DriveWealth Data Breach Exposed Wio Invest Customer Info
The incident compromised personal details of clients but did not lead to unauthorized trading or account access.
Updated on Oct. 6, 2026 in Cybersecurity

Live Poll
Do you trust that your personal financial data is secure when shared with third-party investment services?
Between September 4 and September 5, 2026, unauthorized actors accessed the DriveWealth network, exposing sensitive personal data of Wio Invest customers. The breach impacted information ranging from contact details to employment and investment experience.
Why it matters
The incident highlights the risks inherent in third-party brokerage partnerships where sensitive customer data is stored for regulatory compliance. By notifying the UAE Capital Market Authority, Wio Invest sought to address the systemic exposure of client information.
The unauthorized access compromised names, email addresses, phone numbers, home addresses, employment details, and investment experience. Systems confirmed that passwords, login credentials, bank accounts, and identity documents were excluded from the exposure.
The players
DriveWealth
DriveWealth is a financial technology company that operates as an executing broker and maintains customer information for firms.
Wio Invest
Wio Invest is a digital investment platform based in the United Arab Emirates.
UAE Capital Market Authority
The UAE Capital Market Authority is the government regulator responsible for overseeing financial markets and institutions in the region.
The details
DriveWealth, which serves as the executing broker for Wio Invest, maintained the data for regulatory compliance before the unauthorized actors removed it during the two-day window. While a snapshot of US portfolio values from September 4, 2026, was accessed, cybersecurity specialists found no evidence of trades or withdrawals.
Timeline
The breach and the portfolio snapshot occurred on September 4, 2026.
The unauthorized access to the network lasted from September 4 to September 5, 2026.
The Tech Race
This event follows a pattern set by the 2023 MoveIT data breach regarding third-party vendor risk. It underscores a growing reliance on interconnected brokerage systems and the inherent security challenges for firms managing international financial data.
Impacted customers may face an increased risk of targeted phishing attempts due to the exposure of their contact information and employment details. Users are encouraged to remain vigilant for suspicious communications and monitor their financial accounts for any unusual activity.
The takeaway
While no financial loss was detected, the incident serves as a reminder for investors to utilize multi-factor authentication across all financial platforms. Customers should remain proactive in updating their security settings whenever a data breach is disclosed by their brokerage or service provider.
Further reading
For broader insights on protecting digital assets, visit our Cybersecurity section.
Source note: This article includes information reported by Arabianbusiness.
Live Poll
Do you trust that your personal financial data is secure when shared with third-party investment services?







