DriveWealth Data Breach: What Happened and Who's Affected
DriveWealth, the broker behind Revolut and Hatch US stock trading, confirmed names and other personal data were stolen in a September 2026 network breach.

DriveWealth, the brokerage-as-a-service firm that powers US stock trading for fintech apps including Revolut, Hatch, and Stake, has confirmed a data breach in which an unauthorized party accessed its network between September 4 and September 5, 2026, and exfiltrated customers' names along with other personal data elements. DriveWealth contained the intrusion on September 5, finished a document review on September 28, and began mailing notification letters in early October, with a sample filed with the California Attorney General's office on September 30.
What happened
In a notice filed with the California Attorney General, DriveWealth, LLC said it "discovered unauthorized access to our network that occurred between September 4, 2026 and September 5, 2026." The company says it launched an investigation with outside cybersecurity professionals, confirmed the compromise was contained on September 5, and has "not observed further unauthorized activity to date." A comprehensive investigation and document review concluded on September 28, 2026, after which DriveWealth determined that customers' full names and additional data elements had been taken from its network.
DriveWealth is not a consumer-facing brand. It is a "brokerage-as-a-service" infrastructure provider: more than 150 fintech apps, brokers, and advisors plug into its platform to offer US equities trading, and customers typically hand their personal information to an introducing broker-dealer, registered investment advisor, or partner app — not to DriveWealth directly. That is why the breach surfaced publicly through DriveWealth's partners rather than through DriveWealth's own consumer channels: Revolut, the New Zealand investing app Hatch, and Australia's Stake each separately notified their own users that data held on DriveWealth's systems may have been exposed.
- What happened: Unauthorized access to DriveWealth's network, Sept. 4–5, 2026
- Contained: Sept. 5, 2026; investigation/document review concluded Sept. 28, 2026
- Data taken: Full names and other personal data elements; DriveWealth says no passwords and no financial payment data (card or bank account numbers) were compromised
- No trading impact: No unauthorized trades, transfers, withdrawals, ACAT requests, or balance/position changes identified
- Confirmed official count: Approximately 62,074 Rhode Island residents, per DriveWealth's notice; the company has not published a total nationwide figure
- Partners affected: Revolut, Hatch, and Stake customers who used DriveWealth's US brokerage infrastructure
Why a breach at a company you've never heard of matters
Most people affected by this breach have never opened a "DriveWealth" account and may not recognize the name at all. That's by design: DriveWealth operates as invisible infrastructure behind the scenes of dozens of consumer-facing investing apps. According to DriveWealth's own site, its APIs power US equities, ETF, options, mutual fund, and fixed-income trading for more than 150 fintechs, brokers, and advisors worldwide, including well-known names like Revolut, Hatch, Stake, MoneyLion, and Toss. When a customer of one of those apps buys a US stock, the trade is frequently executed and custodied through DriveWealth's broker-dealer infrastructure, even though the customer never interacts with DriveWealth directly.
That "brokerage-as-a-service" model is efficient for fintech companies that don't want to build and license their own broker-dealer, but it also means a single infrastructure breach can ripple out to the customer bases of many unrelated consumer brands at once, each of which has to issue its own notification while pointing back to DriveWealth as the source of the exposure. It also means affected customers can be caught off guard: the notification may arrive branded as a DriveWealth letter even though the recipient has only ever heard of the trading app they actually signed up with, which is part of why this breach has fueled confusion and both DriveWealth and Revolut have had to explicitly warn customers about scam messages impersonating the breach notice itself.
Timeline of the DriveWealth breach
- September 4–5, 2026: An unauthorized party accesses DriveWealth's network.
- September 5, 2026: DriveWealth says it contained the compromise; no further unauthorized activity has been observed since.
- September 21, 2026: Stake begins notifying its Australian customers about the incident.
- September 22, 2026: Hatch notifies its New Zealand customers that their data, held by DriveWealth, may have been affected.
- September 28, 2026: DriveWealth's "comprehensive investigation and document review" concludes, identifying the specific data taken.
- September 30, 2026: DriveWealth files a sample notification letter with the California Attorney General's office.
- Early October 2026: DriveWealth and its partners, including Revolut, begin mailing and emailing notification letters to affected individuals in the US and elsewhere.
Who is affected
DriveWealth's own letter, a redacted copy of which is posted on the California Attorney General's data breach list, states that the company received affected individuals' personal information "through an introducing broker dealer, registered investment advisor, or other financial institution" so it could open a brokerage account on their behalf. In practical terms, that means anyone who used a DriveWealth-powered trading feature at a partner app — current or former — could be included, even if they closed their account years ago, since US recordkeeping rules require brokers to retain certain customer data for a set period.
In its own help center notice, Revolut told customers that DriveWealth reported an unauthorized party accessed customer data on DriveWealth's systems and that Revolut's own systems were not affected; it said affected customers would receive separate notification emails from both DriveWealth and Revolut. Hatch likewise said its own systems were not breached, but that client data DriveWealth holds on Hatch's behalf may have been affected, with potentially exposed records including contact details, income ranges, net-asset ranges, cash balances, and total portfolio values for Hatch users specifically.
The only affected-population figure DriveWealth has made public through an official filing is a state-specific one: its notice states that "approximately 62,074 Rhode Island residents were impacted." DriveWealth's letter also includes state-specific notices for residents of California, Iowa, Maryland, Massachusetts, New Mexico, New York, North Carolina, Oregon, and Washington D.C., indicating the notification went out broadly across the US — but the company has not published a single nationwide total. Some secondary reports, citing a separate state filing, have put the nationwide count at well over a million, and have described Social Security numbers as part of the exposure; Pandromeda could not independently confirm those figures against an official company filing, and DriveWealth's own notice to US consumers makes credit-monitoring enrollment contingent on whether a Social Security number was affected — language that implies SSNs were exposed for at least some, though not necessarily all, recipients. Readers should treat the 62,074 figure, and the "no passwords, no payment card or bank data" assurance, as the confirmed facts, and any larger nationwide number circulating online as unverified until DriveWealth or a state regulator publishes one.
| Detail | What DriveWealth says |
|---|---|
| Unauthorized access window | September 4–5, 2026 |
| Containment date | September 5, 2026 |
| Investigation/document review concluded | September 28, 2026 |
| Data confirmed taken | Full names plus other personal data elements (not itemized in the public redacted notice) |
| Data confirmed NOT taken | Passwords; financial payment information (credit card or bank account numbers) |
| Trading/account activity | No unauthorized trading, transfers, withdrawals, ACAT requests, or balance/position changes identified |
| Confirmed official affected count | ~62,074 Rhode Island residents (no nationwide total published) |
| Remedy offered | 12 months of complimentary Triple Bureau credit monitoring/credit report services via Cyberscout, a TransUnion company; enroll within 90 days of the letter date |
How the breach happened
DriveWealth's public notice does not describe the technical method of intrusion. The company characterizes it only as "unauthorized access to our network," investigated with the help of outside cybersecurity professionals, and says no further unauthorized activity has been observed since containment on September 5. DriveWealth has not published a root-cause summary (for example, whether the access stemmed from compromised credentials, a social-engineering campaign, or a software vulnerability), and no such detail appears in its filing with the California Attorney General or in the FAQ page it has set up for US customers.
What the company has been specific about is what its investigation ruled out. DriveWealth says its production trading systems and client-facing platform were not affected, and that it found no evidence of unauthorized trading, transfers, withdrawals, ACAT (account transfer) requests, or changes to account balances or positions. In other words, the exposure DriveWealth has confirmed is a data-theft incident involving personal information, not a breach of the trading systems themselves or of customers' holdings.
What each partner app has told its customers
Because DriveWealth sits behind multiple consumer brands, the specifics each brand has shared with its own users vary slightly, depending on what data that brand's customers had on file with DriveWealth:
- Revolut: Told customers that DriveWealth reported unauthorized access to customer data on DriveWealth's systems, and that Revolut's own systems were not affected. Revolut said affected customers would receive two separate emails — one from DriveWealth, one from Revolut — and that anyone who didn't receive these emails is not affected. The exposure for Revolut's historical US stock-trading customers reportedly includes contact details, employment information, and a partial DriveWealth account number, in addition to identifiers like name and date of birth.
- Hatch: Said its own systems were not compromised, but that client data held by DriveWealth on Hatch's behalf may have been affected, including contact information along with income ranges, net-asset ranges, cash balances, and total portfolio values. Hatch said login credentials were not affected because those are held in Hatch's own systems. Customers with closed Hatch accounts may also be included, since DriveWealth is required to retain certain brokerage records for a set period under US financial regulations.
- Stake: Among the first to notify its customers, in late September, pointing back to the same underlying DriveWealth incident.
Across all three, the consistent message is the same as DriveWealth's own: no login credentials or passwords were taken, no payment card or bank account data was taken, and no unauthorized trading or money movement has been identified.
DriveWealth's response
DriveWealth says it is not aware of any reports of identity fraud or improper use of information as a direct result of the incident. It is offering affected individuals 12 months of complimentary Triple Bureau Credit Monitoring and Triple Bureau Credit Report services, delivered through Cyberscout, a TransUnion company that specializes in fraud assistance and remediation. Recipients of the letter have 90 days from the date on their notice to enroll using the unique code printed in their letter. DriveWealth has also set up a dedicated response line, open Monday through Friday from 8:00 a.m. to 8:00 p.m. ET, and directs questions to its own cyber-response information page.
What affected users should do next
If you've ever used a DriveWealth-powered trading feature inside an app like Revolut, Hatch, or Stake — even an account you closed years ago — treat any notification email or letter from DriveWealth or your app as real, but verify it carefully before clicking anything:
- Confirm you were notified, not just affected by rumor. Revolut has said affected customers will receive two separate emails, one from DriveWealth and one from Revolut itself; if you haven't received one, check your spam folder before assuming you're clear.
- Enroll in the free credit monitoring within 90 days of the date on your letter, using the unique code it provides, via the instructions in your notice.
- Place a fraud alert or security freeze with Equifax, Experian, and TransUnion — both are free and the three bureaus will cross-notify each other once one is in place.
- Pull your free credit reports at annualcreditreport.com and review them for accounts or inquiries you don't recognize.
- Watch your brokerage statements for any trading, transfer, or withdrawal activity you didn't initiate, even though DriveWealth says none has been identified so far.
- Be alert to phishing. DriveWealth and Revolut both warn that neither company will ever ask for your passcode or tell you to move money to another account — treat any message that does as a scam. If you want a refresher on how these scams work, see Pandromeda's social engineering explainer.
- Use a password manager and enable multi-factor authentication on your brokerage and banking apps if you haven't already; this password manager comparison can help you pick one.
- If you suspect identity theft, file a report at identitytheft.gov or call the FTC at 1-877-438-4338, and keep a copy of any police report for your records.
If you want a broader sense of what's exposed about you across past breaches, Pandromeda's guide to password managers and a rundown of identity-theft protection services are good next reads alongside monitoring your DriveWealth-related accounts specifically.
Frequently asked questions
What happened in the DriveWealth data breach?
DriveWealth, a brokerage infrastructure firm used by fintech apps like Revolut, Hatch, and Stake, discovered unauthorized access to its network between September 4 and 5, 2026. It contained the intrusion on September 5, and a document review completed September 28 confirmed that customers' full names and other personal data elements were taken.
Was my Social Security number or bank information stolen?
DriveWealth says no passwords and no financial payment information, such as credit card or bank account numbers, were compromised. However, its US consumer notice ties free credit monitoring enrollment to whether a Social Security number was affected, which suggests SSNs were exposed for at least some recipients. The company has not published an itemized list of exactly which data elements were taken for which customers.
How many people are affected?
The only official figure DriveWealth has disclosed is state-specific: approximately 62,074 Rhode Island residents, according to its breach notice. The company has not published a total nationwide count. Some media reports citing a separate state filing describe a much larger population, but Pandromeda could not verify that figure against an official company filing.
I trade US stocks through Revolut, Hatch, or Stake — am I affected?
You may be. DriveWealth provides the US brokerage infrastructure behind all three apps. Revolut says affected customers will receive two separate notification emails, one from DriveWealth and one from Revolut; if you haven't received either, check your spam folder. Hatch and Stake have issued similar notices to their own affected customers.
Is my brokerage account or money at risk?
DriveWealth says its investigation found no unauthorized trading, transfers, withdrawals, ACAT requests, or changes to account balances or positions. The company says it is not aware of any identity fraud or misuse of information linked to this incident so far.
What should I do if I'm affected?
Enroll in the complimentary 12-month credit monitoring within 90 days using the code in your letter, consider a fraud alert or credit freeze with Equifax, Experian, and TransUnion, watch your brokerage and bank statements, and be alert for phishing messages impersonating DriveWealth or your trading app.
Sources
- DriveWealth Notice of Data Breach (filed with the California Attorney General)oag.ca.gov
- California Attorney General - Data Security Breach report: DriveWealthoag.ca.gov
- DriveWealth Cyber Response (US customers)legal.drivewealth.com
- Revolut Help Center: DriveWealth security incidenthelp.revolut.com
- DriveWealth - official sitedrivewealth.com
- Identitytheft.gov (FTC)identitytheft.gov
Sana Qureshi runs the security and privacy desk. She reports on actively exploited vulnerabilities, vendor patches and data breaches, and covers the password managers, VPNs and authentication tools readers use to protect themselves. Her alerts cite vendor advisories, CISA and the CVE record directly.

