Irish Revolut customers involved in second data protection leak in a week

sponsored by

Revolut customers in Ireland have been caught up in a data breach for the second time this month, this time through DriveWealth, the US broker that carried out American stock trades for users of the app. DriveWealth says an unauthorised party got into its network on 4 and 5 September through a social engineering campaign, and gained access to historical personal data belonging to some of its customers.

I’m one of them. I used Revolut to buy US shares before the cut-off, and an email from Revolut landed in my inbox identifying me as potentially affected. The one from DriveWealth took a bit more finding, as it had gone straight to my spam folder. Now from running a website, I understand what drives emails into spam. It’s one of many things including the likes of an SPF record. And for a financial instituion to not have a SPF record set up is a major red flag.

Revolut is keen to stress that its own systems and infrastructure weren’t touched, and that customer funds and investments are safe.

Coming so soon after the earlier Revolut data breach affecting Irish customers, there are a lot of understandably nervous people out there. Despite the two sounding extremely similar, when I put the question to Revolut, the company confirmed the two incidents are unrelated, involving different systems, different causes and different data. Here’s what we know so far about this one, and what we don’t.

Kindly sponsored by
Anker SOLIX XE

How big is the DriveWealth data breach?

Nobody has put a number on it yet, and a big part of the reason is that this happened at one of Revolut’s third-party providers rather than at Revolut itself.

Revolut told me every affected customer has been contacted directly, but that DriveWealth is best placed to set out the overall numbers across its systems. So far, DriveWealth hasn’t done that. Its cyber response page does say it isn’t aware of any identity fraud or misuse of information linked to the incident, that its trading systems and client-facing platform weren’t affected, and that outside cybersecurity experts have confirmed there’s no ongoing threat inside its network.

Brought to you by
Anker SOLIX XE

What we do know is that this isn’t a Revolut-only problem. DriveWealth provides the trading plumbing for a number of investment apps, and platforms such as Stake in Australia and Hatch in New Zealand have also warned their own customers. In the email I received, DriveWealth says it has brought in a third-party forensic firm to investigate, shut down further access to its systems and reported the incident to the Data Protection Authority in Lithuania.

What personal data was exposed in the Revolut breach?

The list is longer than you’d like, and this wasn’t just a case of someone having a peek. DriveWealth’s own cyber response page confirms the data was exfiltrated, meaning it was copied out of its network. The historical data involved may include customer profile information such as names, email addresses, phone numbers, postal addresses and employment details, along with biographical data like country of citizenship, age and gender. Partial DriveWealth account numbers are also in there.

DriveWealth says it has no reason to believe passwords or payment details, such as card or bank account numbers, were included. Revolut adds that no Revolut passwords, passcodes, card details or ID documents were exposed. Those were never shared with DriveWealth in the first place, so it never held them. Revolut also says your account can’t be accessed using the leaked information alone, and that it hasn’t detected any unauthorised activity on affected accounts. DriveWealth says it found no unauthorised trades, transfers or withdrawals either.

Kindly sponsored by
Anker SOLIX XE

To be honest, that’s the good news. The bad news is that a name, address, phone number and employer is more than enough for a scammer to build a very convincing story around. More on that shortly.

Who is affected by the DriveWealth breach?

If you’re in Ireland and you used Revolut to invest in US stocks before December 2023, you could be affected.

DriveWealth handles the execution and clearing of trades for Revolut customers using the optional US stock trading feature, and it held customer information to carry out and settle those trades and to meet US regulatory requirements. Back then, anyone using the feature effectively signed up to two contracts, one with Revolut and one with DriveWealth. The DriveWealth email I received spells this out, noting that it “historically contracted directly” with me.

Revolut has since changed how its US stock trading works, moving customers to a model that doesn’t require their personal details to be shared with DriveWealth. That switch happened in December 2023 for customers in the European Economic Area, including Ireland, followed by the UK in March 2025 and Australia in June 2025. The problem is that DriveWealth held on to the older records to meet its regulatory retention requirements, which is how a partnership that ended nearly three years ago for Irish users has come back to bite. In the US, where the old model still applies, the incident relates to anyone who has used US stock trading.

Anyone affected should have received emails from both DriveWealth and Revolut, and Revolut says that if you haven’t received an email, you aren’t affected. That said, the DriveWealth email has a habit of ending up in spam. Mine did, and other customers have reported the same. If you traded US shares on the app before the end of 2023, have a dig through your junk mail before assuming you’re in the clear. If you do find it, Revolut’s own email confirms the DriveWealth message is genuine, which is reassuring given how much a breach notice sitting in spam looks like the kind of thing you’d normally bin.

How many Revolut customers in Ireland are affected?

Neither Revolut nor DriveWealth has confirmed how many customers in Ireland, or anywhere else, are caught up in this one.

For context, Revolut has around 3.4 million customers in Ireland and more than 80 million worldwide. Last week, the company told some customers that copies of their passports and driving licences, along with dates of birth, home addresses, email addresses and phone numbers, had been handed to criminals. According to Revolut, that happened after an “unauthorised third party” used an email domain belonging to a legitimate government agency to submit “fraudulent requests for information”. It was reported at the time that around 680 customers were affected globally, with 12 of those based in Ireland.

The two incidents are separate, but I think it would be fair to surmise that this latest breach involving DriveWealth could be even more significant in scale. The data involved is less sensitive than passports and driving licences, but the pool of potential victims is anyone in Ireland who dabbled in US shares through the app before 2024. That’s a far bigger group than a dozen people.

What are the risks to Revolut customers?

The main risks are that your personal data gets misused and that you become a target for phishing.

Phishing is when criminals send emails, texts or messages designed to trick you into handing over sensitive information, like login details or card numbers. Scammers who already know your name, address, phone number and where you work can make those messages look far more legitimate than the usual badly spelled chancer.

Beyond phishing, identity fraud, impersonation and social engineering aimed at squeezing more personal or financial information out of you are all real possibilities. There’s a grim irony in that last one, given social engineering is exactly how DriveWealth was breached in the first place.

If you received one of the breach emails, treat any unexpected call, text or email that mentions your Revolut account, your old stock trades or DriveWealth with suspicion, even if it gets your details right. Both companies say they will never ask for your passcode, password or card details, and will never tell you to move money to another account for safekeeping. Anyone who does is a scammer, full stop. Don’t click links or call numbers in those messages. Go straight to the Revolut app instead, and report anything suspicious through the in-app chat or to support@revolut.com, both of which are available around the clock.

DriveWealth also asks that any suspicious email claiming to come from it is forwarded to accountsecurity@drivewealth.com before you click, open or reply to anything. If you have questions about the breach itself, it has set up a contact address at drivewealth@transunion.com, and posts updates on its DriveWealth cyber incident response page which is more aimed at US citizens.

You’d be tired of it all the same.

Brought to you by
Anker SOLIX XE

Written by

Marty
Martyhttps://muckrack.com/marty-goosed
Founding Editor of Goosed, Marty is a massive fan of tech making life easier. You'll often find him testing something new, brewing beer or finding some new foodie spots in Dublin, Ireland. - Find me on Bluesky

Sponsored by

Related articles

Microsoft’s in-game ads patent wants to pause your games for adverts

Microsoft has filed a patent application for a system...

How to get tickets to Macklemore at the 3Arena, Dublin

Macklemore is heading to Dublin's 3Arena on Monday 26...

What AI usage gets Irish students investigated and what happens next?

Irish colleges are heading into another academic year with...

Brought to you by

Anker SOLIX XE

Get more Goosed

Discussion

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.