Wise didn't get hacked. Wise gave your data to a bank that got hacked. Evolve Bank & Trust -- Wise's partner for US dollar accounts -- was hit by LockBit ransomware in 2024. Seven point six million records stolen: names, addresses, dates of birth, Social Security numbers. Published on the dark web. Wise had shared customer KYC data with Evolve: your passport scan, your proof of address, your identity documents. Wise's own servers were fine. Your data wasn't on Wise's servers anymore. It was on Evolve's servers, which were anything but fine. This is the fintech supply chain problem: you trusted Wise, Wise trusted Evolve, and Evolve got ransomwared. Your Social Security number is on the dark web because of a bank you've never heard of. To use Wise, you scan your passport, provide your address, declare your source of funds, and submit your identity documents. Wise needs this data -- regulations require it. But regulations don't require your banking partners to protect it. Evolve Bank & Trust proved that. Your passport scan, submitted to Wise in good faith, ended up on the dark web through a bank you never chose. And because Wise operates in dozens of countries, your data is subject to government access requests from every jurisdiction. A money transfer from the UK to India means your data can be requested by British and Indian authorities. KYC data is mandatory to collect and impossible to un-collect. Once it's in the system, it stays -- even when the system's partners get ransomwared.
What they claim: Wise markets itself as the transparent, trustworthy alternative to traditional banks for international money transfers.
What we found: Wise's subsidiary in Abu Dhabi was fined by the FSRA in August 2022 for failing to identify the source of funds for high-risk customers and lacking "adequate systems and controls" for anti-money laundering compliance. Wise processes data under GDPR's "legitimate interests" basis -- a catch-all that doesn't require user consent. This means Wise can collect, process, and share customer data without asking permission, as long as it determines the processing serves its own business interests. Wise's privacy policy states it does not sell personal data -- but it collects transaction data, call recordings, online chat logs, email content, device info, and IP addresses. For enhanced due diligence, Wise reviews publicly available media stories and websites about customers. The transparent alternative to banks records your phone calls, reads your emails, and researches you online -- all under "legitimate interests" that require no consent.
What they claim: Wise positions itself as the transparent, honest alternative to traditional banks: "The cheap, fast way to send money abroad" with a mission to "money without borders."
What we found: In July 2024, Wise disclosed that customer data was exposed in a ransomware attack on Evolve Bank & Trust, a US banking partner Wise used to provide USD account details from 2020 to 2023. The LockBit ransomware gang stole data including names, addresses, dates of birth, Social Security numbers, and other identity document numbers from 7.6 million Evolve customers across its fintech partners. The data was published on the dark web after Evolve refused to pay the ransom. Wise's own systems were not breached -- the vulnerability was in the banking partner Wise shared customer data with. This supply chain breach illustrates a fundamental fintech risk: your data is only as secure as the weakest partner in the chain. Wise collected sensitive KYC data (passport scans, proof of address, source of funds) and shared it with a bank that stored it insecurely enough to be stolen by ransomware.
What they claim: Wise collects extensive KYC (Know Your Customer) data as required by financial regulations: passport or ID scans, proof of address, source of funds declarations, and transaction history.
What we found: KYC data is among the most sensitive personal information: it contains everything needed for identity theft -- full legal name, date of birth, address, government ID numbers, and photographs of identity documents. Wise holds this data for millions of customers across multiple jurisdictions. The Evolve breach demonstrated that this data can be exposed through third-party banking partners that Wise shares it with. Financial regulations require KYC collection but do not mandate how securely banking partners store it. Wise responds to government data requests from multiple jurisdictions -- any government where Wise operates can request customer data. The international nature of the service means your financial data is subject to the data access laws of every country Wise operates in, not just your home country. A transfer from the UK to India subjects your data to both UK and Indian regulatory access.