DriveWealth Data Security Incident

We have been informed that DriveWealth, the partner that supports U.S. trading and wallet functionality for several Australian investing platforms including Stake, has experienced a cyber incident.
September 21, 2026
We have been informed that DriveWealth, the partner that supports U.S. trading and wallet functionality for several Australian investing platforms including Stake, has experienced a cyber incident.
Since learning of this incident, we have been working with DriveWealth to understand the nature and extent of any impact to our customers. They have conducted an urgent investigation, and have now informed us that some personal information belonging to Stake customers was affected during this incident.
It is important that our customers and stakeholders understand that this incident took place within DriveWealth's environment. Stake’s systems, app and website have not been affected.
In addition, DriveWealth has informed us the incident is contained and that no unauthorised trading, transfers or withdrawals occurred on any account. Customer trading accounts and portfolios were not impacted, and you can continue to access your account and trade, deposit and withdraw as normal on Stake.
Having said that, there was some impact to personal information for some of our customers. As such, we are in the process of notifying affected customers directly via email to outline what personal information was involved, and the steps they can take to protect the security of their personal information.
What has happened
When our customers open a Stake Wall St account, we pass certain personal information to DriveWealth so that it can open and maintain the customer’s US trading account. DriveWealth provides execution, custody and clearing for Stake Wall St, which is why DriveWealth holds information about Stake customers.
DriveWealth recently notified us that it had identified a data security incident affecting part of its environment. It has since confirmed that information relating to some Stake customers was involved. DriveWealth's investigation is continuing, and we are working with them to obtain answers to key questions on behalf of our customers.
What information was impacted
Not every Stake customer is affected, and the information involved differs from person to person. Where a customer was affected, the information involved may include some or all of the following information:
Name, email address, phone number and postal address.
W-8 or W-9 tax status and country of taxation. This does not include tax file numbers or other tax identification numbers.
An aggregate value snapshot of a portfolio (but not individual holdings).
A cash balance and “buying power” snapshot.
If you are affected, the email we are sending you sets out exactly which of these applies to you. We are not able to provide individual detail through this page.
What was not involved
DriveWealth's investigation has determined that the following information was not accessed:
Stake login credentials and passwords (Stake does not share these with DriveWealth).
Tax file numbers and government identification numbers.
Bank account details.
Identity document details and images, including passports and driver licences.
Individual security positions or trading history.
If you no longer use Stake
Some people who opened a Stake Wall St account - but who may not be actively using it now - were also affected. DriveWealth is required to retain customer records for as long as the law requires, which is why information can be involved even where an account has been inactive.
What we are doing
We have been working with DriveWealth to establish exactly what happened, what information was involved, and who is affected.
We have engaged external legal and cyber security advisers to support our response.
We have notified the Office of the Australian Information Commissioner and the Office of the Privacy Commissioner in New Zealand, and provided courtesy notifications to other regulatory bodies. We will continue to assess any further notification obligations as the investigation continues.
We are monitoring for any sign that information has been misused, and we will say so on this page if that position changes.
We will keep this page updated as we have accurate and relevant information to share.
What you can do
It is important that we all remain vigilant to cyber security risk, so whether or not you have received an email from us, these steps are worth taking as a precaution:
1. Be alert to scams, especially anything that looks like it is from us
Be extra alert to emails, texts or calls claiming to be from DriveWealth or Stake, especially anything that references your personal details, or asks you to confirm details, log in or provide a one-time code. We will never ask for your password, PIN or one-time codes, and we will never ask you to move your money to keep it safe. Do not click links or open attachments in messages that look unusual or unexpected.
2. Check your recent Stake activity
Review your holdings, transfers and any changes to your account details.
3. Make sure your contact details are up to date
Check that your email address and mobile number are current, so that anything we send reaches you.
4. Reset your Stake password
Open the Stake app or go to hellostake.com and change your password. Use one you do not use anywhere else.
5. Turn on two-factor authentication
Use an authenticator app rather than SMS where you can. It is harder to intercept.
If anything feels off, verify it by contacting us directly at hellostake.com/au/support/security-report
Additional resources
If you have received a scam message, or you think your identity is at risk, you can also get free support from:
AU: Scamwatch (scamwatch.gov.au)
NZ: Netsafe (netsafe.org.nz), CERT NZ (cert.govt.nz)
If you have any specific questions for us as a result of reviewing this information, please contact our customer service at hellostake.com/au/support/security-report and our dedicated team will respond as quickly as possible.
We understand the importance people place on the security of their personal information, and we sincerely apologise for any concern or confusion this news has caused.
Subscribe
By subscribing, you agree to our Privacy Policy.

