Last Updated on August 26, 2026 by Mat Diekhake
Security overview
Wise shows a strong but not perfect technical security posture. TLS, HSTS, DMARC, SPF, DKIM, and major security headers are in place, and multiple external ratings classify Wise as above‑average in security. However, there are some configuration gaps (DNSSEC, CSP hardness, HttpOnly cookies) and a real third‑party breach via Evolve Bank, plus an unverified forum leak claim, which matter for risk‑aware users.
SSL/TLS & encryption
- HTTPS: Enabled on Wise’s public web properties.
- TLS version & ciphers:
- Negotiates TLS 1.3 with
TLS_AES_256_GCM_SHA384(256‑bit), with no deprecated protocols or weak ciphers detected.
- Negotiates TLS 1.3 with
- Certificate validity & issuer:
- Certificate valid with ~88 days remaining at last scan.
- Issued by DigiCert Inc.
- Uses a wildcard certificate, which slightly increases impact if the key were ever compromised.
- Mixed content: No mixed‑content issues reported in external scans.
- Security headers (web):
- HSTS: Enabled with
max-age=31536000(1 year), but withoutincludeSubDomainsorpreload. - CSP: Implemented, but flagged as unsafe in places (
unsafe-inline,unsafe-eval, insecure passive sources), increasing XSS risk surface. - Referrer‑Policy: Present and not set to unsafe‑url.
- X‑Frame‑Options: Missing per one scan; clickjacking protection relies on CSP/frame‑ancestors instead.
- HSTS: Enabled with
Hosting & infrastructure
- Primary infrastructure: Wise runs on a full‑stack, cloud‑based architecture, with security described as “central to all our infrastructure,” including machine‑learning‑based fraud detection and dedicated security teams.
- Cloud & SaaS supply chain (partial):
- Uses Amazon Web Services (AWS), GitHub, Mailchimp, Statuspage, Google Workspace, Zendesk, OnDMARC, Slack, OneTrust, Google Tag Manager, Mixpanel, Hotjar, New Relic, Google Analytics, Zoom, and others.
- DNS & email infrastructure:
- Multiple nameservers and MX records configured; zone transfers restricted.
- DNSSEC not configured, meaning DNS responses could theoretically be spoofed if other controls fail.
- Uptime reputation: Public status page and large global user base; no systemic uptime issues flagged in security ratings.
- Infrastructure risks:
- Main flagged risk is lack of DNSSEC; otherwise, CVE exposure is low because versions are not leaked and Cloudflare‑linked tech is excluded from direct CVE matching.
Malware & phishing scan
- Malware detection: External attack‑surface ratings do not show active malware on Wise’s main web properties.
- Phishing flags:
- Wise actively runs anti‑fraud and anti‑phishing programs, with dedicated teams and 7 million checks per day to stop thieves.
- Blacklist checks: No major blacklist listings reported in public security ratings.
- Redirect behavior & scripts:
- CSP is present but includes
unsafe-inlineandunsafe-eval, which can make script‑level attacks easier if an attacker finds an injection point.
- CSP is present but includes
- Third‑party injections:
- Multiple analytics and UX tools (Hotjar, Mixpanel, New Relic, etc.) are integrated; these are standard but increase the number of third‑party scripts on pages.
Privacy & data handling
- Data collected:
- Financial and identity data (names, addresses, dates of birth, contact details, IDs), plus behavioral and analytics data, due to Wise’s role as a regulated financial platform.
- Tracking technologies:
- Uses Google Analytics, Mixpanel, Hotjar, New Relic, Google Tag Manager, and other SaaS tools for telemetry and UX analytics.
- Cookie behavior:
- Secure cookies are used.
- Some cookies are not HttpOnly, which allows client‑side script access and slightly increases risk for certain attack types (e.g., XSS‑driven session theft).
- Privacy policy & legal:
- Public privacy policy and terms of service are published and maintained; Wise is regulated in multiple jurisdictions and emphasizes encryption, biometrics, and strong authentication.
- Privacy risks:
- Main risk is volume and sensitivity of data (financial + identity) combined with a large SaaS supply chain—any breach has high impact, even if likelihood is mitigated by strong controls.
App permissions (if applicable)
- Mobile & app security:
- Wise uses biometrics, two‑step authentication, and customizable controls (location permissions, auto log‑out, hiding currencies).
- Authentication options:
- Supports SSO, login with Google/Microsoft, and multiple forms of two‑factor authentication (SMS, email, hardware, software, TOTP, U2F).
- Permission alignment:
- App permissions (biometrics, device security features, location) are aligned with fraud prevention and account protection for a financial app.
Breach history
- 2024 — Evolve Bank partner breach (confirmed):
- Wise customer data was compromised via Evolve Bank & Trust, a USD account partner hit by LockBit ransomware.
- Exposed data included names, addresses, dates of birth, contact details, SSNs/EINs (US), and identity document numbers (non‑US).
- Wise notified affected customers; this is a real, supply‑chain breach impacting Wise users.
- 2026 — forum claim of ~4.9M records (unverified):
- Threat actor advertised ~4.9M Wise customer records, mostly Spanish users, with sample data including names, DOB, gender, contact details, and NIF numbers.
- Classified as unverified actor claim; Wise has not confirmed it.
- Known breaches in public databases:
- Some external scanners report no known breaches, but that typically reflects only confirmed, first‑party disclosures and may not fully capture partner incidents.
Security certifications
- Security ratings:
- LynxRadar: B+ (88/100), better than 81% of scanned companies.
- UpGuard: B (772/950) external security rating.
- Program & certifications:
- CSA STAR Level 1 compliant.
- Public security page, bug bounty / vulnerability disclosure, and extensive regulatory licensing (65+ licences worldwide).
- Regulation:
- Wise is regulated as a financial institution in multiple countries, with safeguarding requirements and separation of customer funds from company funds.
Final safety verdict
Wise is technically safe to use, but with non‑trivial risk considerations.
On the positive side, Wise has strong TLS, HSTS, DMARC/SPF/DKIM, secure cookies, mature authentication, formal certifications (CSA STAR), and above‑average external security ratings. On the caution side, CSP and cookie configuration could be hardened further, DNSSEC is missing, and there is a confirmed third‑party breach (Evolve Bank) plus an unverified large leak claim, which matter given the sensitivity of the data Wise holds.
For a purely technical safety verdict:
- Safe for normal use, with elevated impact if something goes wrong—appropriate for a major fintech, but worth pairing with strong personal hygiene (2FA, unique passwords, monitoring statements).
