Data leak

Wealthsimple Third-Party Vendor Data Breach

πŸ“… 2025-08-15
Primary Source β†—

Incident Details

Wealthsimple, a major Canadian online investment and financial services platform, disclosed in September 2025 that a third-party vendor had been compromised, resulting in the exposure of sensitive customer data. The breach exposed customer contact details, government-issued identity documents (passports, driver’s licenses), financial account details, and Social Insurance Numbers (SINs) for affected customers. Wealthsimple notified affected customers and the Office of the Privacy Commissioner of Canada (OPC). Given the sensitivity of identity and financial data exposed, affected customers faced significant identity theft risk.

Technical Details

Initial Attack Vector
A third-party vendor used by Wealthsimple was compromised, exposing sensitive personal and financial identity documents for affected customers

Timeline

  1. 2025-08-15 Breach occurred
  2. 2025-09-05 Publicly disclosed
  3. 2025-09-05 Customers notified