BlackTree Security · Infrastructure · Automation · AI

DriveWealth Breach Notice May Name the Broker Behind the App

DriveWealth says personal information was copied during network access on 4 and 5 September 2026. The Texas attorney general lists 2,556,688 affected residents. Those records do not provide a US total.

DriveWealth works through other financial institutions, including introducing brokers and investment advisers. A customer may therefore recognise the investing app or partner firm but not the infrastructure provider named in the notice. Verifying the message with that known institution is the first practical step.

The state figures describe different groups

DriveWealth says the access was contained on 5 September. Its sample notice says the document review ended on 28 September, while the Texas register published its row on 2 October.

The sample notice gives approximately 62,074 affected Rhode Island residents. DriveWealth’s current page rounds the same Rhode Island population to approximately 62,000. Both figures describe Rhode Island, not separate groups. Neither should be added to the Texas count or treated as a national total.

The sample redacts each recipient’s fields as <PII>. The Texas row lists name, Social Security number and financial information, but those categories do not automatically apply to every person.

The company says brokerage systems were separate

DriveWealth says its production brokerage and client platform were separate from the affected network. It reports no unauthorised trades, transfers, withdrawals, ACAT requests, or balance or position changes.

The company also says passwords and payment-card or bank-account details were not compromised and reported no known misuse as of 7 October. These are time-bound company findings, not independent forensics.

BlackTree recommends verifying the relationship first

  • Open the investing app or partner website yourself, or call a number already on file. Ask whether the account was introduced to or cleared through DriveWealth and which fields applied to you.
  • If your notice says a Social Security number was affected, consider freezes with all three nationwide credit bureaus. Keep the confirmation details somewhere separate from the account.
  • Enable multi-factor authentication where available. Review balances, trades, transfers, withdrawals and linked-bank changes, then report anything unfamiliar through a trusted channel.
  • Treat unexpected breach emails, texts and calls as untrusted. BlackTree’s Trezor and Brevo analysis explains why even a real communications channel should not replace independent verification.
  • Keep the notice. If its description does not match your relationship or records, ask the institution for a written clarification.

Primary sources: DriveWealth’s US customer notification, observed 7 October 2026; Massachusetts sample notice 2026-1706; and the Texas attorney general’s breach register, row published 2 October 2026.

Leave a Reply

Your email address will not be published. Required fields are marked *