Customers of Revolut have been affected second time data breach this month after attackers accessed historical personal information held by US brokerage DriveWealth through a social engineering attack.
DriveWealth provides execution and clearing services to investment firms. The company previously held brokerage accounts directly for Revolut customers and said that they received unauthorized access occurred on 4 and 5 September.
DriveWealth claimed the disruption was caused by a “complex social engineering scheme” and that its clients’ personal details were compromised by yet-to-be-identified intruders. Attackers acquired information on the clientele who had previously operated accounts with DriveWealth. The affected data might consist of the clients’ names, email addresses, phone numbers, home addresses, as well as their employment status, age and gender.
DriveWealth maintained that they did not think that any other sensitive information had been disclosed. Passwords, transaction data and bank credentials have remained intact.
Similarly, Revolut stated that some of its clients had been affected by the hack, which involved their records acquired from their previous cooperation with DriveWealth. Both companies notified affected customers, but neither has disclosed how many Revolut users were involved.
The DriveWealth incident follows a separate breach disclosed by Revolut on 12 September. In that case, criminals used fraudulent information requests and impersonated a legitimate government agency to obtain sensitive customer information.
The two incidents involved different attackers and methods. Although the DriveWealth hack did not expose passwords or payment details, the stolen personal information could still be used for further phishing, forgery, or social engineering attempts.