Was your data in the DriveWealth breach?
Our scan cannot match this breach yet
A scan checks your address against Have I Been Pwned, and DriveWealth is not in that record yet. We have published this page from the company’s own notice so you know what was taken and what to do. If you were affected, DriveWealth or the app you used it through is contacting you directly.
Check every other breachWhat this one means here
Most people caught in this never opened an account with DriveWealth, knowingly. When you turned on US share trading in Revolut, you were also given a brokerage account at DriveWealth in New York, and your onboarding details were sent there. Revolut moved UK customers off DriveWealth in March 2025 and wrote to those affected on 24 September 2026, so the exposed record is the one you gave at sign-up before then: including your employer and where you live. That is the material for a convincing phone call or message from someone claiming to be your bank.
What to do: Expect contact that quotes your real details, and treat it as the scam this makes possible. Neither Revolut nor DriveWealth will ask for your passcode or card details, or tell you to move money to a "safe" account. To find out exactly what DriveWealth holds on you, write to accountsecurity@drivewealth.com. Your address and phone number are also what people-search sites list, so it is worth checking that they are not published there too.
DriveWealth (drivewealth.com) suffered a data breach in 2026 that exposed an undisclosed number of accounts. If you had an account, some of your personal data may be circulating in leaked databases. This page is built from the company’s own notice; our scan will match it once the data reaches Have I Been Pwned.
What happened
Between 4 and 5 September 2026 an attacker gained access to systems at DriveWealth, the US broker that carries out US share trades for apps including Revolut, Stake and Hatch, and copied historical customer records. DriveWealth attributes the access to social engineering and says no trades, transfers or withdrawals were made. For Revolut customers the exposed records include name, email address, phone number, postal address, employment details, country of citizenship, age, gender and a partial DriveWealth account number; Stake and Hatch customers also had tax status, income ranges or account balance snapshots taken. No passwords or card or bank details were involved.
Compiled by Nullivo from DriveWealth — cyber incident notice and Finance Magnates — Revolut, Stake and Hatch customers affected. Not yet in Have I Been Pwned.
What was exposed, and why it matters
Not all breaches carry the same risk — what matters is which fields leaked. Here is what the DriveWealth breach exposed and what each item actually enables:
Also listed in this breach: Email addresses, Names, Phone numbers, Physical addresses, Employers, Nationalities, Ages, Genders, Partial account numbers.
What to do if you were affected
These steps are ordered for this specific breach — the most urgent action given what leaked comes first.
- Home addresses
Get your address removed from data brokers — they re-list roughly every four months, so this needs repeating. - Phone numbers
Move two-factor authentication off SMS to an authenticator app or passkey, and add a port-out PIN with your mobile provider. - Names and usernames
Search your usual username to see what else it exposes, and use distinct handles for sensitive accounts. - Email addresses
Treat any message referencing this service with suspicion, and never act on links in unexpected emails. - Look for the notice
If you were affected, DriveWealth or the app you used it through has written to you. Search your inbox for it before assuming either way.
This breach put your details on data-broker sites
Because DriveWealth exposed home addresses, this is one of the breaches that feeds people-search and data-broker sites. Those sites scrape leaked databases, combine them with public records, and republish the result as a searchable profile — which is how a single breach turns into a permanent public listing. Removal works, but brokers typically re-list within about four months, so it has to be repeated.
See our broker-by-broker removal guides →
How urgent is this now?
This breach is recent, so the data is actively traded and the risk is at its highest right now.
Remember: a breach can’t be “un-leaked” — once a database is out, it exists in countless copies. The goal is to make the leaked data useless: change what can be changed, lock down what can’t, and remove what has been republished.
Frequently asked questions
What data was exposed in the DriveWealth breach?
The DriveWealth breach exposed home addresses, phone numbers, names and usernames, email addresses. Home addresses feed people-search and data-broker sites, which republish them publicly. They also make phishing far more convincing and, in the worst cases, enable real-world harassment.
How many people were affected by the DriveWealth breach?
The total has not been disclosed yet. Affected customers are being contacted directly by DriveWealth and the apps that used it.
What should I do if I had a DriveWealth account?
Get your address removed from data brokers — they re-list roughly every four months, so this needs repeating. The company is writing to the people affected, so check your inbox for its notice.
Breaches that exposed similar data
If the DriveWealth breach affected you, these breaches exposed comparable information — worth checking too, since leaked datasets are routinely combined.