Revolut customers have received breach notifications for the second time in September after a third-party brokerage service was compromised through social engineering. The incident exposed historic personal data retained under regulatory requirements, though no financial credentials or Revolut systems were directly affected.
What happened
DriveWealth, a US-based brokerage providing execution and clearing services, confirmed unauthorized access to customer records on 4 and 5 September. Attackers used a "sophisticated social engineering campaign" to extract data from accounts previously held directly with DriveWealth, including those linked to Revolut’s former US stock trading arrangement. The exposed information includes names, email addresses, phone numbers, postal addresses, employment details, citizenship, age, gender, and partial account numbers. DriveWealth stated that passwords, payment details, and other sensitive financial data were not compromised.
Revolut confirmed that its own infrastructure remained secure, with no exposure of passwords, passcodes, card details, or identity documents. The affected records date from before Revolut migrated customers in the UK, EEA, and Australia away from DriveWealth between December 2023 and June 2025. After migration, personal details were no longer shared with the brokerage.
- Breach occurred on 4–5 September 2026 at DriveWealth
- Exposed data: names, contact details, employment info, partial account numbers
- No passwords, payment details, or Revolut credentials compromised
- Revolut migrated customers away from DriveWealth between Dec 2023 and Jun 2025
- Neither company disclosed the number of affected Revolut customers
Why it matters
The breach highlights persistent risks in third-party data handling, even after service relationships end. DriveWealth retained customer records to comply with regulatory obligations, creating a lingering exposure vector. The stolen data—while not including financial credentials—provides ample material for phishing, identity fraud, or further social engineering attacks. Revolut customers may face targeted scams leveraging their employment history, citizenship, or former account details.
This incident follows a separate breach earlier in September, where Revolut disclosed that criminals obtained sensitive customer information—including passports, driver’s licenses, and transaction data—through fraudulent information requests. The two breaches involved distinct attack methods and datasets, underscoring the challenges fintech firms face in securing customer data across multiple touchpoints.
What to watch
Neither Revolut nor DriveWealth has disclosed the number of affected customers, leaving uncertainty about the scale of potential follow-on attacks. Professionals should monitor for:
- Increased phishing attempts targeting Revolut users, particularly those who previously traded US stocks
- Potential regulatory scrutiny of data retention practices at third-party service providers
- Evolving social engineering tactics exploiting historic account relationships
Revolut has emphasized that customer funds and investments remain secure, but the repeated breach notifications may erode user trust in the platform’s data protection measures.
Companies mentioned
Automated pipeline · Security
Synthesized from 1 industry feed on 25 Sep 2026. Passed independent editor verification (score 95/100) before publication. Style guide v1.4.
Sources
Decision trail
- Checking for duplicates — Deduped batch of 1 candidates
- Checking for duplicates — Failed no verdict returned
- Checking for duplicates — Deduped batch of 1 candidates
- Checking for duplicates — Failed no verdict returned
- Checking for duplicates — Deduped batch of 2 candidates
- Checking for duplicates — New story No recent or in-pipeline article covers a Revolut-related breach.
- Checking for duplicates — New story pre_write:; No recent or in-pipeline article covers a Revolut-related data breach.
- Writing the article — Draft created article_id=600 slug=revolut-customers-hit-by-second-data-breach-in-september
-
Editor review — Approved
- Score: 95/100
- Factual grounding: The draft states the breach occurred on '4 and 5 September' without clarifying if this is the confirmed event date or the detection date. Source 1 states 'unauthorized access occurred on September 4 and 5' but does not specify if this is the intrusion window or detection. This is a minor ambiguity, not a material error.
- Style compliance: The standfirst uses 'historic' to describe the records, which is correct but slightly echoes Source 1's phrasing ('historic personal information'). While not copied, the term could be paraphrased further (e.g., 'legacy records').
- Audience relevance and notability: The story is relevant to hosting/domains/DNS/email professionals due to its focus on third-party data handling risks and social engineering, but the connection is tangential. The primary audience is fintech, not infrastructure operators. However, the takeaway on third-party risk is defensible for the trade.
- Generating reader Q&A — Generated 4 items
- Assigning hero image — Reused library image reused image #8
- Linking related stories — Linked 3 relations from 335 candidates
- Publishing — Published revolut-customers-hit-by-second-data-breach-in-september
- Mastodon — Posted https://mstdn.social/@hostingpaper/117332009427515073




Discussion · coming soon
Be the first to join the thread when community discussion launches.