DriveWealth Breach Exposed Hatch Customer Data
Unauthorized access to a U.S. brokerage platform in September 2026 compromised personal details of international users.
Updated on Sept. 21, 2026 in Cybersecurity

Live Poll
Do you trust investment platforms to adequately protect your personal information from data breaches?
An unauthorized party accessed data on DriveWealth systems between September 4 and September 5, 2026, leading to the exposure of personal information belonging to Hatch customers. Hatch confirmed that its own internal systems remained secure throughout the incident.
Why it matters
This incident highlights the security risks inherent in third-party data dependencies, where vulnerabilities in a backend service provider can impact the customers of dependent consumer-facing firms. It serves as a reminder of how interconnected brokerage architecture creates ripple effects across global financial services.
The incident involved unauthorized access to information held on DriveWealth systems rather than a breach of Hatch internal architecture. The scale of the intrusion remains unknown, with no specific count of exposed user records provided in the notification.
The players
DriveWealth
A U.S.-based financial technology firm providing API-driven brokerage infrastructure for global partners.
Hatch
A financial platform providing investment services to users in New Zealand by leveraging external brokerage infrastructure.
The details
DriveWealth, a U.S.-based brokerage infrastructure provider, notified its partner Hatch that an unauthorized third party bypassed its data systems. This breach allowed the actor to view personal information stored within the DriveWealth environment. Hatch reported that their proprietary internal systems were not accessed, meaning the vulnerability was isolated to the service provider layer of the stack.
Timeline
September 4, 2026: Unauthorized access to DriveWealth systems began.
September 5, 2026: The unauthorized access event concluded.
The Tech Race
This incident follows the established pattern of supply-chain vulnerabilities where a single upstream provider becomes a single point of failure for sensitive user data. It mirrors the systemic risks demonstrated by the 2023 MoveIT data breach, where software supply chain weaknesses compromised downstream users globally.
Affected customers should remain vigilant for phishing attempts, as Hatch has explicitly warned users about potential scams resulting from the data exposure. Users do not need to take action on their Hatch accounts, as the internal system was not breached.
The takeaway
The event emphasizes the necessity for users to monitor for unsolicited communications after a third-party breach. Watch for future updates from Hatch or DriveWealth regarding specific steps to secure affected personal credentials.
Further reading
For more on evolving threats to financial infrastructure, read the latest coverage on Cybersecurity.
Live Poll
Do you trust investment platforms to adequately protect your personal information from data breaches?







