Stake alerts customers after DriveWealth hack exposes personal data
Stake disclosed that a cyberattack on its US partner DriveWealth leaked customers' names, emails, phone numbers and addresses, though trading accounts and financial details remained safe.
Stake informed its users that a security incident at DriveWealth, the third-party provider handling its US trading and wallet operations, resulted in the exposure of personal information for its customers. The data compromised includes names, email addresses, telephone numbers, mailing addresses, as well as tax status and tax country, but does not cover trading accounts, portfolio holdings, tax file numbers or bank account details.
DriveWealth stated the breach stemmed from a social-engineering attack and that the threat has been neutralised. Stake emphasized that there has been no unauthorized trading, fund transfers, or withdrawals. Customers have been cautioned that the leaked details could be leveraged for targeted phishing or impersonation schemes. The company apologized for the inconvenience and said it is working closely with DriveWealth to assess the impact.
Why it matters
Customers' personal data can be misused for phishing, raising security concerns for a platform serving half-million investors.
In this story
