The short answer
Stake has notified customers that DriveWealth had a data security incident. DriveWealth is the US partner that provides US trading and wallet functionality for Stake Wall St and several other investing platforms. Stake says its own systems were not accessed.
For affected customers the exposed data may include:
- Name, email address, phone number and postal address.
- W-8 or W-9 tax status and country of taxation.
- The DriveWealth account number, which is the Stake Wall St account number.
- A snapshot of total portfolio value, not individual holdings.
- A snapshot of cash balance and buying power.
According to DriveWealth’s investigation as reported by Stake, these were not accessed:
- Stake logins and passwords, which Stake does not share with DriveWealth.
- Tax file numbers and other government ID numbers.
- Bank account details.
- Passport, licence and other ID document images.
- Individual positions and trading history.
DriveWealth says the incident is contained. Stake says no unauthorised trading, transfers or withdrawals occurred.
What is known and what is not
Stake published its notice on 21 September 2026 and is emailing affected customers directly. It has notified the Office of the Australian Information Commissioner and the New Zealand Privacy Commissioner. Hatch, a New Zealand platform, has told its customers that an unauthorised party accessed DriveWealth data on 4 and 5 September.
The number of affected customers has not been disclosed. Nor has the attacker or how access was gained. DriveWealth’s investigation is continuing, so treat anything more specific as unconfirmed.
Why this data still matters
No password was taken, but the exposed fields are what a convincing scam needs. A caller who knows your name, your account number and roughly what your portfolio is worth sounds like the real support team.
Expect messages that quote your balance and ask you to “verify” your account. Some will ask you to move funds to a “safe” account. Tax residency details make fake tax or W-8 renewal emails more believable. Stake says it will never ask for your password or one-time codes, and never ask you to move money to keep it safe.
What to do if you are affected
These steps go further than the official notice. They help whether or not you received an email.
- Verify any notice yourself. Open the Stake app, or type hellostake.com into your browser. Do not use links in emails or texts.
- Change your Stake password. Then change it anywhere else you reused it. A password manager makes unique passwords easy.
- Turn on two-factor authentication with an authenticator app. SMS codes can be intercepted through a SIM swap.
- Check your account. Review recent activity and withdrawal settings. Confirm your email and phone number are still yours.
- Treat contact about your portfolio as suspect. Hang up and call back on a number from the app. Never share a code or PIN.
- Protect your mobile number. Ask your telco for a port-out PIN or extra verification before any SIM change.
- Secure your email account. It is how passwords get reset, so give it a unique password and two-factor too.
- Get help if you suspect identity misuse. IDCARE is a free Australian identity and cyber support service.
- Report scams and cybercrime. Report scam contact to Scamwatch. Report cybercrime to ReportCyber at cyber.gov.au.
- Consider a credit ban only if misuse is likely. A ban is free and lasts 21 days at first. Apply with Equifax and Experian. Experian now covers the former illion file.
- In New Zealand, contact Netsafe or CERT NZ, now part of the National Cyber Security Centre.
Questions for Stake go through its security report form. The OAIC explains how to respond to a breach notification and how notifiable data breaches work.
The lesson for businesses: your data lives with your vendors
Stake’s systems were not breached, yet its customers’ data was. That data sat with a partner that needed it to run the service. Most businesses have the same exposure through payroll, CRM, payments and cloud providers.
- Know which vendors hold customer data, and which fields.
- Send vendors only the data they need, and ask what they retain.
- Review each vendor’s security before signing, then yearly.
- Write breach notification times into the contract.
- Rehearse telling your customers about a breach you did not cause.
Retention matters too. Former Stake customers were affected because records must be kept for years. Your own obligations are set out on our Privacy Act readiness page.
If nobody owns vendor risk in your business, a vCISO retainer can. A cloud security review maps what your own accounts expose. More reading is in the guides index, or talk to us.
Sources
- Stake: DriveWealth data security incident (21 September 2026)
- 1News: Hatch investors warned personal data may be exposed (22 September 2026)
- BusinessDesk: Hack hits Hatch and Stake’s US broker (22 September 2026)
- SecurityBrief NZ: Hatch warns customers of DriveWealth data exposure (22 September 2026)
- OAIC: Fraud and your credit report
Facts on this page were checked against these sources on 23 September 2026. We will update the page if Stake or DriveWealth publish new information.