Skip to content
Another week, another data breach for Revolut customers

Another week, another data breach for Revolut customers

Theregister • September 25, 2026

DriveWealth coughs up historic customer info after attackers socially engineer their way inside

Someone went shopping in ASUS's eShop – for customer data 19 hours ago

Someone went shopping in ASUS's eShop – for customer data

Academic publisher Elsevier hit by LAPSUS$ redirect attack 1 day ago

Academic publisher Elsevier hit by LAPSUS$ redirect attack

Whisky merchant Master of Malt confirms customer data spilt 2 days ago

Whisky merchant Master of Malt confirms customer data spilt

Cybercrooks trawl Fishbrain to net password hashes 21 days ago

Cybercrooks trawl Fishbrain to net password hashes

Australian hotel chain leaks guests’ PII after breach at third-party database operator August 19, 2026

Australian hotel chain leaks guests’ PII after breach at third-party database operator

Revolut customers have been caught up in a second data breach this month after attackers socially engineered their way into US brokerage DriveWealth and stole historic personal information.

DriveWealth provides execution and clearing services for investment firms and previously held brokerage accounts directly for Revolut customers trading US stocks. It said the unauthorized access occurred on September 4 and 5.

In an email sent to affected customers and seen by The Register , the broker blamed a "sophisticated social engineering campaign" carried out by unknown third parties.

The intruders exfiltrated data retained from the period when those customers held accounts directly with DriveWealth. The broker said regulatory requirements obliged it to keep the records.

The potentially exposed haul includes names, email addresses, phone numbers, postal addresses, employment information, country of citizenship, age, gender, and partial DriveWealth account numbers.

DriveWealth said it had no reason to believe any other personal information was affected. Passwords and payment information, including credit card and bank account details, were not compromised.

Even so, the exposed details would provide ample material for a convincing phishing message. DriveWealth warned customers that the stolen information could potentially be used for identity fraud, impersonation, further social engineering, or unsolicited from strangers.

Revolut customers are among those affected, with the records dating from its arrangement with DriveWealth, the company confirmed to the Irish Examiner .

Revolut said its systems and infrastructure were not compromised, and that customer funds and investments remained safe. No Revolut passwords, passcodes, card details, or identity documents were exposed.

The data is a hangover from Revolut's former arrangement for customers trading US stocks. The fintech moved customers in the UK, EEA, and Australia away from that arrangement between December 2023 and June 2025, with the timing varying by market. Their personal details were no longer shared with DriveWealth after the respective migrations.

DriveWealth contacted affected customers directly, while Revolut sent its own notifications. Neither company has disclosed how many Revolut customers were affected, and both failed to answer The Register's questions.

The breach comes at an awkward time for Revolut. On September 14, the fintech admitted it had handed sensitive customer information to criminals after they submitted fraudulent information requests using an email domain belonging to a legitimate government agency.

That separate incident potentially exposed more sensitive information, including passports, driver's licenses, verification selfies, dates of birth, addresses, phone numbers, email addresses, and financial and transaction data.

Revolut said at the time that it had fallen victim to a "sophisticated external impersonation scam" and that only a limited number of customers were affected.

Two different incidents, two different sets of attackers, and two different routes to customer data. For Revolut customers, September has provided more breach notifications than anyone would want from their banking app. ®

Dyfed-Powys Police cops to cyberattack, staff data potentially nicked

Force says public data appears untouched, but investigators looking into whether crims grabbed employee information

Another week, another data breach for Revolut customers

DriveWealth coughs up historic customer info after attackers socially engineer their way inside

Huawei Cloud Rolls Out Enterprise AI Products Across the Board, Building an Open Agentic Cloud

PARTNER CONTENT: Huawei Cloud strengthens the silicon bedrock on the cloud

Judge uses electronic tag on Pokémon card tracker. It's super effective!

Ohio man planted a device on a delivery van to follow scarce trading card stock and caught a year of probation

In the age of AI, teaching networking principles remains more important than learning protocols

Kids can learn why BGP matters in a semester, but that won’t leave them ready to implement it

Your files are in four places and nobody knows which one is right

Joe Fay chairs a Register dinner on the file infrastructure nobody has got round to replacing, under the Chatham House Rule.

Anthropic decides to support OpenAI's markdown instructions spec

Anthropic decides to support OpenAI's markdown instructions spec

Microsoft agentically ports Copilot runtime to Rust for $120K

Microsoft agentically ports Copilot runtime to Rust for $120K

KPMG tech cuts come with a severance sum some staff call insulting

KPMG tech cuts come with a severance sum some staff call insulting

on call Techie fixed Wi-Fi dead zone with a drill

Techie fixed Wi-Fi dead zone with a drill

ShinyHunters claims FBI hack: 'This is NOT financially motivated'

ShinyHunters claims FBI hack: 'This is NOT financially motivated'

Researchers find way to listen in on headphones from afar

Researchers find way to listen in on headphones from afar

Google's TPUs to catch some rays in orbit week Part of Project Suncatcher, the proof of concept aims to see how well lightly modified compute fares in orbit

Google's TPUs to catch some rays in orbit week

Part of Project Suncatcher, the proof of concept aims to see how well lightly modified compute fares in orbit

Meta's new AI fidget is a ... Tamagotchi? We hope Zuck's Muse Charm doesn't die if you neglect it

Meta's new AI fidget is a ... Tamagotchi?

We hope Zuck's Muse Charm doesn't die if you neglect it

CVE flood pushes Ubuntu onto weekly kernel release cycle AI-assisted bug hunting is helping pile up vulnerabilities faster than defenders can patch them, so Canonical is picking up the pace

CVE flood pushes Ubuntu onto weekly kernel release cycle

AI-assisted bug hunting is helping pile up vulnerabilities faster than defenders can patch them, so Canonical is picking up the pace

Google to critical infra orgs: Our AI scanners won't be evil, promise Gemini 3.8 Flash Cyber and Wiz's Red Agent team up to protect hospitals, public transit, and tech

Google to critical infra orgs: Our AI scanners won't be evil, promise

Gemini 3.8 Flash Cyber and Wiz's Red Agent team up to protect hospitals, public transit, and tech

Shut up and calculate: Jev's new AI primitives for coders Developers test what they can build with TypeSafe's fast, typed decision model

Shut up and calculate: Jev's new AI primitives for coders

Developers test what they can build with TypeSafe's fast, typed decision model

Security Russians are posing as Signal support to launch phishing attacks PLUS: US takes down Iranian propaganda sites; Marketing company asks 'Why Do We Have Your Information?' And more!

Russians are posing as Signal support to launch phishing attacks

PLUS: US takes down Iranian propaganda sites; Marketing company asks 'Why Do We Have Your Information?' And more!

Security Microsoft patches failed to fix on-prem SharePoint, which is now under zero-day attack PLUS: China upgrades smartphone surveillance tools; Ring eases anti-snooping stance; and more

Microsoft patches failed to fix on-prem SharePoint, which is now under zero-day attack

PLUS: China upgrades smartphone surveillance tools; Ring eases anti-snooping stance; and more

Black Hat and DEF CON DEF CON Franklin project enlists hackers to harden critical infrastructure Voting village reports have been so successful, says Jeff Moss, that the whole of DEF CON will now be included

Black Hat and DEF CON

DEF CON Franklin project enlists hackers to harden critical infrastructure

Voting village reports have been so successful, says Jeff Moss, that the whole of DEF CON will now be included

Security EQT buys majority in Swiss cybersecurity biz Acronis Went at equivalent of $3.5B+ valuation for entire firm, though portion sold not specified

EQT buys majority in Swiss cybersecurity biz Acronis

Went at equivalent of $3.5B+ valuation for entire firm, though portion sold not specified

Malware Month Ten years since the first corp ransomware, Mikko Hyppönen sees no end in sight On the plus side, infosec's a good bet for a long, stable career

Ten years since the first corp ransomware, Mikko Hyppönen sees no end in sight

On the plus side, infosec's a good bet for a long, stable career

KDE turns 30 and someone's brought an AI-native desktop proposal Akademy talk imagines Plasma assembling itself around a personal model of each user

KDE turns 30 and someone's brought an AI-native desktop proposal

Akademy talk imagines Plasma assembling itself around a personal model of each user

Shopify extends lifeline to Tailwind as vibe coding erodes web dev platform's bottom line Acquisition gives open source CSS framework 'a stable long-term '

Shopify extends lifeline to Tailwind as vibe coding erodes web dev platform's bottom line

Acquisition gives open source CSS framework 'a stable long-term '

Switzerland tests a FOSS escape route from Microsoft 365 Swiss Army sticks a knife in American cloud apps with its own FOSS push

Switzerland tests a FOSS escape route from Microsoft 365

Swiss Army sticks a knife in American cloud apps with its own FOSS push

Feel peak Windows was 7? You might like Kumander Linux Debian and Xfce – solid, sensible choices – with a pretty skin

Feel peak Windows was 7? You might like Kumander Linux

Debian and Xfce – solid, sensible choices – with a pretty skin

Canonical shuttering some of its legacy chat channels The Ubuntu Pastebin went in June, IRC gets demoted

Canonical shuttering some of its legacy chat channels

The Ubuntu Pastebin went in June, IRC gets demoted

Audacity audio-editing app no longer looks like it's from the early 2000s The FOSS tool for audio editing has a fresh coat of paint, and new features to boot

Audacity audio-editing app no longer looks like it's from the early 2000s

The FOSS tool for audio editing has a fresh coat of paint, and new features to boot