
Notas del episodio
Sydney-based investing platform Stake has told customers that a breach at its US broker partner, DriveWealth, exposed personal and account information that Stake shares with DriveWealth to open US trading accounts. Stake's own systems, app and website were not affected. Revolut and New Zealand's Hatch customers were caught up in the same incident.
Timeline. 4–5 September (US) — unauthorised access to DriveWealth's network via what DriveWealth calls a "sophisticated social engineering campaign"; contained 5 September per DriveWealth's notice to the California Attorney-General. 21 September — Stake publishes its incident page and notifies the OAIC and NZ's Privacy Commissioner. 22 September — Hatch notifies customers. 24 September — Revolut and DriveWealth email affected Revolut customers. 25 September — Stake emails customers (per Australian media reports). 28 September — DriveWealth's investigation and document review concludes.
What was exposed (Stake customers; varies by person). Name, email, phone and postal address; W-8/W-9 tax status and country of taxation; DriveWealth account number (same as the Stake Wall St account number); aggregate portfolio value, cash balance and buying power snapshots. Not exposed, per Stake: Stake logins and passwords; tax file numbers and government ID numbers; bank account details; identity documents; individual holdings and trading history. No unauthorised trades, transfers or withdrawals. Inactive and closed accounts were included because DriveWealth must retain records for as long as the law requires. The number of affected Stake customers has not been disclosed; no group has claimed the attack; no CVE is involved.
Lessons. Map where your customers' data goes beyond your own systems — your vendor's vendor is your risk. Check supplier contracts for a duty to report cyber incidents promptly (the Queensland Audit Office found only 2 of 36 contracts reviewed had one). Apply retention rules: records kept past their purpose are records you can lose, and the OAIC's Latitude investigation is examining exactly that. Under the Notifiable Data Breaches scheme, a breach at a supplier can still be your obligation to assess and notify. Warn customers specifically about what a scam using the leaked data would look like, and recommend authenticator-app 2FA.
Visit www.kinsoft.com.au to talk through your security and IT needs.
Sources: Stake incident page (hellostake.com); DriveWealth notice to the California Attorney-General; Hatch help centre; Cyber Daily; The West Australian; Nine.com.au; The Register; The Next Web; Finance Magnates; SecurityBrief NZ; Queensland Audit Office; OAIC.
