendor risk.
For customers, the practical concern is social engineering. Contact details and employment information can be used to craft convincing phishing or impersonation attempts.
Revolut has urged users to treat unexpected messages with caution, check official app communications rather than links in unsolicited emails, and watch account activity.
DriveWealth has recommended remaining alert for unusual financial activity and, where relevant, considering credit-monitoring or fraud-alert options.
The episode is a reminder that fintech products often rest on a chain of specialist providers.
When one link is breached, customer data can surface even if the consumer-facing bank was not hacked. Revolut says it is still working with DriveWealth to pin down the exact scope. Until that work is finished, affected users should assume their older trading profile information may be in circulation and act accordingly.