Revolut customer data breached twice this month after DriveWealth attack
DriveWealth says data was accessed on September 4 and 5
Revolut says customer data was breached twice this month after its former third-party US broker, DriveWealth, was hit by a social engineering attack. A social engineering attack is when someone tricks a person into giving up access, rather than breaking in through a technical flaw.
Both Revolut and DriveWealth revealed the incident on September 24. The unauthorized access happened on September 4 and September 5, according to DriveWealth.
DriveWealth previously handled share trading for Revolut's US customers.
Key details from both companies
- Reported data taken includes names, emails, ages, genders, citizenship information, postal addresses and employment details.
- Neither Revolut nor DriveWealth said how many users were affected.
- Neither company explained what happened during the social engineering attack.
- Revolut said its core infrastructure, funds and accounts were not impacted.
- Revolut said the newly revealed breach does not include data from affected European Economic Area customers after 2023.
Revolut investor shared the DriveWealth email
Revolut investor Max Karpis shared an email he received from DriveWealth about the incident. The list of compromised data types was reported from that email.
Reporting on the breach also came from journalist Jason Mikula, who commented on the hacker's activity in a post on X.
Earlier breach linked to an Italian government email
Earlier in September, Revolut revealed that hackers used an Italian government email to gain access to company data. That is a separate incident from the DriveWealth breach.
Reported ransom demands after that email attack ranged from $760 million in BTC to $3 million in XMR a few days later.
The hacker now claims that negotiations "didn't go as planned" and has published what is being called the "Italy Files," which include data on 680 crypto whales. Crypto whales are people who hold very large amounts of cryptocurrency.
Mikula noted that the hacker is selling the data at 10 times less than their ransom demand, which he said suggests the group is struggling to make money from the data it took. The hacker is also said to be offering affected users, including Mt. Gox CEO Mark Karpelès, the chance to pay to stop their information from being leaked.
What is confirmed
- Revolut and DriveWealth both disclosed the DriveWealth incident on September 24.
- The unauthorized access happened on September 4 and 5.
- Revolut said core infrastructure, funds and accounts were not affected.
- Revolut said affected European Economic Area customer data from after 2023 is not part of the newly revealed breach.
What is still unclear
Neither Revolut nor DriveWealth said how many users were affected. Neither company described how the social engineering attack was carried out. The identity of the attacker has not been confirmed in the source material, and the ransom figures and the "Italy Files" claims come from reported demands and the hacker's own statements rather than confirmed company disclosures.
Why this matters
The incident involves personal profile data held by a third-party broker that used to serve Revolut's US share trading customers. That means a breach at an outside partner can expose customer information even when the company's own systems are not affected. Revolut has not said that customer money or accounts were touched.