Data leak
Wealthsimple Third-Party Vendor Data Breach
Primary Source βIncident Details
Wealthsimple, a major Canadian online investment and financial services platform, disclosed in September 2025 that a third-party vendor had been compromised, resulting in the exposure of sensitive customer data. The breach exposed customer contact details, government-issued identity documents (passports, driver’s licenses), financial account details, and Social Insurance Numbers (SINs) for affected customers. Wealthsimple notified affected customers and the Office of the Privacy Commissioner of Canada (OPC). Given the sensitivity of identity and financial data exposed, affected customers faced significant identity theft risk.
Technical Details
- Initial Attack Vector
- A third-party vendor used by Wealthsimple was compromised, exposing sensitive personal and financial identity documents for affected customers
Timeline
- 2025-08-15 Breach occurred
- 2025-09-05 Publicly disclosed
- 2025-09-05 Customers notified