IT Brief New Zealand - Technology news for CIOs & IT decision-makers
New Zealand
Hatch warns customers of DriveWealth data exposure

Hatch warns customers of DriveWealth data exposure

Tue, 22nd Sep 2026 (Today)
Sean Mitchell
SEAN MITCHELL Publisher

Hatch has told customers that personal information was exposed in a cybersecurity incident at its US broker partner, DriveWealth. Its own systems were not accessed.

A notice to customers said an unauthorised party accessed data held on DriveWealth systems over two days in September, including information linked to Hatch users. The compromised data may include names, addresses, phone numbers, email addresses, investor profile information such as income range and net asset range, and cash balance and portfolio value.

No unauthorised transactions were made and investment holdings were not affected, Hatch said. It also told customers that Hatch login details were not involved because those are held on Hatch systems rather than on DriveWealth infrastructure.

According to the notice, several more sensitive categories of information were not exposed. These include identity documents and their details, dates of birth, IRD numbers, foreign tax identifiers, children's account details, and other documents customers may previously have provided, such as proof of address or source-of-wealth information.

The incident highlights the operational risks that can arise when retail investment platforms rely on third-party brokers and custodial partners for market access and account infrastructure. Even when the front-end platform is not directly breached, customer records can still be exposed through suppliers that handle account data.

What Was Taken

The data involved does not appear to include passwords or tax identifiers, but it could still be useful to criminals seeking to impersonate legitimate firms. Contact details combined with portfolio values and investor profile information can make phishing emails, text messages, or phone calls appear more credible.

Hatch warned customers to take extra care with unexpected contact referring to Hatch, DriveWealth, or their investments. It said customers did not need to change their Hatch password because of the incident, and noted that two-factor authentication is required for customer accounts.

Users were also urged never to share their password or two-factor authentication code, and to avoid clicking links in suspicious messages. Customers were advised to protect their email accounts with a unique password and multi-factor authentication, along with other important online accounts.

Third-Party Exposure

DriveWealth has become a widely used brokerage and infrastructure provider for fintech investment apps, particularly those offering retail investors access to US-listed shares. That model has allowed platforms in markets including New Zealand to offer overseas investing without building their own execution and custody systems from scratch.

But the arrangement also means customer data can sit across several systems operated by different parties. When a breach affects a service provider, the fallout can quickly spread across multiple brands whose customers may have no direct relationship with the underlying broker.

Hatch said it is continuing to work closely with DriveWealth as the investigation progresses and that relevant authorities are being engaged. It added that DriveWealth investigated the incident with support from independent cybersecurity experts.

The customer message said DriveWealth had not identified an ongoing threat to its systems and had strengthened security controls after the breach. Hatch did not disclose how many of its customers were affected.

Customer Response

For customers, the immediate risk appears to be social engineering rather than direct account takeover. Because the exposed information may include financial profile details and account value data, fraudsters could use it to craft messages that appear tailored to a person's circumstances.

That could include emails or calls that cite a customer's investments, suggest urgent account action is needed, or claim to come from Hatch or DriveWealth support teams. Security specialists have long warned that even partial financial data can make scams more convincing.

Hatch sought to reassure users that holdings were unaffected and that no unauthorised transactions had been identified. It also said it would contact customers again if it learned anything that changed what the incident means for them.

The message apologised to users, saying: "We know you trust us to safeguard your personal and financial information, and we're sorry this happened. We're treating this incident very seriously and will continue working closely with DriveWealth and the relevant authorities. We'll contact you again if we learn anything that changes what this means for you."