DriveWealth broker data breach (2026): Revolut / Stake / Hatch US-trading customers: what was exposed and what to do
We publish these pages from public notices and reporting so you can understand what was exposed. Everything here is already public. Always confirm with the organization named in your notice.
Separate from Revolut’s mid-September KYC / fake-government-email incident. This page covers a DriveWealth broker-side security incident. Revolut has stated its own systems and infrastructure were not accessed or compromised here, and that Revolut passwords, passcodes, card details, and ID documents were not exposed in this event. It is a separate incident from the September 2026 Revolut case in which staff answered fraudulent requests styled as government information requests (press reports put that one at about 680 customers). That case involved a different method, different data, and different systems.
What happened
DriveWealth, LLC, a U.S. broker-dealer that provides U.S. securities brokerage, custody, and clearing for introducing brokers and fintech apps, disclosed unauthorized access to personal data in certain of its systems. On its official cyber-response page, DriveWealth says it discovered unauthorized network access occurred between September 4, 2026, and September 5, 2026, that certain personal information was exfiltrated, and that production brokerage/trading systems and the client-facing platform were not impacted. It reports no unauthorized brokerage activity (trades, transfers, withdrawals, ACAT requests, or balance/position alterations) and says it is not aware of identity fraud or improper use of information as a direct result of the incident.
Press coverage quoting DriveWealth customer communications attributes the access to a social-engineering campaign by unknown third parties. DriveWealth’s public cyber-response page confirms the September 4–5 window and exfiltration but does not itself describe the intrusion method. The “social engineering” description comes from customer notices and press reports.
Partner apps were not the breached environment. Introducing brokers and apps that use DriveWealth for U.S. trading have issued parallel customer notices, including:
- Stake (Australia / NZ Wall St): DriveWealth supports U.S. trading and wallet functionality; Stake says its systems, app, and website were not affected (notice dated September 21, 2026).
- Hatch (New Zealand): Hatch says Hatch systems were not accessed; login credentials are held on Hatch systems (help-centre notice).
- Revolut: Customers who used Revolut’s U.S. stock trading (historically via DriveWealth as clearing/broker partner) received notices. Revolut told customers and press that Revolut systems were not accessed or compromised, funds/investments remain safe, and, in Europe, the incident relates to historical records from before Revolut changed its U.S. stock trading model (EEA changes from about December 2023; UK/Australia by about June 2025, depending on market). Revolut said DriveWealth contacted affected customers and Revolut followed up; if you did not receive an email, Revolut says you are not affected.
DriveWealth’s cyber-response page states that approximately 62,000 Rhode Island residents were impacted. That figure is a Rhode Island–resident count from DriveWealth’s notice, not a global census of all DriveWealth customers or of any single partner (Revolut / Stake / Hatch). Do not treat 62,000 as a worldwide total.
Sources
- Cyber Response – DriveWealth Legal Hub (official; Sep 4–5 access window; about 62,000 Rhode Island residents; no passwords/payment cards; no unauthorized brokerage activity)
- DriveWealth Data Security Incident – Stake (Sep 21, 2026; field list including tax-status + portfolio/cash snapshots; Stake systems not affected)
- DriveWealth cybersecurity incident – Hatch Help Centre (official Hatch notice; field list; Hatch systems not accessed)
- Irish Revolut customers impacted by data breach – RTÉ (Sep 24, 2026; Revolut systems not compromised; historical EEA/UK/AU model change; separates mid-September KYC incident)
- DriveWealth breach exposes data of Revolut customers who traded US stocks – The Next Web (Sep 24, 2026; quotes DriveWealth on social-engineering access and field list; cites 62,000 RI figure)
What data was exposed
Fields vary by person and by which introducing broker held the relationship. Cite partner notices accurately; do not invent fields.
Common profile / contact fields (Revolut customer email as reported by RTÉ / The Next Web; consistent with DriveWealth’s “see your individual notice” framing):
- Name
- Email address
- Phone number
- Postal address
- Employment information
- Biographical data such as country of citizenship, age, and gender
- Partial DriveWealth account number
Revolut / DriveWealth notices (as reported) state passwords and financial payment information (credit card or bank account details) were not involved. Revolut separately stated no Revolut passwords, passcodes, card details, or ID documents were exposed in this incident.
Stake (per Stake’s September 21, 2026 notice; may include some or all, person-by-person):
- Name, email, phone, postal address
- W-8 or W-9 tax status and country of taxation (not tax file numbers or other tax identification numbers)
- DriveWealth account number (Stake Wall St account number)
- Aggregate portfolio value snapshot (not individual holdings)
- Cash balance and “buying power” snapshot
Stake says not involved: Stake login credentials/passwords; tax file numbers and government ID numbers; bank account details; identity document details/images; individual security positions or trading history.
Hatch (per Hatch help-centre notice; may have been exposed):
- Name, address, phone number, email address
- Investor profile information (e.g. income range and net asset range)
- Cash balance and portfolio value
Hatch says not involved: Hatch login details; ID documents and their details including date of birth; IRD number and/or foreign tax identifiers; kids-account personal details; other documents such as source-of-wealth or proof-of-address packs. Hatch says customers do not need to change Hatch passwords because of this incident (Hatch requires 2FA).
Inactive / closed accounts can still be in scope where DriveWealth retained records under regulatory retention rules (Stake and Hatch both note this).
Breach details
| Detail | Value |
|---|---|
| Breach name | DriveWealth (U.S. broker; partners include Revolut US-trading, Stake Wall St, Hatch, others) |
| Date | Unauthorized access September 4–5, 2026 (DriveWealth); partner notices around September 21–24, 2026 |
| Disclosed | DriveWealth cyber-response page + partner notices (Stake Sep 21; Hatch around Sep 21–22; Revolut customer emails / press Sep 24) |
| Accounts affected | Global N not published as a single census. DriveWealth notice: about 62,000 Rhode Island residents (state figure only, not global). Partner-specific counts undisclosed. |
| Domain | drivewealth.com / legal.drivewealth.com (partners: revolut.com, hellostake.com, hatchinvest.nz) |
| Method (reported) | Social-engineering campaign per DriveWealth customer notices / press quoting them; official cyber-response confirms Sep 4–5 unauthorized access + exfiltration |
This summary is compiled from public notices and reporting available when this page was last updated. Figures reflect what those sources report and may change as investigations continue. If something here looks wrong or you think your personal data is involved, contact our support team.
We report breaches as a factual record to help people check their exposure. Inclusion here is not an allegation of wrongdoing or negligence by DriveWealth, Revolut, Stake, Hatch, or other introducing brokers; it reflects a publicly reported security incident and subsequent customer notifications.
For whether your personal data was involved and for official remediation offers, rely on notices from DriveWealth and/or the app you used for U.S. trading (or anyone they say will contact you), not this page alone.
What to do now
Based on the data that may have been exposed, here are the steps you should take:
- If you used Revolut, Stake, Hatch, or another app that clears U.S. trades through DriveWealth, check email (and in-app messages) for official notices. Revolut has said: if you did not receive an email about this DriveWealth incident, you are not affected. Prefer links and phone numbers printed in those notices over unsolicited messages.
- Treat unexpected emails, texts, or calls that cite your name, address, trading relationship, tax status, or portfolio/cash figures as likely phishing. DriveWealth, Revolut, Stake, and Hatch say they will not ask for passwords, PINs, or one-time codes, and will not tell you to move money “to keep it safe.”
- Review recent activity on the relevant trading app (holdings, transfers, contact-detail changes). Partners report no unauthorized trading from this incident, but still verify.
- U.S. residents: follow DriveWealth’s individual notice for credit-monitoring enrollment if an SSN was listed for you; DriveWealth’s cyber-response page also points to fraud alerts, freezes, and a response line (1-844-770-4353) / email contacts printed there. Do not assume SSN was in scope for every person. Only your notice settles that.
- Revolut users: changing a Revolut password does not alter historic records already held by DriveWealth. Focus on phishing vigilance for this incident; keep Revolut’s separate KYC/fake-gov email incident guidance distinct if you also received that notice.
- Stake / Hatch: follow the steps on their official incident pages (password reset / 2FA guidance differs: Hatch says password change is not required for this event; Stake still recommends vigilance and optional password reset as hygiene).
Was Revolut, Stake, or Hatch hacked in the DriveWealth story, or can Delist clear this broker dump?
Neither. DriveWealth reported unauthorized access on its broker systems around September 4–5, 2026. Revolut, Stake, and Hatch say their own apps and systems were not compromised. Whether you were included depends on official notices from DriveWealth or the app you used, not a tracker membership check. The 62,000 figure DriveWealth published is Rhode Island residents only, not a global total.
Frequently asked questions
Can Delist remove my data from DriveWealth, Revolut, Stake, Hatch, or this incident’s files?
No. Delist does not scrub broker or fintech-partner systems or this incident’s files. Open-web people-search removal is a separate pipeline.
Is this the same as Revolut’s mid-September KYC / fake-government email case?
No. That was a separate event (press reports put it at about 680 customers) in which staff answered fraudulent requests styled as government requests. It involved a different method and different data.
What should notice recipients do first?
Use the contacts printed in your official DriveWealth or trading-app notice. Treat messages that cite name, address, tax status, or portfolio/cash figures and ask for codes or money moves as phishing. Freeze or enroll in credit monitoring only if your individual notice says an SSN was involved.
What to do after a breach
- A company emailed me about a breach: what should I do?
- Dark web data versus data brokers
- What to do after a data breach
- Got a breach email?
- First 48 hours after a data breach
- Dark web vs. data brokers
A free Delist scan checks open-web exposure we support: people-search sites, public records, data brokers, and breach-source signals. Signals are not live listings, and this is not removing you from a dump, a DMV database, or a vendor's private ID store.
More breaches
Free personal data exposure scan
We search the open web for your personal data and show what’s exposed. The scan is free. Removal and monitoring require a paid plan.