
In September 2026, Revolut customer data reached people it should never have reached. Twice. In neither case were the bank's own systems broken into. In one case a US brokerage partner was compromised. In the other, criminals impersonated a government agency and simply asked. This is the structural weakness of a financial product assembled from other companies' infrastructure, and it is the reason MobiBank is building a closed system on its own rail.
On 4 and 5 September 2026, DriveWealth, the United States brokerage that provided execution and clearing for Revolut's US stock trading, was accessed without authorisation. The company attributed it to a sophisticated social engineering campaign. Earlier the same month, Revolut confirmed that an unauthorised third party had used a legitimate government agency email domain to submit fraudulent information requests, and that customer data was handed over in response.
Revolut has stated that its own systems and infrastructure were not accessed or compromised, and that customer funds and investments are safe. We have no reason to doubt either statement. That is precisely what makes these incidents worth reading carefully. A bank can build its own systems well and still lose control of its customers' data, because in the assembled model of modern fintech the data does not only live inside the bank.
The speed of the neobank generation came from not building things. Card issuing, brokerage, identity verification, messaging, cloud: each one bought in, each one holding some copy of the customer in order to do its job. Here is what that means the day somebody comes looking.
Name, address, date of birth, identity documents. Regulation requires the bank to hold it, and it does.
Cards, identity checks, share dealing: parts of the job are bought in from specialists, and each of them ends up holding a record of you. In this case the brokerage partner did not just hold a copy, it held the customer account itself.
Revolut states its own systems and infrastructure were never accessed or compromised in either September incident. That part held.
On 4 and 5 September 2026 DriveWealth, which handled US stock trading for Revolut customers, was accessed without authorisation. The company attributes it to a sophisticated social engineering campaign by unknown third parties.
Names, email addresses, phone numbers, postal addresses, employment information, citizenship, age, gender and partial account numbers. Passwords, payment details and identity documents were reported as not part of it, and DriveWealth reported no unauthorised trades, transfers, withdrawals or balance changes.
The bank was not broken into and it is not lying about that. Your data simply was not only behind its wall. That is the part nobody advertises.
September produced two separate incidents, by two different routes. One went through a supplier's staff. The other went through a process built to answer official requests. Neither required defeating a bank's defences, and both produced the same result for the customer.
Unauthorised access to DriveWealth on 4 and 5 September, attributed to a sophisticated social engineering campaign. The records date from when Revolut customers held US stock accounts directly with the broker, an arrangement moved away from between December 2023 and June 2025. Exposed: names, email addresses, phone numbers, postal addresses, employment information, citizenship, age, gender and partial account numbers.
Fraudulent information requests sent from a legitimate government agency email domain. Identity documents including passports and driving licences, together with dates of birth, addresses and contact details, were among the data disclosed. The address was blocked once discovered, and the agency, law enforcement and regulators were alerted.
Nobody lost a balance. What was lost is the raw material for impersonation: the details that make a fraudulent call sound legitimate. Security researchers reported phishing messages aimed at Revolut customers within days. Stolen identity data does not expire, and it does not have to be used by whoever took it.
You can outsource a function. You cannot outsource the consequence. Every supplier in the chain is another copy of your customer, another perimeter you do not control, and another set of people who can be persuaded.
MobiBank is being built as a closed system. The core, the transaction rail and the customer data perimeter are being developed in house rather than rented from a chain of third parties. That decision is slower, more expensive and harder to finance than the assembled route. It is also the only version of this business we are willing to put our name on.
The transaction path is being built rather than assembled, so a partner's incident does not automatically become a customer's incident.
What is never collected cannot leak, and what is never copied outward cannot be taken from somebody else's network.
Alpha 1 is being developed to place protection in the hardware itself rather than only in an application running on somebody else's operating system.
Essential services intended to keep working without an internet connection, so availability does not rest on a single path either. Under development, implementation confidential.
No architecture can be declared immune, and we will not claim ours is. What architecture decides is how many doors exist, who holds the keys, and how far a single failure is allowed to travel.
Building the critical path yourself means years before the first customer, not months. It is the least fashionable decision available to a fintech company. It is also the one that determines whether a supplier's bad week becomes your customers' problem.
The platform is being developed as one system rather than a set of contracts around a customer interface, so that the parts that hold customer data are the parts the company operates.
MobiBank's Netless™ capability, intended to allow essential banking without an internet connection, rests on a patented channel. Related patent and intellectual property processes may be ongoing and the implementation is not disclosed.
Corporate structures, customer identification, cybersecurity and compliance processes are prepared in parallel with the product, before launch rather than retrofitted after growth. Every market entry remains subject to local licensing and regulatory approval.
Where a partner is genuinely required, the objective is to limit what that partner holds and for how long, rather than to accept a full copy of the customer as the price of the integration.
We are taking the time to get this correct. The alternative is to be fast now and to write one of these notices later.
We would rather take the time to build our own closed system than launch quickly on infrastructure we do not control.
Exposed identity data is used to make contact sound credible. The practical advice is the same whichever provider you bank with.
A caller who recites your address, your employer or your date of birth has not proved they work at your bank. Those are exactly the fields that were exposed.
There is no such thing as a safe account your bank needs you to transfer to. Any request of that shape is fraud, without exception.
Codes, push approvals and app confirmations exist to stop other people acting as you. Approving one because a caller said it would arrive defeats the entire mechanism.
Close the message, open the application yourself and check. Links and numbers supplied inside an unexpected message are the part you cannot verify.
No. In the September 2026 incidents affecting Revolut customers, the company stated that its own systems and infrastructure were not accessed or compromised. One incident occurred at DriveWealth, a United States brokerage partner. The other involved fraudulent information requests sent from a legitimate government agency email domain.
They were two different sets. In the brokerage incident: names, email addresses, phone numbers, postal addresses, employment information, citizenship, age, gender and partial account numbers, with passwords, payment details and identity documents reported as not part of it. In the impersonation incident: identity documents including passports and driving licences, together with dates of birth, addresses and contact details.
A closed system is one where the bank builds and operates the critical path itself: the core, the transaction rail and the place customer data lives, rather than assembling them from external providers who each hold a copy of the customer. The trade is speed for control.
No system can be called immune, and any company claiming otherwise should be read sceptically. What a closed architecture changes is the number of external parties holding customer data, the number of separate perimeters that must hold, and how far a single failure can travel before it reaches a customer.
Because nothing is bought ready made. The core, the rail, the security model and the compliance processes are developed before the first customer rather than integrated around one. MobiBank is a development-stage company and certain capabilities described here remain under development.
MobiBank is a Finnish financial technology company developing a single platform for everyday banking, payments, savings, investing and financial education, together with the Alpha 1 device and MobiBank's Netless™ capability. The company is currently raising its Series A round.
Request allocationThis article describes publicly reported security incidents affecting a third-party company and its partners, based on the sources listed above and on statements made by the companies concerned. It is provided for general information and comment only. Certain statements on this page describe technologies, capabilities and commercial initiatives that remain under development, evaluation, negotiation or regulatory review, and related patent and intellectual property protection processes may be ongoing. These statements represent current objectives and should not be interpreted as confirmation of commercial availability, or as a guarantee of complete functionality, availability or coverage in all circumstances. Technical implementation details are confidential. Nothing on this page constitutes investment advice, an offer to sell or a solicitation of an offer to buy any securities.
Fill out the form below, and we will be in touch shortly.