Home · Wiki · Incidents & Campaigns
type: incident · created: 2026-09-25 · updated: 2026-09-25 · tags: [incident, financial-services] · confidence: high · severity: low · affected_sectors: [financial-services] · au_impact: true

Revolut customers were affected by a security incident at DriveWealth, the US broker that handles share trading for Revolut users, which told customers it discovered unauthorised network access over a two-day period in September following "a sophisticated social engineering campaign". Stolen data is described as historic personal information — names, email and postal addresses, phone numbers and employment details — with DriveWealth stating it has no reason to believe passwords or payment data were involved. Revolut says it is in direct communication with DriveWealth to establish the exact scope. The exposure is limited by an earlier architecture change: Revolut says it stopped sharing individual customer details with DriveWealth between December 2023 and June 2025 depending on market, so customers in the affected markets are unaffected from that point. The incident follows Revolut's ~11 September admission that it released sensitive customer information, including passports, after fraudulent requests arrived from a legitimate government email domain, with attackers claiming data on 680 high-net-worth crypto accounts.

Attribute Detail
Sector Financial Services
Date 2026-09-25
Source Finextra
Reliability Tier 2