DriveWealth

Sep 2026 · Graded Verified · Financial Services · Government record

Incident summary

DriveWealthSep 2026
Not yet quantified
VVerified
DriveWealth's network was entered between September 4 and 5, 2026 via a social engineering campaign aimed at an unidentified third-party service provider. As the Brokerage-as-a-Service layer underneath Revolut, Stake, and Hatch, one vendor's failure became three brands' breach notice, spilling names, employment data, citizenship, and tax and portfolio data across five countries. Passwords and card numbers were left untouched; too bad the records of who these customers were not.
Financial Services
California AG breach notification
Initial attack type third-party or supply chain confirmed · Impact data theft confirmed

About this record

This incident is on the public government record: an SEC 8-K filing or a state-regulator notification, graded Verified. Every figure links to the source it was read from; if we have read one wrong, tell us at info@hackerinahoodie.com. This index never sums figures across incidents. See the methodology.

Cite this incident

← The complete On the Government Record ledger ← Back to the index