1 min read

Revolut Discloses Second Data Incident After DriveWealth Attack

Information tied to older customer profiles may have been exposed, including names, contact details, addresses and employment data.

Empty brokerage lobby with a security camera above the entrance / TokenPost.ai
Empty brokerage lobby with a security camera above the entrance / TokenPost.ai

Revolut disclosed a second data incident this month after a social engineering attack at former U.S. brokerage partner DriveWealth may have exposed information tied to older customer profiles.

The unauthorized access occurred on Sept. 4 and 5. Potentially exposed records included names, email addresses, ages, genders, citizenship details, postal addresses and employment information.

The affected data did not include European Economic Area customer information from after 2023. The number of potentially affected users was not disclosed.

Revolut’s core infrastructure, customer funds and accounts were not affected by the incident, based on the available details.

DriveWealth previously handled Revolut’s U.S. share trading services. Earlier this month, Revolut disclosed another data incident involving unauthorized access to its data.

Loading…