DriveWealth Data Breach Compromised Customer Records

An unauthorized party accessed historical Revolut user data stored by DriveWealth in early September.

Updated on Oct. 2, 2026 in Cybersecurity

Bold vector editorial illustration of a single metallic data server unit in teal and slate blue, representing cybersecurity vulnerabilities.
DriveWealth confirmed that an unauthorized party accessed its network between September 4 and September 5, 2026, exposing historical records of Revolut customers. AI Illustration. Upload story photo >

Live Poll

Do you still trust financial platforms after they experience data breaches via third-party partners?

DriveWealth confirmed an unauthorized party accessed its network between September 4 and September 5, 2026, exposing historical records of Revolut customers. The breach, which was disclosed to the California Attorney General on September 30, involved personal information but did not compromise payment data or passwords.

Why it matters

DriveWealth retained these older records due to legal and regulatory obligations, illustrating the security risks inherent in long-term data storage. The incident highlights the vulnerability of third-party financial service providers to targeted social engineering campaigns.

The exposed dataset included names, contact information, citizenship, and partial account numbers. While this affected historical records, Revolut systems and infrastructure were not accessed during the event.

The players

DriveWealth

DriveWealth is a brokerage-as-a-service company that provides digital investment infrastructure to various financial technology firms.

Revolut

Revolut is a global neobank and financial technology company that provides banking, currency exchange, and investment services to millions of customers.

California Attorney General

The California Attorney General is the chief law enforcement officer of California responsible for receiving formal data breach notifications under state law.

The details

The breach occurred after an unauthorized party utilized a social engineering campaign to gain access to the DriveWealth network. The firm contained the compromise on September 5 and subsequently completed a comprehensive document review to identify the scope of exposed information.

Timeline

  1. September 4, 2026: An unauthorized party gained access to the DriveWealth network.

  2. September 5, 2026: The company contained the network compromise.

  3. September 14, 2026: A separate, unrelated data breach involving Revolut customer information was reported.

  4. September 28, 2026: DriveWealth concluded its internal investigation and document review.

  5. September 30, 2026: The breach was officially disclosed to the California Attorney General.

The Tech Race

The incident follows the transparency requirements mandated by the California Consumer Privacy Act, which ensures consumers are notified of data incidents. This reflects a broader trend of increased regulatory scrutiny regarding how financial service providers manage legacy data and third-party security.

Affected customers are advised to monitor their accounts for suspicious activity despite passwords and payment information remaining secure. Those impacted have a 90-day window to activate the 12 months of credit monitoring services offered by the company to mitigate potential identity theft risks.

The takeaway

Companies should perform regular data audits to minimize the retention of historical records that no longer serve a core business function. Consumers should utilize credit monitoring services immediately following any notice of personal data exposure to protect their financial identity.

What happens next

Affected customers have 90 days from October 1, 2026, to enroll in 12 months of complimentary credit monitoring services provided by the company.

Further reading

For more information on current trends, visit our Cybersecurity section.

Source note: This article includes information reported by Beinsure: Insurance & InsurTech Media Market Intelligence Platform.

Live Poll

Do you still trust financial platforms after they experience data breaches via third-party partners?