Revolut Confirms Data Breach Affects Irish Customers

Revolut confirmed that some Irish customers have been affected by a separate cyber incident involving DriveWealth, a US broker used for stock investments through the app. According to Revolut, customer profile data including names, email addresses, phone numbers, postal addresses, employment details, and biographical information may have been accessed in the breach.

DriveWealth Security Incident Exposes US Stock Investor Data

The breach affects Revolut customers who used the app for US stock trading. DriveWealth warned affected individuals in a direct email communication that personal data could potentially be misused by unauthorized third parties. The broker stated that customers might face risks related to phishing attempts, identity fraud, impersonation, social engineering, and unsolicited contact from unknown parties.

Revolut clarified that the incident’s scope varies by region. In the United States, the breach involves customers who used US stock trading services. In the UK, the European Economic Area, and Australia, the exposure relates specifically to historical records dating from before Revolut changed its US stock trading model between December 2023 and June 2025. Revolut stated that individual customer personal details in these international markets have not been shared with DriveWealth since those model updates and remain unaffected.

Revolut Distances Its Core Systems From the US Broker Breach

Revolut sought to downplay the risk to its broader customer base in Ireland, where the fintech firm holds 3.4 million users representing approximately 80 percent of the adult population. A Revolut company statement emphasized that its own internal systems and infrastructure were not accessed or compromised during the DriveWealth incident.

“Customer funds and investments are safe,” Revolut said, adding that no account passwords, passcodes, card details, or ID documents were exposed through the US broker. The company confirmed that DriveWealth contacted affected customers directly, and Revolut followed up with its own explanatory email. Customers who did not receive an email from the firm are unaffected by this specific breach.

Did you know? In 2023, Revolut reported that the number of customers using its Invest facility surged by 22 percent, with the average account holding €1,295. The payments firm is actively expanding its app features, recently introducing a private markets assets access option for exposure to private equity and credit.

Comparison With Earlier Revolut Security Alert

This cyber incident represents the second security alert issued by Revolut within the same month. Earlier in the month, Revolut reported a separate incident where the company was tricked into handing over sensitive customer information, including passport data, driver’s licences, phone numbers, home addresses, and birthdays. While the earlier event stemmed from a sophisticated external impersonation scam utilizing a legitimate government agency domain email to submit fraudulent requests—impacting a reported 680 customers globally, including 12 in Ireland—the latest alert originates strictly from third-party broker DriveWealth’s system compromise.

Security analysts note that while the first incident involved direct identity documents like passports and driver’s licences capable of facilitating account takeovers, the DriveWealth breach primarily exposes profile, contact, and biographical data that heightens vulnerability to targeted phishing and social engineering campaigns.

Frequently Asked Questions

How do I know if I am affected by the DriveWealth breach?

Revolut and DriveWealth have contacted affected customers directly via email. If you did not receive an email regarding this incident, you are not affected.

Revolut Confirms Data Breach Affects Irish Customers
Photo: rte.ie

Are my bank account funds and card details safe?

Yes. Revolut confirmed that its own infrastructure was not compromised, and no passwords, passcodes, card details, or ID documents were exposed in the DriveWealth incident.

What information could have been accessed?

Profile data including names, email addresses, phone numbers, postal addresses, employment information, and biographical data such as country of citizenship, age, and gender may have been accessed.

REVOLUT DATA BREACH AFTER FAKE GOVERNMENT REQUESTS – NOW HACKERS ARE TARGETING CUSTOMERS DIRECTLY

Leave a Comment