DriveWealth Data Breach Exposed Hatch Customer Details

An unauthorized party gained access to personal information during a security incident at brokerage firm DriveWealth.

Updated on Sept. 21, 2026 in Cybersecurity

Isometric editorial illustration of a modular data storage block in shades of oxblood, teal, and slate blue, representing digital financial infrastructure.
Brokerage firm DriveWealth reported a security breach between September 4 and 5, 2026, which exposed personal customer information from the investment platform Hatch. AI Illustration. Upload story photo >

Live Poll

Do you trust investment platforms to adequately protect your personal information from data breaches?

Between September 4 and September 5, 2026, an unauthorized party accessed data held on DriveWealth systems. The breach included the personal information of customers using the New Zealand-based investment platform Hatch.

Why it matters

The incident highlights the risks associated with third-party data storage in financial services. Hatch has since warned its users to remain vigilant against potential phishing scams following the unauthorized access.

The incident involved unauthorized access to files stored within DriveWealth systems that contained third-party user data. Hatch confirmed that its own internal systems were not breached during the event.

The players

DriveWealth

DriveWealth is a United States-based brokerage firm that provides clearing and execution services for various investment platforms.

Hatch

Hatch is an investment platform based in New Zealand that allows local users to trade on United States financial markets.

The details

DriveWealth notified Hatch after discovering that an outside party had gained access to data stored on its servers. While Hatch internal infrastructure remained secure, the data exposure puts their customers at risk of identity-related threats.

Timeline

  1. September 4, 2026: Unauthorized access to DriveWealth systems began.

  2. September 5, 2026: The unauthorized activity concluded.

The Tech Race

This incident follows the pattern of supply-chain vulnerabilities recognized by the NIST Cybersecurity Framework, which emphasizes that security is only as strong as a firm's weakest vendor link. It reflects a broader shift where financial platforms must manage the digital security of their clearing partners as closely as their own.

Affected customers should be alert for suspicious emails or messages, as their personal details were included in the exposed dataset. Users are encouraged to update their security settings and monitor financial accounts for any unauthorized activity.

The takeaway

Data security is a shared responsibility that extends beyond a single company to include all third-party service providers. Users should consistently employ multi-factor authentication and treat unexpected communications as potential threats.

Further reading

For more information on protecting your digital assets, visit the Cybersecurity section.

Live Poll

Do you trust investment platforms to adequately protect your personal information from data breaches?

DriveWealth Data Breach Exposed Hatch Customer Details