Skip to main content

Morning Overview

DriveWealth’s data breach reached 2,556,688 Texas residents

Texas alone accounts for 2,556,688 residents on DriveWealth’s breach notification list, a number large enough that it dwarfs the other state totals published so far. The company builds the trading plumbing that lets banks, broker-dealers and consumer investing apps offer stocks, and its network was entered on Sept. 4 and 5, 2026.

By Sept. 30 DriveWealth had begun telling state attorneys general what the intruder reached: full names, Social Security numbers and financial account information.

A Brokerage Back End Shared by Revolut, Stake and Hatch

DriveWealth LLC is a fintech that supplies brokerage infrastructure to institutions around the world, so the people on its list are mostly customers of other companies’ apps. According to Finance Magnates reporting by Tanya Chepkova, three of those partners, Revolut, Stake and Hatch, warned their own users after DriveWealth said the access came through a social-engineering campaign. DriveWealth told partners the incident was contained and that it had found no unauthorized trades, transfers or withdrawals.

What each partner’s users lost differed. Revolut said its own systems were untouched and that DriveWealth acts as an independent data controller for this incident, with affected customers receiving two emails, one from each company. Stake’s exposure included W-8 or W-9 tax status and account numbers; Hatch’s included income and net-asset ranges. Those partner-level details come from the apps’ notices to customers, not from the Texas filing.

Revolut’s European customers fall into a narrower window. Finance Magnates reports that only records Revolut supplied before December 2023 could be involved for EEA customers, because Revolut stopped sending new EEA data to DriveWealth then, and that identity documents and payment details were reportedly not compromised for that group. The same report separates this event from an earlier September Revolut incident in which a compromised Italian government email account was used to request data on about 680 customers; that case has no connection to DriveWealth.

Full Names, Social Security Numbers and Account Data

The state filings are narrower and heavier. ClaimDepot’s summary of the filings lists confirmed exfiltration of full names, Social Security numbers and financial account information such as debit or credit card numbers. ClassAction.org, summarizing the same disclosures, says DriveWealth’s online notice states that no passwords or payment details were compromised. The two descriptions differ on the card-number point, and neither page reproduces the notice letter in full.

The California Attorney General’s office logged the notice on Sept. 30 with a breach date of Friday, Sept. 4, 2026, and a redacted sample letter attached. That entry does not list the data elements itself.

The Texas Report and the Wider Count

An Oct. 2 report to the Texas Attorney General’s Office, in the words of a ClassAction.org write-up, says the breach “impacted over 2.5 million Texans.” The exact figure of 2,556,688 comes from the ClaimDepot entry for the same filing. The state’s data security breach report portal is where those submissions are posted, though its listing table did not render when read for this article, so the exact number rests on ClaimDepot’s transcription.

Rhode Island is the only other state with a count so far: 62,074 residents. ClaimDepot’s page shows filings or placeholders for more than a dozen other jurisdictions, including Maine, Massachusetts, Vermont and Washington, and leaves its overall total blank. The timeline it assembles runs from the Sept. 4-5 access to the investigation’s conclusion on Sept. 28 and the first disclosures two days later. One older item sits beside the filing: on Dec. 25, 2025, a Telegram poster calling itself “Yiqun data” claimed to hold 72,000 DriveWealth customer records. Nothing connects that claim to the September incident, and the filings do not mention it.

ClassAction.org adds that DriveWealth reports no unauthorized brokerage account activity and no effect on its trading systems or client platform. Its summary also says the stolen information concerns people with securities brokerage accounts and may have originated with broker-dealers, registered investment advisors or other financial institutions that use DriveWealth.

Triple-Bureau Coverage for 12 Months

DriveWealth is offering 12 months of triple-bureau monitoring and credit reports, with enrollment due within 90 days of the letter and a toll-free line staffed Monday through Friday from 8 a.m. to 8 p.m. Eastern. Notification is going out by email, ClassAction.org reports, to people with brokerage accounts whose data was held on the network. Enrollment needs the unique code printed in each letter plus internet access and an email account, ClaimDepot notes, and contact is also possible by email or through the company’s cyber response page.

With a Social Security number in the mix, the offer is shorter than the exposure. The 2,556,688 Texans are only the first count to surface from a filing round that began Sept. 30, and the next state postings will show whether Texas remains the largest.

This article was produced with the assistance of AI and reviewed by Morning Overview editors prior to publication.


More from Morning Overview


Morning Overview is reader-supported. Some links in our articles are affiliate links, and we may earn a commission at no extra cost to you. As an Amazon Associate I earn from qualifying purchases. Full disclosure.