DriveWealth Breach Hits GalaxyOne and Other Broker Partners After Employee Phishing

U.S. broker-dealer DriveWealth disclosed a short-lived security incident in early September 2026 after an unauthorized party accessed one of its corporate databases. The access window was September 4–5, 2026. DriveWealth has told partner platforms the incident is contained and that customer funds, securities, and passwords were not accessed.

GalaxyOne began notifying Brokerage customers on September 23, 2026 that DriveWealth—the firm providing brokerage services for GalaxyOne Brokerage accounts—had been hit. GalaxyOne said its own systems were not affected. According to the GalaxyOne notice, DriveWealth attributed the intrusion to a phishing attack targeting its employees.

What was accessed

Impact varies by customer. GalaxyOne said the information associated with an account that may have been accessed can include:

  • Name, email address, and phone number
  • Residential address
  • Investor profile
  • W-8/W-9 status and country code
  • Truncated DriveWealth account number

GalaxyOne said that, based on DriveWealth’s information so far, neither firm is currently aware of identity fraud, misuse, or public disclosure stemming from the incident. DriveWealth expects to send its own notices to affected customers during the week of September 28, 2026, with exact timing still to be confirmed.

Broader partners: Hatch, Stake, and others

DriveWealth sits behind multiple retail investing apps that offer U.S. market access. In mid-to-late September 2026, New Zealand and Australian platforms Hatch and Stake also warned customers that some personal data held by DriveWealth may have been exposed in the same September 4–5 incident. Both stressed that their own apps and login systems were not breached.

Those partner notices generally describe a similar data set—contact details, tax-form status (without tax ID numbers), investor-profile ranges, and in some cases cash-balance or aggregate portfolio-value snapshots—while stating that passwords, government ID documents, bank account details, and individual security holdings or trading history were not accessed. Hatch and Stake also reported no unauthorized trading or withdrawals. Hatch said it had notified New Zealand police and the National Cyber Security Centre; Stake said it had notified the Office of the Australian Information Commissioner and New Zealand’s Office of the Privacy Commissioner.

No public headcount of affected customers has been published as of September 23, 2026.

What customers should watch for

The practical risk looks more like follow-on social engineering than direct account takeover. Contact details plus investor-profile or account-value context can make phishing emails, texts, or calls look tailored. GalaxyOne and DriveWealth say they will never ask for a password or authentication code by email, phone, or text. Customers should treat unexpected messages that reference the account or urge urgent action with caution and verify through official app or website channels.

Why it matters

This incident is a reminder that fintech front ends often depend on third-party broker-dealers for custody and U.S. execution. When the underlying broker is compromised—here, reportedly via employee phishing—customer records can be exposed even when the brand customers log into every day stays intact.

DataBreaches.com would like to highlight that this DriveWealth incident, as described to GalaxyOne customers, started with phishing against employees rather than a novel zero-day. It’s crucial for organizations to use a trustworthy digital identity that can’t easily be Phished. Their domain name choice has never been more critical. Having the most authoritative version of your brand/product name in the exact match .Com along with training your staff on how to recognize these attacks can be far more effective than blindly investing millions in cybersecurity infrastructure.