Cyber Security News

Betterment Confirms that Hackers Gained Access to Internal Systems

A leading digital wealth management platform disclosed on January 9, 2026, that an unauthorized individual obtained access to its internal systems through a sophisticated social engineering attack.

Enabling them to impersonate the company and distribute fraudulent cryptocurrency-related messages to a subset of customers.

The attacker used identity impersonation and social engineering tactics to breach Betterment’s systems, rather than exploiting technical vulnerabilities in its infrastructure.

The unauthorized access specifically targeted third-party software platforms that Betterment relies upon for marketing operations and customer communications.

Following the initial compromise, the threat actor leveraged the access to send a fraudulent crypto promotion message appearing to originate from Betterment’s official channels to affected customers.

Betterment stated that customers who received the unauthorized message have been directly contacted and advised to disregard it.

The company emphasized that the crypto offer is not legitimate and should be treated as a phishing attempt.

Upon detecting the fraudulent message on January 9, Betterment’s security teams immediately revoked the unauthorized access and initiated a comprehensive investigation.

The company has engaged a leading third-party cybersecurity firm to support forensic analysis and incident response. As of the latest update on January 10, the investigation remains ongoing.

Data Exposure and Security Implications

Betterment confirmed that no customer accounts were directly compromised and no passwords or login credentials were stolen.

However, the unauthorized individual did access specific customers’ personally identifiable information (PII), including names, email addresses, physical addresses, phone numbers, and birthdates.

The company indicated it would provide additional details regarding the scope of exposed data once the investigation concludes. Betterment emphasized that multiple security layers protect customer accounts.

The company is reviewing and strengthening its controls and employee training programs to prevent future social engineering attempts.

Betterment plans to publish a comprehensive post-incident review upon completion of its investigation.

The company advised all customers to remain vigilant against unsolicited communications. It reiterated that Betterment will never request sensitive information via phone, text, or email.

Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

Abinaya

Abi is a Security Editor and fellow reporter with Cyber Security News. She is covering various cyber security incidents happening in the Cyber Space.

Recent Posts

Google Chrome 153 Update Fixes 42 Security Flaws, Including 3 Critical Ones

Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…

4 hours ago

CISA and NIST Release Technical Checklist for Safeguarding Identity Tokens From Theft and Misuse

The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology…

14 hours ago

CISA Shares 17 Techniques Used by Hackers to Compromise Active Directory Environments

CISA and five international cybersecurity agencies have released detailed guidance describing 17 common techniques hackers…

15 hours ago

Apple Rolls Out Massive Security Update Fixing 273 Vulnerabilities Across Its Devices

Apple has released one of its largest coordinated security rollouts, addressing 273 distinct critical vulnerabilities…

15 hours ago

How to Keep Malware’s Rotating Infrastructure From Becoming a Detection Gap

You can’t detect today's attacks with yesterday’s threat intelligence; that’s how you could briefly formulate…

16 hours ago

Microsoft Bans Its AI Models From Launching Cyberattacks or Escalating Their Own Access

Microsoft has published a draft Humanist AI Code of Conduct that would prohibit its in-house…

16 hours ago