Community Trust ScoreVerified
A security breach at DriveWealth, a US brokerage infrastructure provider, hit customers of Revolut, Stake, and Hatch on September 4 and 5. Unauthorized access to personal data — and in some cases investment-related records — got through. The damage wasn’t uniform across the three platforms.
DriveWealth said the breach came from a social-engineering campaign. Someone talked their way into the systems, basically. The company confirmed the issue was contained and stressed that no unauthorized trades, transfers, or withdrawals happened as a result. But affected customers are now being warned about phishing and impersonation risks, since real personal data is floating around out there.
What Each Platform Lost
For Revolut users, the exposed data was older. We’re talking historical records — contact details, employment info, basic biographical data, and partial DriveWealth account numbers. Identity documents and payment details weren’t touched. Revolut stopped sending new European Economic Area customer data to DriveWealth back in December 2023 when its operating model changed, so current EEA customers are probably clear. DriveWealth still acts as the clearing broker for Revolut Securities and Revolut Wealth in the US, so the relationship isn’t fully severed — it’s just narrower now.
Stake and Hatch users got hit harder. Hatch customer records may include income ranges, cash balances, and total portfolio values. For Stake users, the exposed data covered tax status, country of taxation, DriveWealth account numbers, and overall portfolio summaries. That’s a more detailed financial snapshot than what Revolut customers lost, and it’s the kind of data that makes phishing attempts more convincing.
Both Stake and Hatch confirmed their own internal systems weren’t touched. The breach stayed inside DriveWealth’s environment.
Social Engineering, Not a Hack
DriveWealth didn’t get cracked through some sophisticated zero-day exploit. It’s a social-engineering story — someone manipulated their way in. The company told its partners the incident was contained fast, and there’s no sign of unauthorized financial activity. Still, “contained” doesn’t mean the data disappeared. Once names, tax statuses, and portfolio summaries are out, they’re out.
Revolut was quick to clarify that the compromised records only covered older data, stuff shared before December 2023. That’s a meaningful distinction — it means the breach doesn’t reflect the current state of Revolut’s customer base in Europe. Customers who signed up or updated their profiles after that model change aren’t in this pool. Whether that’s reassuring depends on how long you’ve been a Revolut customer, and the platform isn’t specifying exactly how many people are affected.
Stake and Hatch, for their part, said they’re working with DriveWealth to tighten things up and prevent future incidents. No details on what that actually looks like in practice. Unclear whether any regulatory notifications beyond customer alerts are planned.
Separate From the Earlier Revolut Incident
Worth being clear here: this DriveWealth breach is a different thing from the earlier Revolut incident that made headlines. In that older case, attackers used a compromised Italian government email account to fraudulently request information directly from Revolut. That breach involved the unauthorized acquisition of Know Your Customer documents and transaction records for roughly 680 Revolut customers. Different method, different data, different scope.
The DriveWealth breach is broader in terms of platforms affected — three companies, not one. But the financial exposure so far seems limited to data theft rather than actual fund movement. DriveWealth is firm on that point.
It’s worth noting that brokerage infrastructure providers sit at a tricky intersection. They power the backend for multiple consumer-facing apps simultaneously, which means a single breach can ripple across platforms that have no direct relationship with each other. Revolut, Stake, and Hatch compete for similar users in some markets. They share a backend provider. And now they share a breach.
Social-engineering attacks on financial infrastructure aren’t new, and they’re not going away. Regulators in multiple jurisdictions have flagged the risk for years. Whether DriveWealth faces any formal scrutiny over this incident hasn’t been confirmed.
Customers on all three platforms are being urged to watch for suspicious emails or messages that reference their real account details — because whoever accessed the data now has enough to make a phishing attempt look legitimate. Stake and Hatch users especially, given the financial data involved.
DriveWealth confirmed no unauthorized financial activity was detected. Stake and Hatch confirmed their own systems were clean. Revolut confirmed the older-data-only scope of its exposure. And all three consumer platforms have pushed notifications to affected users.
The breach dates: September 4 and 5.
Frequently Asked Questions
What personal data was exposed in the DriveWealth breach for Revolut customers?
Revolut customers had historical records exposed, including contact details, employment information, basic biographical data, and partial DriveWealth account numbers. Identity documents and payment details were not compromised.
Were Stake and Hatch customers’ financial details exposed in the DriveWealth breach?
Yes. Hatch customer records may include income ranges, cash balances, and total portfolio values. Stake users had tax status, country of taxation, DriveWealth account numbers, and portfolio summaries exposed.
Why It Matters
This breach underscores the vulnerabilities that exist within the financial technology sector, particularly as companies increasingly rely on third-party service providers for brokerage and trading infrastructure. The incident not only raises concerns about the security of user data across multiple platforms but also highlights the potential risks associated with social engineering tactics, which can undermine consumer trust in digital financial services. As the crypto and broader financial markets continue to evolve, maintaining robust cybersecurity measures will be crucial for protecting user assets and sustaining market confidence.





