Houston/ Crime & Emergencies

DriveWealth Breach Exposed SSNs of 2.5 Million Texans, AG Filing Says

AI Assisted Icon
Published on October 06, 2026
DriveWealth Breach Exposed SSNs of 2.5 Million Texans, AG Filing SaysSource: Markus Spiske / Unsplash

More than 2.5 million Texans may have had their names, Social Security numbers and financial information exposed after a New York-based broker-dealer discovered hackers had broken into its network. DriveWealth says the unauthorized access happened over a two-day span in September and has since been contained, though the company's investigation remains active.

According to a report filed with the Texas Attorney General's Office on October 2, the breach impacted over 2.5 million people in the state and involved names, Social Security numbers and financial information. The filing landed with Attorney General Ken Paxton's office roughly a month after DriveWealth says it first discovered the intrusion, as reported by the Houston Chronicle.

How the Breach Unfolded

DriveWealth said it discovered the unauthorized access occurred between September 4 and September 5, 2026, and that certain personal information was exfiltrated from its network during that window, according to the company's own customer notification posted to its legal hub. The company says it contained the compromise by September 5 and has not observed further unauthorized activity since.

Beyond names, Social Security numbers and financial information, the exposed data set reportedly included email addresses, phone numbers, postal addresses, employment information, country of citizenship, age, gender and partial DriveWealth account numbers, per a report from the technology outlet the Register. That same report says DriveWealth attributed the intrusion to what it called a sophisticated social-engineering campaign carried out by unknown third parties.

Brokerage Accounts Reportedly Untouched

DriveWealth says the fallout stopped short of customers' actual holdings. The firm's notification states no unauthorized brokerage account activity, including trading, transfers, withdrawals, ACAT requests or balance or position changes, was identified, and that its production brokerage and trading systems and client-facing platform were not affected and continued to operate normally throughout the incident.

The company also says no passwords or financial payment information, such as credit card or bank account details, were compromised, and that it is not aware of reports of identity fraud or improper use of information as a direct result of the incident. DriveWealth is notifying potentially affected individuals by email, the same notice states, and the firm began reaching out to customers starting September 4.

What DriveWealth Is Telling Customers to Do

DriveWealth has recommended that affected customers use antivirus software, regularly update their passwords and stay alert for scam emails containing suspicious links, according to the seed reporting from the Houston Chronicle. The company has also apologized for the incident and says it is committed to maintaining the privacy of personal information in its possession, adding that it has taken many precautions to safeguard that data and continues to evaluate and modify its practices and internal controls to enhance security and privacy.

DriveWealth did not respond to a request for comment immediately, per the Houston Chronicle's reporting. The company's investigation into the incident is continuing, according to a statement referenced by the investing platform Stake in its own update to users about the breach.

A Wider Pattern Among Brokerage Partners

DriveWealth's reach extends beyond its own direct customers, since the firm provides back-end brokerage infrastructure for other financial apps. Revolut has told its own affected customers they received two separate emails, one from DriveWealth and one from Revolut, confirming they were impacted and explaining the scope of the breach, according to Revolut's help center.

The incident also arrives against a federal backdrop of tightened expectations for how brokerages handle customer data. Amendments to Regulation S-P require covered institutions to develop, implement and maintain written policies and procedures for an incident-response program reasonably designed to detect, respond to and recover from unauthorized access to customer information, and generally require firms to notify customers after a breach, according to the U.S. Securities and Exchange Commission.

It remains unclear how many customers nationwide were affected beyond the Texas filing, or whether additional state reports will surface as DriveWealth's notification process continues. For now, the company says its core trading systems were never touched, even as it works to determine the full scope of what hackers managed to take.