Bamboo has alerted users to cybersecurity Incident at US Brokerage partner DriveWealth.
NewsOnline Nigeria reports that Bamboo, a Nigerian investment platform, has informed its users of a cybersecurity incident involving its United States brokerage partner, DriveWealth, after unauthorised access to the partner’s systems in September 2026.
In an email to customers, Bamboo Chief Executive Officer Richmond said the incident occurred between September 4 and 5, 2026, adding that users’ funds and investments were not affected.
ALSO: New Google data reveals Nigeria’s favorite coffee-related searches in 2026
The company said no money was lost or moved and that Bamboo account credentials, investments and transaction information remained secure.
According to the notification, DriveWealth has secured the affected systems, blocked further unauthorised access and strengthened its security measures.
Personal information may have been exposed
Bamboo warned that the information potentially exposed includes customers’ names, email addresses, phone numbers, citizenship, age, gender, partial DriveWealth account numbers and a snapshot of their total portfolio value as of September 4.
The company stressed that its customers’ passwords, account credentials, funds, investments and payment information were not compromised.
The incident appears to extend beyond Bamboo’s customer base. Other investment platforms that use DriveWealth’s brokerage services, including Australia’s Stake and New Zealand’s Hatch, have also notified customers about the security incident.
DriveWealth’s own incident notice confirms that personal information was copied from its network but says it found no unauthorised brokerage activity, including trades, transfers or withdrawals. The company also said its production brokerage and trading systems were not affected.
Bamboo advises users to remain vigilant
Bamboo said customers do not need to take any immediate action because their accounts, funds and investment holdings remain intact.
However, the platform advised users to be cautious about unexpected emails, phone calls and text messages requesting personal information, passwords, PINs, verification codes or financial details.
The company emphasised that it would never ask customers to disclose their passwords, PINs or one-time verification codes.
Customers with questions or concerns about suspicious communications were advised to contact Bamboo through its support or compliance email addresses.
The incident highlights the security risks associated with third-party service providers in the digital investment industry, where a breach at a brokerage infrastructure provider can affect customers using different financial platforms.




















