← Finance
C

Wise

Notable issues
Wise plc · 🇬🇧 United Kingdom
PolicyApp PermissionsNetwork TrafficFirmwareRegulatory
Technical details
App: com.transferwise.android
Manufacturer: Wise plc

⚠️ The bottom line

Wise didn't get hacked. Wise gave your data to a bank that got hacked. Evolve Bank & Trust -- Wise's partner for US dollar accounts -- was hit by LockBit ransomware in 2024. Seven point six million records stolen: names, addresses, dates of birth, Social Security numbers. Published on the dark web. Wise had shared customer KYC data with Evolve: your passport scan, your proof of address, your identity documents. Wise's own servers were fine. Your data wasn't on Wise's servers anymore. It was on Evolve's servers, which were anything but fine. This is the fintech supply chain problem: you trusted Wise, Wise trusted Evolve, and Evolve got ransomwared. Your Social Security number is on the dark web because of a bank you've never heard of. To use Wise, you scan your passport, provide your address, declare your source of funds, and submit your identity documents. Wise needs this data -- regulations require it. But regulations don't require your banking partners to protect it. Evolve Bank & Trust proved that. Your passport scan, submitted to Wise in good faith, ended up on the dark web through a bank you never chose. And because Wise operates in dozens of countries, your data is subject to government access requests from every jurisdiction. A money transfer from the UK to India means your data can be requested by British and Indian authorities. KYC data is mandatory to collect and impossible to un-collect. Once it's in the system, it stays -- even when the system's partners get ransomwared.

Legal jurisdiction
🇬🇧 United Kingdom (headquarters)
Investigatory Powers Act read more →
Govt can bulk-intercept internet traffic and force companies to remove encryption
Online Safety Act read more →
Ofcom can require scanning of private messages for illegal content
Audited by: Deloitte (SOC 2 Type II, Jun 2024)
An audit is a snapshot, not a guarantee. How reliable are these auditors?
Spying
2/4 MODERATE
Is someone spying on me?
Data Sharing
2/4 MODERATE
Who gets my data?
Security
3/4 HIGH
Is it actually secure?
Honesty
1/4 LOW
Can I trust what they say?
CONFIGURE High-risk areas that can be partially mitigated with settings changes.
3Contradictions
2Critical
1High
0Medium
3Sources
Findings by concern
Spying 2/4 MODERATE 1 finding
⚡ highmarketing claims vs regulatory findings
Wise records your phone calls. Reads your online chat logs. Collects your email content. Researches publicly available media stories about you. All under GDPR's "legitimate interests" -- a legal basis that doesn't require your consent. Wise decides what's in its interest and processes your data accordingly. Its Abu Dhabi subsidiary was fined for failing AML controls -- couldn't identify where high-risk customers' money came from. The transparent alternative to banks that records your calls, reads your chats, researches you online, and failed to track suspicious money flows. Transparency for customers. Opacity for compliance.

What they claim: Wise markets itself as the transparent, trustworthy alternative to traditional banks for international money transfers.

What we found: Wise's subsidiary in Abu Dhabi was fined by the FSRA in August 2022 for failing to identify the source of funds for high-risk customers and lacking "adequate systems and controls" for anti-money laundering compliance. Wise processes data under GDPR's "legitimate interests" basis -- a catch-all that doesn't require user consent. This means Wise can collect, process, and share customer data without asking permission, as long as it determines the processing serves its own business interests. Wise's privacy policy states it does not sell personal data -- but it collects transaction data, call recordings, online chat logs, email content, device info, and IP addresses. For enhanced due diligence, Wise reviews publicly available media stories and websites about customers. The transparent alternative to banks records your phone calls, reads your emails, and researches you online -- all under "legitimate interests" that require no consent.

Security 3/4 HIGH 2 findings
⚠️ criticalmarketing claims vs third party research
Wise didn't get hacked. Wise gave your data to a bank that got hacked. Evolve Bank & Trust -- Wise's partner for US dollar accounts -- was hit by LockBit ransomware in 2024. Seven point six million records stolen: names, addresses, dates of birth, Social Security numbers. Published on the dark web. Wise had shared customer KYC data with Evolve: your passport scan, your proof of address, your identity documents. Wise's own servers were fine. Your data wasn't on Wise's servers anymore. It was on Evolve's servers, which were anything but fine. This is the fintech supply chain problem: you trusted Wise, Wise trusted Evolve, and Evolve got ransomwared. Your Social Security number is on the dark web because of a bank you've never heard of.

What they claim: Wise positions itself as the transparent, honest alternative to traditional banks: "The cheap, fast way to send money abroad" with a mission to "money without borders."

What we found: In July 2024, Wise disclosed that customer data was exposed in a ransomware attack on Evolve Bank & Trust, a US banking partner Wise used to provide USD account details from 2020 to 2023. The LockBit ransomware gang stole data including names, addresses, dates of birth, Social Security numbers, and other identity document numbers from 7.6 million Evolve customers across its fintech partners. The data was published on the dark web after Evolve refused to pay the ransom. Wise's own systems were not breached -- the vulnerability was in the banking partner Wise shared customer data with. This supply chain breach illustrates a fundamental fintech risk: your data is only as secure as the weakest partner in the chain. Wise collected sensitive KYC data (passport scans, proof of address, source of funds) and shared it with a bank that stored it insecurely enough to be stolen by ransomware.

⚠️ criticalpolicy claims vs app permissions
To use Wise, you scan your passport, provide your address, declare your source of funds, and submit your identity documents. Wise needs this data -- regulations require it. But regulations don't require your banking partners to protect it. Evolve Bank & Trust proved that. Your passport scan, submitted to Wise in good faith, ended up on the dark web through a bank you never chose. And because Wise operates in dozens of countries, your data is subject to government access requests from every jurisdiction. A money transfer from the UK to India means your data can be requested by British and Indian authorities. KYC data is mandatory to collect and impossible to un-collect. Once it's in the system, it stays -- even when the system's partners get ransomwared.

What they claim: Wise collects extensive KYC (Know Your Customer) data as required by financial regulations: passport or ID scans, proof of address, source of funds declarations, and transaction history.

What we found: KYC data is among the most sensitive personal information: it contains everything needed for identity theft -- full legal name, date of birth, address, government ID numbers, and photographs of identity documents. Wise holds this data for millions of customers across multiple jurisdictions. The Evolve breach demonstrated that this data can be exposed through third-party banking partners that Wise shares it with. Financial regulations require KYC collection but do not mandate how securely banking partners store it. Wise responds to government data requests from multiple jurisdictions -- any government where Wise operates can request customer data. The international nature of the service means your financial data is subject to the data access laws of every country Wise operates in, not just your home country. A transfer from the UK to India subjects your data to both UK and Indian regulatory access.

Sources