logo

Betterment breach may expose 1.4M users after social engineering attack

ID: 396fa2ed-c53d-539a-b286-9b409dcdd132

STIX ID: report--396fa2ed-c53d-539a-b286-9b409dcdd132

Feed Name: The Register (Security)

Threat Score
65/100

Date Published: 2026-02-05

Date Updated: 2026-04-26

Author: Carly Page

...
...

Have I Been Pwned added a Betterment breach to its database after the fintech disclosed an intrusion on January 9 that exposed roughly 1.4 million unique email addresses and, for a subset of users, names, mailing addresses, phone numbers, or dates of birth. Betterment says attackers gained access via social engineering targeted at third-party marketing and operations tools and used the access to send a fraudulent cryptocurrency promotion; account passwords and authentication data were reportedly not exposed. The extortion group ShinyHunters has claimed to have accessed systems and posted records, though its leak site was offline at publication, and the incident raises phishing and account takeover risks for affected customers.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.