Connect with us

Hi, what are you looking for?

Science&Tech News

DriveWealth Blames Social Engineering Campaign for Revolut…

What Happened at DriveWealth?

Revolut customers have been caught up in another security incident after U.S. broker DriveWealth confirmed unauthorized access to its network, exposing historical personal information belonging to some users of Revolut’s U.S. share-trading service.

DriveWealth, which has provided U.S. brokerage services for Revolut customers, said attackers gained access to its network over a two-day period in September through what it described as a “sophisticated social engineering campaign.”

The compromised information may include customer names, email addresses, postal addresses, telephone numbers and employment information. DriveWealth said it currently has no reason to believe passwords or financial payment information, including credit card and bank account details, were involved.

Revolut told affected customers that it is “in direct communication with the DriveWealth team to confirm the exact scope of the incident.”

The incident did not involve an intrusion into Revolut’s own systems. For European customers, the affected information relates to historical records created before Revolut changed the structure of its U.S. stock-trading service. Those changes were implemented between December 2023 and June 2025 depending on the market, after which Revolut says individual customer details in those jurisdictions were no longer shared with DriveWealth.

Why Does Historical Customer Data Still Matter?

The age of the records limits some immediate risks, but it does not make the information harmless. Names, addresses, telephone numbers, email addresses and employment details can still be useful for phishing, impersonation and targeted social-engineering attacks long after a customer relationship or data-sharing arrangement changes.

That makes the incident primarily a data-security issue rather than a threat to customer balances. Revolut says no passwords or payment credentials were exposed through the DriveWealth breach, while there has been no indication that customer investments or funds were accessed.

It also illustrates the security exposure created by fintech partnerships. Companies such as DriveWealth provide the brokerage infrastructure that allows consumer platforms to offer investment products without building every part of the securities operation themselves. FinanceFeeds has previously covered how DriveWealth has expanded its brokerage infrastructure and risk operations as its partner network has grown.

Investor Takeaway

The latest incident does not indicate that Revolut’s banking systems or customer funds were compromised. The more important issue is third-party risk: customer information can remain exposed through external service providers even after the original data-sharing relationship has changed.

How Is This Different From Revolut’s Earlier Data Exposure?

The DriveWealth incident is separate from the customer-data exposure Revolut disclosed earlier this month.

In that case, attackers did not gain direct access to Revolut’s internal infrastructure. Instead, fraudulent information requests were sent from a legitimate government agency email domain, leading Revolut personnel to disclose sensitive customer records to an unauthorized party.

The earlier incident involved substantially more sensitive information, including identity documents such as passports and driving licences as well as customer contact and account information. Subsequent reporting put the number of affected customers at 680 and prompted an investigation by the UK’s Information Commissioner’s Office.

Hackers claiming responsibility later demanded approximately $3 million in Monero and threatened to sell the stolen information. The deadline eventually expired with no independently confirmed sale of the customer database.

There is no evidence that the DriveWealth incident and the earlier Revolut exposure are connected. Their attack methods also differ: the first involved fraudulent government requests directed at Revolut, while DriveWealth says its own network was accessed following a social-engineering campaign.

Why Is the Second Incident a Bigger Trust Test for Revolut?

Two separate customer-data incidents surfacing within weeks of each other create a reputational problem even when Revolut itself was not technically breached in the latest case.

Customers generally experience a financial platform as a single service, even when brokerage, custody, payments and other functions are provided through outside companies. That means security failures at a partner can still affect confidence in the primary brand.

The immediate question is therefore not whether Revolut customer funds are at risk. The available information says they are not. The issue is whether Revolut and its external providers can establish exactly which historical records were accessed, notify everyone affected and limit the chances that stolen personal information is later used for targeted fraud.

The DriveWealth breach also shows why changing providers or data-sharing structures does not instantly eliminate historical exposure. Old records may remain with regulated service providers after a commercial relationship changes, leaving customer data dependent on security controls outside the platform customers currently use.

For Revolut, the next test is disclosure rather than service availability: establishing the scale of the DriveWealth incident, explaining which customers are affected and showing that two separate September security events do not point to a wider weakness across its partner network.

You May Also Like

World News

US Secretary of State Marco Rubio will discuss the possibility of deporting suspected Tren de Aragua gang members to El Salvador in an upcoming...

Crypto News

Stablecoins:- India’s digital payments leadership is reshaping global finance. Yet, one layer remains stuck in inefficiency: cross-border transactions. Remittances and trade payments still rely...

Crypto News

While the emergence of the concept of cryptocurrency generated a lot of interest within the crypto community, times became tough when the “proof-of-work” consensus...

Crypto News

Trends:- A former Find Satoshi Lab (FSL) leader Mable Jiang has announced the launch of a new social protocol project – called Trends. The...