Wealthsimple discloses data breach after third-party software compromise
Canadian fintech Wealthsimple confirmed that a supply-chain compromise of a third-party software package exposed personal data — including contact details, government IDs, Social Insurance Numbers and account numbers — for a small fraction of its roughly three million clients.
- Victim
- Wealthsimple
On 5 September 2026, Wealthsimple — one of Canada's largest online investment and money-management platforms, with roughly three million clients — confirmed a data breach after detecting unusual activity in its systems on 30 August. The company traced the incident to a compromised third-party software package used within its environment, making it a supply-chain attack rather than a direct breach of Wealthsimple's own applications.
Wealthsimple said the exposure affected fewer than one percent of its clients, but the categories of data involved were sensitive. Depending on the client, the accessed information could include names and contact details, government-issued identification, Social Insurance Numbers, dates of birth, account numbers, and IP addresses. Crucially, the firm stressed that passwords were not compromised, no client accounts were accessed, and no funds were moved or stolen.
Containment and response
The company said its internal security team, backed by external experts, contained the intrusion within hours of detection and launched an investigation, notifying privacy and financial regulators. Wealthsimple emailed all affected clients directly and offered two years of complimentary credit monitoring and dark-web monitoring, along with identity-theft protection and insurance. A senior executive publicly apologised to customers, emphasising that no account details had been misused.
Because the intrusion was quickly contained, limited to a minority of clients, and produced no evidence of account takeover or financial loss, Wealthsimple characterised the situation as contained — though the exposure of government IDs and Social Insurance Numbers left affected customers at heightened risk of identity fraud and follow-on phishing.
Timeline
Wealthsimple detects unusual activity traced to a compromised third-party software package used in its environment and contains the intrusion within hours.
The firm publicly discloses the breach and completes direct email notifications to affected clients, offering two years of free credit and dark-web monitoring plus identity-theft protection.
Sources
- bleepingcomputer.comhttps://www.bleepingcomputer.com/news/security/financial-services-firm-wealthsimple-discloses-data-breach/
- securityweek.comhttps://www.securityweek.com/fintech-firm-wealthsimple-says-supply-chain-attack-resulted-in-data-breach/
- infosecurity-magazine.comhttps://www.infosecurity-magazine.com/news/wealthsimple-confirms-data-breach/
- cbc.cahttps://www.cbc.ca/news/business/wealthsimple-data-security-breach-1.7626565