BREACH

DriveWealth broker breach ripples to Hatch, Stake, and Revolut US-trading customers.

DriveWealth, the US brokerage infrastructure behind multiple retail investing apps, had an unauthorized party access data on its systems on September 4–5, 2026 (Hatch / BusinessDesk). Hatch (NZ) says its own systems were not breached, but customer records held at DriveWealth were among those potentially accessed. Holdings and transactions were unaffected. Full victim tally: Undisclosed.

Sep 24, 2026 · 3 min read

Primary partner notice path: SecurityBrief NZ (Sean Mitchell, Sep 22) quoting Hatch’s customer message. Hatch said an unauthorized party accessed data held on DriveWealth systems over two days in September, including information linked to Hatch users. BusinessDesk (Rebecca Stevenson, Sep 22) dates the access window to September 4 and 5 and notes Stake customers may also be in scope via the same US broker.

Data Hatch says may have been exposed: names, addresses, phone numbers, email addresses, investor profile fields such as income range and net-asset range, plus cash balance and portfolio value. Hatch says not exposed: identity documents and their details, dates of birth, IRD numbers, foreign tax identifiers, children’s account details, proof-of-address / source-of-wealth documents. Hatch login credentials were not on DriveWealth infrastructure. No unauthorized transactions; investment holdings not affected. DriveWealth investigated with independent cybersecurity experts, told partners it had not identified an ongoing threat, and strengthened controls (per Hatch message via SecurityBrief).

Sep 24 Irish press headlines (RTE, The Journal, Irish Independent) report Revolut confirming some Irish customers were affected by a new third-party data incident tied to US stock trading — consistent with DriveWealth as the shared broker layer. Treat Revolut-specific counts and exact field lists as Undisclosed until a Revolut primary notice is on the desk.

DriveWealth’s public newsroom as of this brief lists no incident press release; watch partner notices and SEC/regulatory filings. POV: classic fintech supply-chain exposure — front-end apps stay up while the shared US broker’s customer graph leaks enough profile + portfolio color to fuel targeted phishing. Count of Hatch / Stake / Revolut victims: Undisclosed.

Sources