Revolut customers, including thousands in Ireland, faced their second data incident this month. This time, a third-party provider, not Revolut’s own systems, was responsible.
DriveWealth, the US broker that previously handled US stock trading for Revolut users, confirmed the breach occurred on September 4 and 5.
What Actually Happened at DriveWealth
A social engineering attack manipulates people into revealing sensitive information, rather than exploiting a technical software flaw directly. DriveWealth confirmed that’s exactly how attackers gained unauthorized network access this time.
The exposed data covers only historical customer records from before Revolut changed its trading model. In the European Economic Area, including Ireland, that cutoff fell in December 2023. Revolut stopped sharing individual customer details with DriveWealth after that switch, so recent users remain unaffected.
Exposed information may include names, email addresses, phone numbers, postal addresses, employment details, and biographical data like citizenship, age, and gender. Partial DriveWealth account numbers were also affected.
Passwords, payment card details, bank information, Revolut passcodes, and identity documents were not compromised. A Revolut spokesperson confirmed DriveWealth contacted affected customers directly, with Revolut following up through its own emails.
Why Does This Keep Happening to Revolut Customers?
This breach follows a separate incident earlier in September, when a sophisticated impersonation scam using a legitimate Italian government email domain tricked Revolut into releasing sensitive data. That case affected roughly 680 customers globally and involved identity documents.
The breach also reached beyond Revolut. Stake and Hatch, two other platforms using DriveWealth’s infrastructure, confirmed similar exposure.
Neither Revolut nor DriveWealth has disclosed exact numbers of impacted customers. Revolut serves approximately 3.4 million customers in Ireland alone.
Affected users should monitor communications, watch for phishing attempts, and contact Revolut through official channels with concerns. Two breaches in one month highlight growing risk tied to third-party fintech infrastructure.
Read the Original story Revolut Customers Hit by Second Data Breach in Just One Month by Luis Blanco at beincrypto.com