Cryptelio

Revolut Customers Experience Second Data Breach in September

Cryptelio Editorial Published 24 Sep 2026 · 22:45 UTC
Revolut Customers Experience Second Data Breach in September

Revolut has reported that its customers' data was compromised for the second time this month, following a breach at DriveWealth, a third-party US broker that previously managed Revolut's US stock trading. The incidents occurred on September 4 and 5, 2023, and were attributed to a social engineering attack.

The exposed data includes historical customer records such as names, email addresses, ages, genders, citizenship information, postal addresses, and employment details. However, it is important to note that the breach does not affect any data from customers in the European Economic Area after December 2023, as Revolut ceased sharing individual customer details with DriveWealth after changing its trading model.

Revolut emphasized that its core infrastructure, customer funds, and accounts were not compromised during this incident. Following the breach, DriveWealth has reached out to affected customers directly, and Revolut has also communicated with its users regarding the situation.

This latest breach follows an earlier incident in September where hackers used a legitimate Italian government email to deceive Revolut into disclosing sensitive information, impacting around 680 customers globally. Both Revolut and DriveWealth have not disclosed the exact number of customers affected by the recent breach.

As Revolut serves approximately 3.4 million customers in Ireland alone, users are advised to remain vigilant for phishing attempts and to monitor communications from the company.

FAQ

What happened in the recent Revolut data breach?

Revolut reported a data breach affecting its customers due to a social engineering attack on DriveWealth, a third-party broker. The breach occurred on September 4 and 5, 2023, exposing historical customer records such as names, email addresses, and other personal information.

How does this breach affect customers in the European Economic Area?

The breach does not affect any data from customers in the European Economic Area after December 2023, as Revolut stopped sharing individual customer details with DriveWealth after changing its trading model.

Was any customer financial information compromised in the breach?

No, Revolut emphasized that its core infrastructure, customer funds, and accounts were not compromised during this incident.

What should affected customers do following the breach?

Affected customers should remain vigilant for phishing attempts and monitor communications from Revolut. DriveWealth has reached out directly to those impacted.

How many customers were affected by the recent breach?

Both Revolut and DriveWealth have not disclosed the exact number of customers affected by the recent breach.

Related

Comments

Comments are moderated before publish.

No comments yet — be the first.

Comment as guest

Captcha