
![]()
Revolut customers in Ireland are among those affected by a data breach involving a third-party company responsible for processing US stock trades.
DriveWealth, a US-based broker that previously carried out US stock transactions for Revolut customers, has confirmed a security incident involving unauthorised access to historical personal information held on some of its customers.
Revolut said it is working directly with DriveWealth to establish the full extent of the incident.
In an email sent to customers, the fintech company said the information potentially accessed includes personal profile details such as names, email addresses, phone numbers, postal addresses and employment information.
The data may also include biographical details, including customers' country of citizenship, age and gender, as well as partial DriveWealth account numbers.
However, Revolut said there was no indication that passwords or financial payment information had been compromised.
"At this time, DriveWealth has no reason to believe any other personal information was affected, in particular, no passwords or financial payment information (such as credit card or bank account details) were involved," the company said.
A Revolut spokesperson also stressed that the company's own systems and infrastructure were not accessed or compromised as part of the incident.
"Revolut passwords, passcodes, card details, or ID documents were not exposed," the company said, adding that customer funds and investments remain safe.
According to Revolut, the incident only affects historical records in Europe from before the company changed the way it handled US stock trading.
The changes were introduced between December 2023 and June 2025, depending on the market.
"Since then, individual customers' personal details in these markets have not been shared with DriveWealth, and as a result are not affected," Revolut said.
DriveWealth has contacted customers whose information may have been involved, while Revolut has also followed up with its own notification explaining the incident.
The company said customers who have not received an email do not appear to be affected.
The incident is the second data breach involving Revolut customers to emerge this month.
On 14 September, Revolut informed some customers that criminals had obtained copies of identity documents, including passports and driving licences, along with other personal details such as dates of birth, home addresses, email addresses and phone numbers.
In that case, Revolut said an "unauthorised third party" had used an email domain belonging to a legitimate government agency to submit fraudulent requests for customer information.
The company did not disclose how many customers were affected or identify the countries involved. Reports at the time said approximately 700 customers worldwide were impacted, including around 12 in Ireland.