Hundreds of thousands of Nigerians who trade United States stocks through Bamboo just received an email nobody wants to open.
The message confirmed that an unauthorized party accessed personal data held by the app’s American brokerage partner.
No money was moved, no trades were executed, and no passwords were compromised during the incident that occurred in early September.
But the data that was exposed included each user’s total portfolio value, turning a distant American cybersecurity incident into something deeply personal for Bamboo’s Nigerian user base.
DriveWealth breach exposed names, phone numbers, and portfolio snapshots
DriveWealth LLC, the New York-based broker-dealer that executes US stock trades for Bamboo, discovered unauthorized network access between September 4 and September 5, 2026.
The company disclosed the breach through a data breach report filed with the Texas Attorney General’s Office posted on October 2, 2026, listing names, Social Security numbers, and financial information among the affected data categories.
More stories on FinanceTracked:
- Dangote Foundation sweetens the deal for student investors
- Dangote IPO stirs a fintech resilience awakening
- PlotWeaver and EndowPay are rewriting the bill script
Bamboo Chief Executive Officer Richmond Bassey confirmed the specific data categories affecting Nigerian users in an email sent to affected customers.

The exposed information included names, email addresses, phone numbers, country of citizenship, age, gender, and partial DriveWealth account numbers, Bassey confirmed in the letter.
The email also disclosed that a snapshot of each user’s total portfolio value as of September 4, 2026, was among the compromised categories.
That portfolio-value detail hands unauthorized parties an exact picture of how much each affected user holds in investments, a data point that personal contact details alone would not reveal.
Similar exposure patterns appeared across DriveWealth’s other global partners, with Hatch and Stake users also seeing leaked cash balances and aggregate portfolio snapshots among compromised data, BrokerChooser reported.
Bassey stressed that Bamboo account credentials, funds, and investments were not compromised, and no transaction or payment data was affected.
DriveWealth powers Nigerian apps serving hundreds of thousands of investors
DriveWealth provides brokerage infrastructure for several Nigerian investment platforms, including Bamboo, Chaka, and Trove, that give retail investors direct access to US-listed equities.
The company’s application programming interface (API) handles order execution, custody, and clearing for a generation of new Nigerian stock market participants who entered investing through mobile-first platforms over the past five years.

Bamboo alone had accumulated more than 300,000 users in Nigeria by early 2022, with nearly 75% of its early adopters having never previously traded stocks, TechCrunch reported.
That user base has grown substantially since then, and the platform recently served as a distribution channel for the Dangote Refinery public offer, an event that tested the resilience of Nigeria’s fintech infrastructure.
The breach extended far beyond Nigerian users, with the state attorney general filing alone listing more than 2.5 million Texans as affected.
International platforms including Revolut, Stake, and Hatch also confirmed that their users’ data held at DriveWealth was compromised, The Next Web reported. Australian platform Pearler separately disclosed the same breach.
Nigerian investors face a targeted phishing risk from exposed data
The financial risk from this breach is indirect, centering on what cybercriminals can assemble from the combination of personal details and portfolio data.
Nigeria already records more than 4,700 cyberattacks weekly, and more than 281,000 leaked user accounts surfaced in the first quarter of 2026 alone, cybersecurity professional Anthony Fakiyesi told the News Agency of Nigeria.
Fakiyesi’s warning about third-party exposure applies directly to the Bamboo situation, where users trusted one platform, but their data sat on another company’s servers across a different continent and regulatory jurisdiction.

“Organizations do not just manage their own vulnerabilities; they inherit risk from every system they trust,” Fakiyesi said.
When attackers hold a person’s name, phone number, email address, citizenship, and exact portfolio balance, they possess everything needed for a convincing targeted phishing campaign.
This concern extends across Nigeria’s rapidly expanding digital finance landscape, where user trust remains the decisive factor separating platform adoption from abandonment in the fintech sector.
What the DriveWealth breach means for Bamboo users going forward
Key details from the DriveWealth breach disclosure
- Names, emails, phone numbers, citizenship, age, gender, and partial account numbers were exposed, Bassey confirmed in his email to affected users.
- A snapshot of each user’s total portfolio value as of September 4, 2026, was included in the compromised data, the CEO letter stated.
- Account credentials, passwords, funds, and investment positions were not affected by the incident, Bamboo stated in its user notification email.
- DriveWealth contained the breach by September 5, 2026, and completed its investigation on September 28, 2026, ClaimDepot reported.
- Users who suspect suspicious contact can reach Bamboo at support@investbamboo.com or compliance@investbamboo.com for direct verification assistance, Bassey noted.
Bassey told users that Bamboo will never ask for a password, PIN, or one-time code outside of its application, and any unsolicited message requesting such information is fraudulent.
DriveWealth is offering affected US-based users 12 months of complimentary triple-bureau credit monitoring and credit report services through TransUnion, the company disclosed in its breach notification letter.





