In Focus
The data breach occurred on September 4 and 5, 2026
The cyberattack was the result of a social engineering campaign
Revolut said its systems and infrastructure were not affected by the incident
Over 3.4 million people in Ireland use Revolut’s payment service
Personal data belonging to some of Revolut's customers was exposed after DriveWealth was breached. DriveWealth, which is Revolut’s U.S. stock trading partner, said the security incident occurred on September 4 and 5, 2026. The data breach affected Revolut customers in Ireland.
The cyberattack resulted from a social engineering campaign conducted by unknown third parties. The stockbroker said the incident had been reported to the data protection authority in Lithuania.
What Customer Data Was Accessed During the Breach?
DriveWealth said attackers accessed a range of Revolut customer data during the incident. This includes names, phone numbers, email addresses, postal addresses, and gender. Details about their nationality, age, and part of their DriveWealth account numbers were also accessed.
However, the hackers did not gain access to customer payment details like bank account or account numbers or passwords. Revolut, which rose to become Europe’s most valuable startup, informed Irish customers about the incident and maintained that its systems were not affected.
“Revolut’s systems and infrastructure were not accessed or compromised, and customer funds and investments are safe. No Revolut passwords, passcodes, card details or ID documents were exposed,” the fintech firm said, as cited by the Irish Independent.
Revolut is the largest payment service in Ireland. Over 3.4 million people, representing 80% of the adult population in the country, use the company’s platform.
DriveWealth Sent Phishing Attack Warning to Customers
DriveWealth also sent a separate email to customers warning them that they may become targets of phishing attacks.
“As a result of this security incident, there is a potential risk that your personal data could be misused by unauthorised third parties. You may be exposed to phishing attempts (fraudulent emails or messages designed to trick you into revealing sensitive information), identity fraud or impersonation, social engineering aimed at obtaining additional personal or financial information and unsolicited contact from unknown parties,” DriveWealth wrote in the email.
Revolut isn’t the only firm whose data got exposed in DriveWealth’s cyberattack. Brokers such as Australia’s Stake and New Zealand’s Hatch were also affected. For these brokers, the cyberattack exposed data relating to customer portfolio values and cash balances. Stake reportedly informed customers about the incident on September 21, while Hatch did so on September 22.
A Second Security Incident for Revolut
The DriveWealth cyberattack is the second security incident that Revolut has alerted customers about this month. Last week, the British fintech said it was tricked into sharing sensitive customer data with scammers who posed as government officials.
The data included phone numbers, dates of birth, addresses, passport, and driver's licence details. Revolut’s valuation stands at $115 billion. The fintech firm is planning a dual listing in London and New York.
.webp&w=3840&q=75)

.webp&w=750&q=75)
.webp&w=750&q=75)
.webp&w=750&q=75)
.webp&w=750&q=75)