Stake and DriveWealth data breach: what was exposed and what to do

Contact details and account snapshots were exposed at Stake’s US broker. Passwords, bank details and ID documents were not.

Published

Last reviewed: · 5 min read

The short answer

Stake has notified customers that DriveWealth had a data security incident. DriveWealth is the US partner that provides US trading and wallet functionality for Stake Wall St and several other investing platforms. Stake says its own systems were not accessed.

For affected customers the exposed data may include:

  • Name, email address, phone number and postal address.
  • W-8 or W-9 tax status and country of taxation.
  • The DriveWealth account number, which is the Stake Wall St account number.
  • A snapshot of total portfolio value, not individual holdings.
  • A snapshot of cash balance and buying power.

According to DriveWealth’s investigation as reported by Stake, these were not accessed:

  • Stake logins and passwords, which Stake does not share with DriveWealth.
  • Tax file numbers and other government ID numbers.
  • Bank account details.
  • Passport, licence and other ID document images.
  • Individual positions and trading history.

DriveWealth says the incident is contained. Stake says no unauthorised trading, transfers or withdrawals occurred.

What is known and what is not

Stake published its notice on 21 September 2026 and is emailing affected customers directly. It has notified the Office of the Australian Information Commissioner and the New Zealand Privacy Commissioner. Hatch, a New Zealand platform, has told its customers that an unauthorised party accessed DriveWealth data on 4 and 5 September.

The number of affected customers has not been disclosed. Nor has the attacker or how access was gained. DriveWealth’s investigation is continuing, so treat anything more specific as unconfirmed.

Why this data still matters

No password was taken, but the exposed fields are what a convincing scam needs. A caller who knows your name, your account number and roughly what your portfolio is worth sounds like the real support team.

Expect messages that quote your balance and ask you to “verify” your account. Some will ask you to move funds to a “safe” account. Tax residency details make fake tax or W-8 renewal emails more believable. Stake says it will never ask for your password or one-time codes, and never ask you to move money to keep it safe.

What to do if you are affected

These steps go further than the official notice. They help whether or not you received an email.

  1. Verify any notice yourself. Open the Stake app, or type hellostake.com into your browser. Do not use links in emails or texts.
  2. Change your Stake password. Then change it anywhere else you reused it. A password manager makes unique passwords easy.
  3. Turn on two-factor authentication with an authenticator app. SMS codes can be intercepted through a SIM swap.
  4. Check your account. Review recent activity and withdrawal settings. Confirm your email and phone number are still yours.
  5. Treat contact about your portfolio as suspect. Hang up and call back on a number from the app. Never share a code or PIN.
  6. Protect your mobile number. Ask your telco for a port-out PIN or extra verification before any SIM change.
  7. Secure your email account. It is how passwords get reset, so give it a unique password and two-factor too.
  8. Get help if you suspect identity misuse. IDCARE is a free Australian identity and cyber support service.
  9. Report scams and cybercrime. Report scam contact to Scamwatch. Report cybercrime to ReportCyber at cyber.gov.au.
  10. Consider a credit ban only if misuse is likely. A ban is free and lasts 21 days at first. Apply with Equifax and Experian. Experian now covers the former illion file.
  11. In New Zealand, contact Netsafe or CERT NZ, now part of the National Cyber Security Centre.

Questions for Stake go through its security report form. The OAIC explains how to respond to a breach notification and how notifiable data breaches work.

The lesson for businesses: your data lives with your vendors

Stake’s systems were not breached, yet its customers’ data was. That data sat with a partner that needed it to run the service. Most businesses have the same exposure through payroll, CRM, payments and cloud providers.

  • Know which vendors hold customer data, and which fields.
  • Send vendors only the data they need, and ask what they retain.
  • Review each vendor’s security before signing, then yearly.
  • Write breach notification times into the contract.
  • Rehearse telling your customers about a breach you did not cause.

Retention matters too. Former Stake customers were affected because records must be kept for years. Your own obligations are set out on our Privacy Act readiness page.

If nobody owns vendor risk in your business, a vCISO retainer can. A cloud security review maps what your own accounts expose. More reading is in the guides index, or talk to us.

Sources

Facts on this page were checked against these sources on 23 September 2026. We will update the page if Stake or DriveWealth publish new information.

Instant quote

Get an instant quote in 2 minutes

Answer four questions. The indicative price updates as you go. Prices are ex GST.

Indicative until we confirm scope in writing, within one business day. We use your details only to reply. See our Privacy notice.

Questions before you book

Practical answers.

Was my Stake account hacked?

Stake says its own systems, app and website were not affected. DriveWealth told Stake that no unauthorised trading, transfers or withdrawals occurred. The incident exposed personal information held by DriveWealth, not Stake logins.

What data was exposed in the DriveWealth breach?

For affected Stake customers it may include name and contact details, W-8 or W-9 tax status and country of taxation, and the Stake Wall St account number. It may also include a snapshot of total portfolio value, cash balance and buying power. Stake is emailing each affected customer with the items that apply to them.

How many people were affected?

Neither Stake nor DriveWealth has disclosed a number. Stake says not every customer is affected. Hatch, a New Zealand platform that also uses DriveWealth, has not disclosed a number either.

Do I need to change my Stake password?

Stake says passwords were not shared with DriveWealth and were not involved. It still recommends a reset as a precaution. If you reused that password anywhere else, change it there too.

I closed my Stake account years ago. Could I be affected?

Yes. Stake says some people with inactive Stake Wall St accounts were affected. DriveWealth must keep customer records for as long as US law requires.

Should I put a ban on my credit report?

A ban suits people who believe they are, or are likely to be, victims of identity fraud. The data listed here does not include ID documents or tax file numbers, so most people will not need one. If you see signs of misuse, a ban is free and lasts 21 days at first.

Let’s scope it

Do you know which vendors hold your customer data?

Tell us who your key suppliers are. We will scope a short review of what they hold and how a breach would reach you.

Request a quote