Was your data in the DriveWealth breach?

2026 · drivewealth.comAccounts not yet disclosedSeverity 8 / 10 — critical, because home addresses and phone numbers leaked

Our scan cannot match this breach yet

A scan checks your address against Have I Been Pwned, and DriveWealth is not in that record yet. We have published this page from the company’s own notice so you know what was taken and what to do. If you were affected, DriveWealth or the app you used it through is contacting you directly.

Check every other breach

What this one means here

Most people caught in this never opened an account with DriveWealth, knowingly. When you turned on US share trading in Revolut, you were also given a brokerage account at DriveWealth in New York, and your onboarding details were sent there. Revolut moved UK customers off DriveWealth in March 2025 and wrote to those affected on 24 September 2026, so the exposed record is the one you gave at sign-up before then: including your employer and where you live. That is the material for a convincing phone call or message from someone claiming to be your bank.

What to do: Expect contact that quotes your real details, and treat it as the scam this makes possible. Neither Revolut nor DriveWealth will ask for your passcode or card details, or tell you to move money to a "safe" account. To find out exactly what DriveWealth holds on you, write to accountsecurity@drivewealth.com. Your address and phone number are also what people-search sites list, so it is worth checking that they are not published there too.

DriveWealth (drivewealth.com) suffered a data breach in 2026 that exposed an undisclosed number of accounts. If you had an account, some of your personal data may be circulating in leaked databases. This page is built from the company’s own notice; our scan will match it once the data reaches Have I Been Pwned.

What happened

Between 4 and 5 September 2026 an attacker gained access to systems at DriveWealth, the US broker that carries out US share trades for apps including Revolut, Stake and Hatch, and copied historical customer records. DriveWealth attributes the access to social engineering and says no trades, transfers or withdrawals were made. For Revolut customers the exposed records include name, email address, phone number, postal address, employment details, country of citizenship, age, gender and a partial DriveWealth account number; Stake and Hatch customers also had tax status, income ranges or account balance snapshots taken. No passwords or card or bank details were involved.

Compiled by Nullivo from DriveWealth — cyber incident notice and Finance Magnates — Revolut, Stake and Hatch customers affected. Not yet in Have I Been Pwned.

What was exposed, and why it matters

Not all breaches carry the same risk — what matters is which fields leaked. Here is what the DriveWealth breach exposed and what each item actually enables:

Home addresses
weight 8 / 10
Home addresses feed people-search and data-broker sites, which republish them publicly. They also make phishing far more convincing and, in the worst cases, enable real-world harassment.
Phone numbers
weight 7 / 10
Enables SIM-swap attacks (hijacking your number to intercept SMS codes), smishing, and voice scams that appear to come from your bank.
Names and usernames
weight 4 / 10
Links this leak to your other accounts — a reused username lets anyone build a profile of you across platforms.
Email addresses
weight 3 / 10
Puts you on spam and phishing lists, and confirms to attackers that you hold an account with this service — which makes impersonation emails more believable.

Also listed in this breach: Email addresses, Names, Phone numbers, Physical addresses, Employers, Nationalities, Ages, Genders, Partial account numbers.

What to do if you were affected

These steps are ordered for this specific breach — the most urgent action given what leaked comes first.

  1. Home addresses
    Get your address removed from data brokers — they re-list roughly every four months, so this needs repeating.
  2. Phone numbers
    Move two-factor authentication off SMS to an authenticator app or passkey, and add a port-out PIN with your mobile provider.
  3. Names and usernames
    Search your usual username to see what else it exposes, and use distinct handles for sensitive accounts.
  4. Email addresses
    Treat any message referencing this service with suspicion, and never act on links in unexpected emails.
  5. Look for the notice
    If you were affected, DriveWealth or the app you used it through has written to you. Search your inbox for it before assuming either way.

This breach put your details on data-broker sites

Because DriveWealth exposed home addresses, this is one of the breaches that feeds people-search and data-broker sites. Those sites scrape leaked databases, combine them with public records, and republish the result as a searchable profile — which is how a single breach turns into a permanent public listing. Removal works, but brokers typically re-list within about four months, so it has to be repeated.

See our broker-by-broker removal guides →

How urgent is this now?

This breach is recent, so the data is actively traded and the risk is at its highest right now.

Remember: a breach can’t be “un-leaked” — once a database is out, it exists in countless copies. The goal is to make the leaked data useless: change what can be changed, lock down what can’t, and remove what has been republished.

Frequently asked questions

What data was exposed in the DriveWealth breach?

The DriveWealth breach exposed home addresses, phone numbers, names and usernames, email addresses. Home addresses feed people-search and data-broker sites, which republish them publicly. They also make phishing far more convincing and, in the worst cases, enable real-world harassment.

How many people were affected by the DriveWealth breach?

The total has not been disclosed yet. Affected customers are being contacted directly by DriveWealth and the apps that used it.

What should I do if I had a DriveWealth account?

Get your address removed from data brokers — they re-list roughly every four months, so this needs repeating. The company is writing to the people affected, so check your inbox for its notice.

Breaches that exposed similar data

If the DriveWealth breach affected you, these breaches exposed comparable information — worth checking too, since leaked datasets are routinely combined.

See all breaches we cover →

DriveWealth data breach (2026): what was taken and what to do | Nullivo