TL;DR:
- DriveWealth, Revolut’s former US broker, suffered a social engineering attack on September 4–5 that compromised customer profile records.
- The attacker initially demanded up to $760 million in Bitcoin before lowering the demand to $3 million in Monero and leaking files linked to 680 crypto investor accounts.
- The financial institution confirmed that its funds, accounts, and core infrastructure suffered no operational disruptions during the reported incidents.
British digital bank Revolut and its former US brokerage partner DriveWealth confirmed on Thursday, September 24, two customer data breaches that occurred during the current month.
JUST IN: Revolut is emailing customers about another data incident. This one is at DriveWealth, the US broker that used to handle Revolut’s US share trading.
DriveWealth says unauthorised access hit its systems on 4–5 September. The data taken is older customer-profile… pic.twitter.com/xPO7YbOk57
— Max Karpis (@maxkarpis) September 24, 2026
The incident in DriveWealth’s systems took place between September 4 and 5. The attackers gained unauthorized access to information including names, email addresses, ages, gender, nationality, mailing addresses, and employment details.
DriveWealth previously handled US stock trading operations for the British platform’s users. The information stolen in this event comprises historical profiles and does not include records of European Economic Area users after 2023.
Both companies sent formal notifications to affected users throughout the day on September 24. Neither corporation disclosed the exact number of exposed individuals nor the technical methods used by the attackers in the initial intrusion.
The fintech company emphasized via a statement that its funds, account balances, and internal infrastructure remain intact. The event is categorized as a breach of profile data privacy and not as a financial loss of custodied assets.

Official Email Attack and the “Italy Files” Leak
This represents the second security failure disclosed by the company in recent weeks. In early September, the entity admitted that cybercriminals used a legitimate email account belonging to the Italian government to bypass internal controls and extract confidential information.
The attacker made fluctuating financial demands to halt the exposure of the information. The initial request reached approximately $760 million in Bitcoin, an amount that was later reduced to $3 million in Monero.
After the entity refused to pay the ransom, the attacker leaked a batch of records dubbed the “Italy Files”. The published documentation includes information corresponding to 680 large cryptocurrency holders.
Among the public figures impacted by the disclosure is Mark Karpelès, former CEO of the Mt. Gox exchange. According to a market report, the hacker began offering this data at discounts of up to ten times the original demand, suggesting difficulties with monetization on the black market.
British and European regulatory compliance protocols require notifying data protection supervisory authorities within 72 hours of confirming a breach. The banking entity maintains open personalized assistance channels while submitting corresponding reports to financial agencies and law enforcement bodies leading the investigation.



