Skip to content
Supply chainContained

Wealthsimple discloses data breach after third-party software compromise

Canadian fintech Wealthsimple confirmed that a supply-chain compromise of a third-party software package exposed personal data — including contact details, government IDs, Social Insurance Numbers and account numbers — for a small fraction of its roughly three million clients.

Victim
Wealthsimple

On 5 September 2026, Wealthsimple — one of Canada's largest online investment and money-management platforms, with roughly three million clients — confirmed a data breach after detecting unusual activity in its systems on 30 August. The company traced the incident to a compromised third-party software package used within its environment, making it a supply-chain attack rather than a direct breach of Wealthsimple's own applications.

Wealthsimple said the exposure affected fewer than one percent of its clients, but the categories of data involved were sensitive. Depending on the client, the accessed information could include names and contact details, government-issued identification, Social Insurance Numbers, dates of birth, account numbers, and IP addresses. Crucially, the firm stressed that passwords were not compromised, no client accounts were accessed, and no funds were moved or stolen.

Containment and response

The company said its internal security team, backed by external experts, contained the intrusion within hours of detection and launched an investigation, notifying privacy and financial regulators. Wealthsimple emailed all affected clients directly and offered two years of complimentary credit monitoring and dark-web monitoring, along with identity-theft protection and insurance. A senior executive publicly apologised to customers, emphasising that no account details had been misused.

Because the intrusion was quickly contained, limited to a minority of clients, and produced no evidence of account takeover or financial loss, Wealthsimple characterised the situation as contained — though the exposure of government IDs and Social Insurance Numbers left affected customers at heightened risk of identity fraud and follow-on phishing.

Timeline

  1. Wealthsimple detects unusual activity traced to a compromised third-party software package used in its environment and contains the intrusion within hours.

  2. The firm publicly discloses the breach and completes direct email notifications to affected clients, offering two years of free credit and dark-web monitoring plus identity-theft protection.

Sources

  1. bleepingcomputer.comhttps://www.bleepingcomputer.com/news/security/financial-services-firm-wealthsimple-discloses-data-breach/
  2. securityweek.comhttps://www.securityweek.com/fintech-firm-wealthsimple-says-supply-chain-attack-resulted-in-data-breach/
  3. infosecurity-magazine.comhttps://www.infosecurity-magazine.com/news/wealthsimple-confirms-data-breach/
  4. cbc.cahttps://www.cbc.ca/news/business/wealthsimple-data-security-breach-1.7626565

Related incidents

Supply chainContained

Leak at Alan (via Almerys)

On 23 May 2026, French digital health insurer Alan warned members that a cyberattack on its third-party claims processor Almerys had exposed their personal data — names, dates of birth, social security numbers and insurance contract details — though payment, password and health data were spared.

Victim
Alan
Supply chainUnknown

Data leak at Wemind (via Allianz)

On 28 January 2026, a data leak affecting Wemind, the French neo-insurer for freelancers and small businesses, exposed members' contact details — names, postal addresses, email addresses and phone numbers — through its Allianz insurance/back-office channel.

Victim
Wemind