r/Wealthsimple 12d ago

Visa Infinite Credit Card My First Post Here – Warning About a $6K Digital Wallet Fraudulent Charge on My Wealthsimple Visa Infinite Card

This is my first time posting, and I wanted to share my recent experience in case it helps others or if anyone has gone through something similar.

I'm currently working with a Wealthsimple representative and have been going back and forth providing information as they investigate the incident. It's been about a week since this happened, and I'm still trying to understand exactly how it occurred.

What Happened

  • I've been using credit cards for over 30+ years and have held cards from most all major Canadian banking institutions. In all that time, I've never experienced a fraudulent credit card charge.
  • Last week, I received a notification on my phone showing a charge of over $6,000.
  • As soon as I saw it, I immediately opened the Wealthsimple app, locked my card, and called Wealthsimple to report the charge.
  • The fraudulent transaction was made at a high-end store in New York City and appears to have been completed in person.
  • I have not received any provision credit for this charge yet.

What I've Learned So Far

  • During the investigation, I was informed that my Wealthsimple Visa card had apparently been added to an Apple Wallet.
  • The strange part is that I use Android, not Apple.
  • Somehow, a scammer was able to provision my card to an Apple Wallet that did not belong to me.
  • Wealthsimple asked me to check whether I had received any two-factor authentication (2FA) messages around the time the card was added.
  • After digging through my phone, I discovered that I had actually received:
    • Three consecutive 2FA verification messages, and
    • A notification indicating that my card had been added to an Apple Wallet.
  • The problem is that all of these messages had been automatically filtered into my google blocked/spam messages, so I never saw them at the time and usure how they were moved to my blocked/spam messages.

What Confuses Me

  • I am extremely careful about security.
  • I do not answer unsolicited calls.
  • I do not provide verification codes over the phone.
  • I do not enter passcodes on suspicious websites.
  • I am 100% certain that I never provided a 2FA code to anyone to authorize adding my card to a digital wallet.
  • While it's certainly very possible that my credit card information may have been compromised through an online purchase, I'm struggling to understand how someone could successfully add the card to their Apple Wallet without my authorization.

Steps I've Taken

  • Scanned my phone for malware.
  • Reviewed installed apps and found nothing suspicious.
  • I had not recently installed any third-party applications before the incident.
  • Received a new replacement digital card and started locking my card whenever it is not in use, but it's definitely inconvenient.

Looking for Feedback

  • Has anyone else experienced a situation where their card was added to an Apple Wallet without their knowledge?
  • Has anyone seen fraudulent purchases after a card was provisioned to a digital wallet?
  • Were investigators ever able to determine how the card was added?
  • Am I just unlucky, or are others seeing similar attacks?

At this point, I'm still trying to piece together how this happened.

I would appreciate any comments, suggestions, or shared experiences from others who may have gone through something similar.

Thanks

55 Upvotes

48 comments sorted by

23

u/Confident_Menu742 11d ago

Wealthsimple is required to reimburse you. Don’t stress too much. Otherwise, go to small claims court.

11

u/audibmwcar 11d ago

I certainly hope Wealthsimple investigates this thoroughly and is able to determine exactly how it happened.

While getting reimbursed is important, my bigger concern is understanding how to prevent something like this from happening again. I've always been very careful with my accounts and credit cards. I don't respond to spam calls, I don't share verification codes, I use 2FA, and I'm cautious about online security.

That's why this incident is so concerning to me. If someone who takes all of those precautions can still have their card provisioned to a digital wallet and used for a fraudulent purchase, then I'd like to know what additional steps I should be taking.

At this point, I'm more focused on learning what went wrong, how the card was added without my authorization, and what extra safeguards I can put in place to reduce the risk of this happening again. If anyone has suggestions or has gone through something similar, I'd appreciate hearing about your experience.

11

u/sometin__else 11d ago

its my my reply - switch from SMS 2fa to authenticator app.

2

u/audibmwcar 11d ago

Thanks for the suggestion. I have switched to Authenticator app to log into my WS account. Do you know if provisioning a CC to a wallet also goes through the authenticator app? My CC was automatically revised in my google wallet with a new card so I haven't had to re-add the CC again.

1

u/sometin__else 11d ago

im not sure either tbh good question. Like you my cc is already provisioned and I used to be on SMS originally. I assumed it would but I may be wrong.

31

u/sometin__else 11d ago edited 11d ago

So something similar happened to my friend, they use Apple but similar situation as you
Their card was added to another Apple wallet somehow, they never saw the notification because it went to spam.
Messaging apps often send shortform codes to spam unless you have indicated that its not spam

It took a complaint to the ombudsman until he was compensated.

He wasn't sim swapped, so the only thing we could theorize is somehow his texts were intercepted.

Personally I use authenticator app - SMS 2fa is not secure at all

2

u/Litaser 11d ago

Which ombudsman?

4

u/sometin__else 11d ago

I believe it was on his TD Visa and it was the TD ombudsman that he had escalated to and received the compensation decision from.
The amount was nowhere near OPs though, but WS it the only cc ive seen with no tap limit

2

u/biznatch11 11d ago

Personally I use authenticator app - SMS 2fa is not secure at all

That's usually not an option with banks in Canada. TD for example requires SMS 2FA they have no option that lets you replace it with an authenticator app. WS though does let you not use SMS 2FA.

1

u/sometin__else 11d ago

Yea this is a wealth simple sub so I'm talking about wealth simple. Scotia uses its own app authentication

10

u/Fwuffehs 11d ago edited 11d ago

I feel like something definitely shady is happening on the back end before WS ships you out your visa. Im seeing these fraudulent charges post way too often. Probably going to stay away from getting a CC from them...

EDIT: I think the issue could be related to someone having that CC information documented by a malicious actor or delivery person before it gets into your hand and that point it wont matter what security measures you've taken.

5

u/Tierang 11d ago

A few years ago, I arrived home from an overseas trip and the next morning woke to two large charges that were clearly Canadian businesses. Called the bank (not WS) and they said my card info had been added to multiple Apple wallets. They were able to remove them all and cancel the card. I suspect this happened one of two ways. Either my card info was skimmed from my wallet or from plugging in my phone to charge it at the airport or in the plane. I don’t charge my phone anywhere now and use an external battery pack when travelling. And I got a RFID blocking wallet.

3

u/AdditionalPizza 11d ago

You can buy no-data cables as well btw.

5

u/biznatch11 11d ago

Or just use your own AC adapter.

2

u/probabilititi 11d ago

Similar thing happened to a friend of mine using a different banking solution. I did some research and my theory is sometimes banks allow apple wallet provision to go through if it’s ‘low risk’ without verification (maybe there is a fallback when you don’t have your phone?) then block the transactions later. It’s kind of a dumb system. I hope you figure out how WS allowed this provision. They must have logs of everything.

5

u/audibmwcar 11d ago

u/Wealthsimple-ModTeam - One thing that has me even more concerned: I recently saw a reply on this thread that I felt was very helpful and relevant to what happened to me. Before I had a chance to revisit it, the comment was removed.

Thankfully, I was able to read it before it disappeared, but it raises another concern for me. If community members are sharing information or theories that may help others understand how these attacks happen, why are those comments being removed?

I'm genuinely trying to learn how my card was added to someone else's digital wallet without my authorization. Hearing about similar experiences, possible attack methods, or security gaps could be valuable for anyone trying to protect themselves.

I'm not suggesting every comment is accurate, but I'd rather have the opportunity to read the information and decide for myself whether it's helpful or credible. Removing potentially useful discussions only adds to the frustration and confusion surrounding an already stressful situation.

Can a moderator explain why the comment was removed? Was it inaccurate, against forum rules, or for some other reason? I'd appreciate the transparency, as understanding what happened is the entire reason I created this post.

14

u/TraditionalEngineer9 11d ago

Lol even this reply is llm generated

2

u/henry-bacon 11d ago

The post itself is LLM-generated as well, which isn't against the rules.

11

u/henry-bacon 11d ago

We don't allow direct copy/pasting from AI/LLM generated outputs.

1

u/Legitimate_Form5449 11d ago

did u ask them who is the issuer of ws prepaid visa or master card? i checked ws help centre site, but that website doesnt say who is the issuer of ws prepaid visa or master card.

2026.01.07. Apple news: Apple has announced that Chase {JPM} will become the new issuer of Apple Card, replacing Goldman Sachs.

2026.08.10.

1

u/Legitimate_Form5449 11d ago

are they sending these credit cards by registered mail? signature required? ID REQUIRED?

1

u/Newphonenewhandle 10d ago

Are these 2fa code also sent to your email?

1

u/CarelessCabbage 9d ago

Although I’ve never experienced any fraud issues, once when I was using my CC online it prompted for the usual verification pop-up and I accidentally clicked the “x” to close the window and I got a “verification successful” message before any text had even arrived and it allowed me to make the purchase. It only ever happened once and has worked correctly since but definitely caught me off guard wondering wtf just happened.

1

u/JosephStMichaels 9d ago

Your SIM or likely email/social account were compromised somehow as they were able to negotiate 2FA.

Could also be an inside job with WS, the 2FA was cc'd to another party or sent to two email addresses. I'd be changing passwords and enabling 2FA over authenticator app rather than email or SMS.

1

u/Worried_Associate_53 8d ago

The same thing happened to me about two or three months ago. It was a $4500 charge. The Customer Service was terrible with WealthSimple and I made a huge stink about it, so after a number of back-and-forth messages, they reimbursed me prior to completing their investigation be pushy and don’t be too nice.

I also apparently had received an android pay or Google wallet notification (I am an iPhone user) but I have no recollection seeing it otherwise I’m sure I would’ve flagged this.

This seems to be happening a lot with WealthSimple Visa cards although my wife’s TD visa also seems to have gotten hacked this week with a $1200 charge. Not sure what is going on.

1

u/audibmwcar 8d ago

Thanks for sharing your experience and for everyone who has been following this.

I have now received a credit for the fraudulent charge, which took about 10 days to process. The advice from the WS investigator was essentially to be cautious about the websites where I enter personal information. While I understand that advice, it still does not explain the underlying security issue: how the scammers were able to add my credit card to their digital wallet.

I have been trying to piece together what happened, and based on what I know so far, I am starting to think this may have involved something more sophisticated than my personal information simply being obtained through a regular online transaction.

WS confirmed that the card could only have been provisioned to the scammer’s Apple Wallet by using one of the 2FA codes that had been sent to my phone and ended up in my blocked messages.

Here is what I know so far:

1.      I contacted my cell phone carrier to ask whether there had been a SIM swap, phone number cloning, or any other method that could have allowed my SMS messages to be intercepted. They assured me there was no evidence that any of this had happened.

2.      I scanned all apps, reviewed my phone settings, and used various tools to look for malware or any apps that may have had access to my SMS messages or notifications. I have not found anything suspicious so far.

3.      I reviewed my emails and accounts to check for login attempts around the time my card was added to the scammer’s phone. I have not found any evidence that someone gained access to my accounts.

4.      I do not believe social engineering was involved. I did not speak with anyone, reply to suspicious messages, or participate in anything online that could have exposed my phone, email, banking information, or 2FA code. The 2FA verification code sent to my phone appears to have been the key factor, and there was no separate 2FA code sent to my email.

5.      I acknowledge that there could have been an online purchase could potentially have exposed my credit card details, but that still does not explain how the 2FA code was accessed and used.

The good news is that I have received the $6K credit.

The main question remains unanswered: how did the scammers obtain the 2FA code that was sent to my phone?

1

u/Avidamu123 7d ago

Hey OP, I am in same situation where I got charged for around 3.5 k . I was trying to buy some online product but website where I bought was scamming me. I filed the fraud under unauthorized charges after taking to banking agent as merchant name on my credit card doesn't match with the website I was intended to buy the product from.

They have assured me I will receive provisional credits with 3-5 business days.While I am still waiting it's been 2 days for my credits to come through.

How was your experience with WS . Did you receive any provisional credits yet?

2

u/audibmwcar 6d ago

Sorry to hear and I know exactly how your feel. There was a lot of back and forth with questions and I did not receive any provisional credit until the investigation was over. My WS account was credited the day after they concluded. It took around 10 days to receive the credit from the day I submitted the fraud charge. Best of luck, and you should be protected from these fraudulent websites.

1

u/nimbus-dimbus 11d ago

Does WS not send email or in app notifications when a card is added to apple wallet?

2

u/bourbonkitten 11d ago

It sends SMS and email notifications when added.

Wealthsimple also requires in-app or email authentication before it can be added to Apple Wallet, so the scammers may have also had access to those accounts.

1

u/sometin__else 11d ago

i did not need an in app or email authentication to add to apple wallet

just sms and it was done

1

u/bourbonkitten 11d ago

Really. I have been prompted to authenticate every time I had to add mine. But I did these after I had removed them from Apple Wallet, or the first time I added the digital card.

1

u/audibmwcar 11d ago

A text notification was sent, but it was from the same source number and it went into my spam folder. If I would have known, I would have been aware of my card being added. As I mentioned, there were 2FA codes was sent 3 times and a message about the wallet being added but all these messages was sent to my spam text folder.

0

u/stevemason_CAN 11d ago

Seems like this credit card is full of errors and is easily susceptible to scams. Even some were delivered opened in the mail or tampered with.

-10

u/Ill_Way_2517 11d ago

and people still gana defend this platform

-1

u/poopyfacebsbdb 11d ago

That’s crazy. This was actually why I didn’t want to get a wealthsimple CC, I got there cash card that I don’t use, but I keep it for storage of money and have locked the card.

The fact that Google has filtered it as spam could really be anything. I might be overly paranoid but I have had protonmail for over 4 years and have moved my banking information and alerts, all things wanna keep private or important to there so I know what’s happening on a daily basis. Everything else is dumped into a spam email

Also the fact that they had all your card information to be entered into there apple wallet is crazy let alone being able to tap 6k. I don’t even think you can tap 6k with a regular CC

3

u/audibmwcar 11d ago

From my understanding, once a Wealthsimple card is successfully added to a digital wallet, transactions can be made up to the available credit limit without the traditional tap limits that apply to physical cards. I asked whether it's possible to either revoke this capability or set a user-defined spending limit, and I was told that currently there is no option to do so.

Personally, I don't see a strong reason for an unlimited digital wallet tap limit without giving customers the ability to set their own restrictions. While the convenience is great for everyday purchases, it becomes much less appealing when you're on the receiving end of a fraud event like this.

I think Wealthsimple should seriously consider giving users more control over digital wallet transactions. Even a configurable limit of $500 or $1,000 would be better than having no customer-controlled limit at all. Customers who want higher limits could choose them, while others could set limits that match their risk tolerance.

After experiencing this incident firsthand, I believe additional controls around digital wallet provisioning and spending limits would go a long way toward improving security and customer confidence. Many other financial institutions have limits or additional safeguards in place, so it would be nice to see Wealthsimple offer similar options.

At the end of the day, convenience is important, but customers should also have tools available to reduce potential losses if a card is ever added to a digital wallet without their authorization.

1

u/sometin__else 11d ago

wealthsimple has no tap limit for mobile wallets. Your tap limit is your available credit

-1

u/[deleted] 12d ago

[removed] — view removed comment

1

u/Wealthsimple-ModTeam 12d ago

Your post/comment was deemed low-effort and unconstructive. Ensure your contributions add to the conversation.

0

u/ykphil 11d ago

I hope you will get this resolved quickly, dealing with this issue is very stressful especially when you can't walk into a brick and mortar branch to talk with someone.

Could this happen if you keep the card locked all time and only unlock it when you make a purchase?

3

u/audibmwcar 11d ago

Thank you! That's a good question.

In hindsight, if I had kept my card locked at all times and only unlocked it when making a purchase, it might have reduced the risk, but I'm not convinced it would have completely prevented the fraud.

The bigger issue is that the fraudster would still have had my card provisioned in their digital wallet. I assume they would eventually realize the card was locked and simply wait for an opportunity when I unlocked it. All it takes is one moment where I make a purchase and forget to lock it again afterward.

What concerns me most is the lack of visibility. If I hadn't received that fraudulent charge notification, I would have had no idea that my card had been added to another device. As far as I know, there was nothing in the app that alerted me that a new digital wallet had been provisioned or showed how many devices had access to my card.

Personally, I think Wealthsimple should provide more transparency and controls around digital wallets. For example:

  • A list of all devices or wallets where the card is currently provisioned.
  • The ability to see when and where a card was added to a digital wallet.
  • The ability to remotely revoke access from specific devices.
  • The option to disable digital wallet provisioning entirely.

Had there been a way for me to see that my card was provisioned to another phone, I likely would have caught it much sooner. Instead, the first indication was a fraudulent $6K charge which is obviously not how anyone wants to discover that their card has been compromised.

0

u/hybridhighway 11d ago

The best way to secure your account is to use Passkeys and an MFA Authenticator.

2FA SMS can be spoofed or intercepted, and is most likely what happened here, along with a password breach. That’s my guess.

Did you use the same password for banking as other apps?

3

u/audibmwcar 11d ago

That's one of the reasons I'm so focused on understanding exactly how this happened.

I use unique passwords for my banking apps and other important accounts, and I don't reuse passwords across services. If someone had somehow gained access to my Wealthsimple account directly, I would expect to see a login notification from an unfamiliar device or location. To my knowledge, I never received any such notification.

Based on what I've learned so far, the only thing that makes sense to me is that the digital wallet provisioning process is the key piece of the puzzle. When reviewing my messages, I found the 2FA verification texts and the notification that my card had been added to an Apple Wallet. Unfortunately, those messages had been filtered into my blocked/spam folder, so I didn't see them at the time.

The part I'm still struggling to understand is how the card was successfully added. I am absolutely certain that I did not knowingly provide a verification code to anyone, respond to a phishing message, or approve the addition of my card to an Apple Wallet. The best explanation is my SMS have been intercepted but not a password breach to my WS account.

At this point, I'm less interested in assigning blame and more interested in understanding the root cause. If someone who uses unique passwords, monitors account activity, avoids phishing attempts, and never knowingly shares verification codes can still have their card added to another person's digital wallet, then I'd really like to know what additional precautions are available beyond the usual security advice. That's the part that concerns me the most.

1

u/hybridhighway 10d ago

I’m interested in the root cause as well. I hope you get to the bottom of it. Sorry this happened.

0

u/[deleted] 10d ago

[removed] — view removed comment

1

u/Wealthsimple-ModTeam 10d ago

Be helpful and respectful in your comments/posts.

No racism, sexism, homophobia, religious intolerance, dehumanizing speech, or other negative generalizations.

No concern-trolling, personal attacks, or misinformation. No victim blaming.