All news
Security
27 September 2026

Historical Revolut customer data exposed via third-party partner

A data breach at DriveWealth, a partner of Revolut, has led to the exposure of historical customer information. The incident occurred after attackers gained access through social engineering tactics directed at the partner's staff.

What this means for your business

Business owners using Revolut for trading or international payments should be alert to targeted phishing attempts. You should review your internal security training regarding social engineering and monitor account activity for unauthorised changes.

Third-party security breach

DriveWealth, a US-based brokerage firm that provides trading services to Revolut, has confirmed a security incident involving customer data. The breach occurred because attackers used social engineering to gain access to internal systems. Social engineering is a method where criminals manipulate individuals into giving away sensitive information or access, rather than using technical hacking methods.

While Revolut itself has not been compromised in this specific instance, the link between the two companies means that data belonging to Revolut customers has been affected. This data is described as historical, meaning it may include information from accounts that are no longer active or older records for current users.

Data involved

The specific types of data accessed have not been fully detailed, but typically include identifiers such as names, contact details, and account numbers. DriveWealth has stated that they have taken steps to secure their environment and are working with law enforcement.

For a UK business owner, the primary concern is not a direct theft of funds from this breach, but the subsequent use of this data. When criminals obtain contact details and the name of your financial provider, they can create more convincing scams. These might take the form of emails or phone calls that appear to be from Revolut or DriveWealth, asking you to move money to a 'safe' account or share your login credentials.

Managing the risk

There is currently no action required to change passwords unless specifically instructed by the provider through their official app. However, it is a suitable time to remind staff that financial institutions will not ask for full security codes or passwords over the phone.

Businesses should ensure that multi-factor authentication (MFA) is active on all financial accounts. This adds a layer of protection that requires a second form of verification, such as a code on a mobile device, before access is granted. If you receive an unexpected call or email regarding your Revolut account, end the communication and contact the provider through their official support channels.

Worried this could affect you?

Cyber Essentials is the quickest way for a small business to close the gaps attackers use most.

See Cyber Essentials

Not sure how exposed you are?

Twenty minutes on a call is usually enough to tell you.