DriveWealth Data Breach Exposed Hatch Customer Details
An unauthorized party gained access to personal information during a security incident at brokerage firm DriveWealth.
Updated on Sept. 21, 2026 in Cybersecurity

Live Poll
Do you trust investment platforms to adequately protect your personal information from data breaches?
Between September 4 and September 5, 2026, an unauthorized party accessed data held on DriveWealth systems. The breach included the personal information of customers using the New Zealand-based investment platform Hatch.
Why it matters
The incident highlights the risks associated with third-party data storage in financial services. Hatch has since warned its users to remain vigilant against potential phishing scams following the unauthorized access.
The incident involved unauthorized access to files stored within DriveWealth systems that contained third-party user data. Hatch confirmed that its own internal systems were not breached during the event.
The players
DriveWealth
DriveWealth is a United States-based brokerage firm that provides clearing and execution services for various investment platforms.
Hatch
Hatch is an investment platform based in New Zealand that allows local users to trade on United States financial markets.
The details
DriveWealth notified Hatch after discovering that an outside party had gained access to data stored on its servers. While Hatch internal infrastructure remained secure, the data exposure puts their customers at risk of identity-related threats.
Timeline
September 4, 2026: Unauthorized access to DriveWealth systems began.
September 5, 2026: The unauthorized activity concluded.
The Tech Race
This incident follows the pattern of supply-chain vulnerabilities recognized by the NIST Cybersecurity Framework, which emphasizes that security is only as strong as a firm's weakest vendor link. It reflects a broader shift where financial platforms must manage the digital security of their clearing partners as closely as their own.
Affected customers should be alert for suspicious emails or messages, as their personal details were included in the exposed dataset. Users are encouraged to update their security settings and monitor financial accounts for any unauthorized activity.
The takeaway
Data security is a shared responsibility that extends beyond a single company to include all third-party service providers. Users should consistently employ multi-factor authentication and treat unexpected communications as potential threats.
Further reading
For more information on protecting your digital assets, visit the Cybersecurity section.
Live Poll
Do you trust investment platforms to adequately protect your personal information from data breaches?







