Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
Wealthsimple

Wealthsimple Vendor Cyber Rating & Cyber Score

wealthsimple.com

Better than your bank. wsim.co/legal


Wealthsimple A.I CyberSecurity Scoring

Wealthsimple
Company Information
Website:http://www.wealthsimple.com
Employees number:1,823
Number of followers:231,751
NAICS:52
Industry Type:Financial Services
Homepage:wealthsimple.com
Wealthsimple Risk Score (AI oriented)
Between 550 and 599
logo
WealthsimpleFinancial Services
Updated:
02/04/2026
551/1000
Very Poor
Ca
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
Wealthsimple Global Score (TPRM)
xxxx
logo
WealthsimpleFinancial Services
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

Wealthsimple
WealthsimpleVery Poor
Current Score
551Ca (VERY POOR)
01000
3 incidents
-112.5 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
563Before Incident
MAY 2026
557Before Incident
APRIL 2026
555Before Incident
MARCH 2026
550Before Incident
FEBRUARY 2026
547Before Incident
JANUARY 2026
543Before Incident
DECEMBER 2025
538Before Incident
NOVEMBER 2025
534Before Incident
OCTOBER 2025
529Before Incident
SEPTEMBER 2025
615Before Incident
Breach
05 Sep 2025Wealthsimple
Wealthsimple

Wealthsimple Data Breach

521After Incident
CRITICAL-94
WEA3363933090625
Wealthsimple, a Canadian online investment management service with over CAD$84.5 billion in assets and 3 million users, suffered a data breach on August 30th. Attackers exploited a compromised third-party software package to unauthorizedly access personal data of less than 1% of its clients. The stolen information included contact details, government IDs (e.g., Social Insurance Numbers), financial account numbers, IP addresses, and dates of birth. While no funds or passwords were stolen, the breach exposed sensitive customer data, prompting Wealthsimple to offer two years of free credit monitoring, dark-web monitoring, identity theft protection, and insurance to affected users. The company advised enabling 2FA, avoiding password reuse, and staying alert for phishing attempts. Though initially linked to the ShinyHunters extortion group’s Salesforce breaches, Wealthsimple later clarified the incident was unrelated to Salesforce. The breach highlights risks from third-party vulnerabilities in financial services.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
Financial Loss: None (no funds stolen)Contact detailsGovernment IDsFinancial details (e.g., account numbers)IP addressesSocial Insurance Numbers (SIN)Dates of birthBrand Reputation Impact: Potential reputational harm due to exposure of sensitive customer dataIdentity Theft Risk: High (SINs, government IDs, and personal details exposed)Payment Information Risk: Low (no payment info explicitly mentioned as compromised)
DATA BREACH
Personal information (contact details)Government-issued IDsFinancial account detailsIP addressesSocial Insurance Numbers (SIN)Dates of birthNumber Of Records Exposed: Less than 1% of 3 million customers (exact number undisclosed)Sensitivity Of Data: High (includes SINs and government IDs)Data Exfiltration: YesPersonally Identifiable Information: Yes (SINs, dates of birth, contact details, government IDs)
AUGUST 2025
746Before Incident
Breach
30 Aug 2025Wealthsimple
Wealthsimple

Breach Roundup: Vidar Infostealer Enhancements, Akira Ransomware Resumes Attacks, and Multiple Data Breaches

615After Incident
CRITICAL-131
WEA0053000100225
Wealthsimple, a Canadian online investment platform managing over $61 billion in assets, disclosed a data breach affecting less than 1% of its 3 million customers (~30,000 individuals). The incident, detected on August 30, exposed sensitive personal data including contact details, government-issued IDs (e.g., passports/driver’s licenses), account numbers, IP addresses, Social Insurance Numbers (SINs), and dates of birth. While no customer funds or passwords were compromised, the breach involved unauthorized access to a third-party software provider’s system, allowing attackers to exfiltrate onboarding verification documents and personally identifiable information (PII) for a brief period before containment. The breach underscores risks tied to supply chain vulnerabilities in fintech ecosystems, where third-party integrations can become attack vectors. Wealthsimple emphasized that financial accounts remain secure, but the exposure of SINs and IDs heightens risks of identity theft, phishing, or fraudulent account openings. The company did not disclose the root cause (e.g., unpatched flaw, misconfiguration, or credential theft) or the specific third-party vendor involved. Regulatory scrutiny under Canada’s PIPEDA or provincial privacy laws (e.g., Ontario’s Personal Information Protection Act) is likely, given the sensitivity of the leaked data.
INCIDENT DETAILS -
TYPE
Malware (Infostealer)Data BreachRansomwareVulnerability ExploitationSupply Chain AttackUnauthorized Data ExposureBackdoorCredential TheftPhishing
MOTIVATION
Financial Gain (Credential Theft, Ransomware, Data Sales)Cybercrime-as-a-Service ProfitSupply Chain DisruptionEspionage (Alleged Russian Energy Sector Targeting)Hacktivism (Scattered Lapsus$)Data Exfiltration for Dark Web SalesPersistence in Targeted Networks (ChillyHell)
IMPACT
Financial Loss: Potential (e.g., $123,054 in BlackDB sales; Wealthsimple breach costs unspecified; Hello Gym breach impact unknown)Credentials (Vidar)Session Cookies (Vidar)Cryptocurrency Wallets (Vidar)Credit Card Data (Vidar, BlackDB)Government IDs (Sapphos, Wealthsimple)Social Insurance Numbers (Wealthsimple)Call Recordings (Hello Gym)API Keys (Cursor Exploit)Corporate Emails (KazMunayGas Phishing Simulation)Windows Machines (Vidar)SonicWall Firewalls/SSLVPN (Akira)Microsoft HPC Pack ClustersSapphos App InfrastructureCursor AI Code EditorHello Gym VoIP/Call Tracking SystemsMacOS Systems (ChillyHell)Sapphos App (Shut Down)Jaguar Land Rover (Production Halted, per Scattered Lapsus$)Potential Downtime for SonicWall VictimsDisrupted Production (Jaguar Land Rover)App Shutdown (Sapphos)Security Drill Misinterpretation (KazMunayGas)Incident Response for Wealthsimple/Hello GymRevenue Loss: Potential (e.g., Sapphos refunded premium subscriptions; Hello Gym reputational harm)Customer Complaints: Likely (Sapphos, Hello Gym, Wealthsimple)Sapphos (App Shutdown, Data Deletion)Hello Gym (1.6M Leaked Call Recordings)Wealthsimple (PII Breach)KazMunayGas (Disputed Hack Claims)BlackDB Admin (Plea Deal, Up to 10 Years Prison)Sapphos (Reported to Brazilian Cybercrime Police)Potential GDPR/Regulatory Fines (Wealthsimple, Hello Gym)High (Vidar, BlackDB, Sapphos, Wealthsimple)Government ID Selfies (Sapphos)High (Vidar, BlackDB, Wealthsimple)Credit Card Data (Vidar, BlackDB)
DATA BREACH
Credentials (Vidar, BlackDB)Payment Card Data (BlackDB)Personal Data (BlackDB, Sapphos, Wealthsimple)Government IDs (Sapphos, Wealthsimple)Social Insurance Numbers (Wealthsimple)Call Recordings (Hello Gym)API Keys (Cursor Exploit)Corporate Emails (KazMunayGas Phishing Simulation)17,000 (Sapphos)1.6M (Hello Gym Call Recordings)<30,000 (Wealthsimple, <1% of 3M)$123,054 in Stolen Data Sales (BlackDB)High (Government IDs, Credit Cards, Call Recordings, PII)Medium (Corporate Emails, API Keys)Vidar (Credentials, Wallets, Cookies)BlackDB (Stolen Data Sales)Akira (Ransomware Data Theft)ChillyHell (Ukrainian Auto Insurance Website)None (Hello Gym Leaked MP3 Files)Unknown (Vidar C2 Traffic Encrypted)MP3 (Hello Gym Call Recordings)JPEG/PNG (Sapphos ID Selfies)JSON (Cursor Tasks)Database Dumps (Sapphos Deletion)Names, Birthdates (Sapphos)Phone Numbers (Hello Gym)Social Insurance Numbers (Wealthsimple)IP Addresses (Wealthsimple)Account Numbers (Wealthsimple)
JULY 2025
746Before Incident
OCTOBER 2020
768Before Incident
Breach
17 Oct 2020Wealthsimple
Wealthsimple US, Ltd.

Wealthsimple US, Ltd. Data Breach

699After Incident
MEDIUM-69
WEA409072625
The Maine Office of the Attorney General reported a data breach involving Wealthsimple US, Ltd. on November 30, 2020. The breach occurred on October 17, 2020, due to unauthorized access through an external system, affecting 58 individuals, including one resident. Compromised information included personal details and financial account numbers.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
personal detailsfinancial account numbers
DATA BREACH
personal detailsfinancial account numbers

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for Wealthsimple ?
?
What was Wealthsimple's A.I Rankiteo Cyber Score in May 2026 ?
?
What was Wealthsimple's A.I Rankiteo Cyber Score in April 2026 ?
?
What was Wealthsimple's A.I Rankiteo Cyber Score in March 2026 ?
?
What was Wealthsimple's A.I Rankiteo Cyber Score in February 2026 ?
?
What was Wealthsimple's A.I Rankiteo Cyber Score in January 2026 ?
?
What was Wealthsimple's A.I Rankiteo Cyber Score in December 2025 ?
?
What was Wealthsimple's A.I Rankiteo Cyber Score in November 2025 ?
?
What was Wealthsimple's A.I Rankiteo Cyber Score in October 2025 ?
?
What was Wealthsimple's A.I Rankiteo Cyber Score in September 2025 ?
?
What was Wealthsimple's A.I Rankiteo Cyber Score in August 2025 ?
?
What was Wealthsimple's A.I Rankiteo Cyber Score in July 2025 ?
?
What is the average per-incident point impact on Wealthsimple's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with Wealthsimple ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view Wealthsimple's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?