Close Menu
  • Home
  • Finance News
  • Personal Finance
  • Investing
  • Cards
    • Credit Cards
    • Debit
  • Insurance
  • Loans
  • Mortgage
  • More
    • Save Money
    • Banking
    • Taxes
    • Crime
What's Hot

Mortgage Rates Move Back Toward Three-Year Lows as Stock Market Crashes

February 7, 2026

What to know about switching plans

February 7, 2026

Betterment data breach exposes 1.4 million customers

February 7, 2026
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram
Smart SpendingSmart Spending
Subscribe
  • Home
  • Finance News
  • Personal Finance
  • Investing
  • Cards
    • Credit Cards
    • Debit
  • Insurance
  • Loans
  • Mortgage
  • More
    • Save Money
    • Banking
    • Taxes
    • Crime
Smart SpendingSmart Spending
Home»Banking»Betterment data breach exposes 1.4 million customers
Banking

Betterment data breach exposes 1.4 million customers

February 7, 2026No Comments4 Mins Read
Facebook Twitter LinkedIn Telegram Pinterest Tumblr Reddit WhatsApp Email
Betterment data breach exposes 1.4 million customers
Share
Facebook Twitter LinkedIn Pinterest Email

  • Key insight: Threat actors likely used “vishing” or voice phishing to compromise IT support at a third-party vendor, believed to be Salesforce. 
  • What’s at stake: While account passwords weren’t compromised, exposed data included names, emails and, for some, physical addresses, phone numbers and birth dates.
  • Supporting data: Threat group ShinyHunters claimed responsibility, listing a database it alleged contained over 2 million records with personally identifiable information.

Overview bullets generated by AI with editorial review

Processing Content

A data breach at robo-advisor Betterment exposed the personal information of nearly 1.4 million customers, according to a Thursday update from breach notification service Have I Been Pwned.

Betterment did not immediately respond to a request for comment. In its public statements about the incident, which Betterment first disclosed in January, it has not confirmed the 1.4 million figure cited by Have I Been Pwned or totals cited by a threat actor that claimed responsibility for the data breach.

The incident involved unauthorized access to third-party marketing and operational platforms — likely Salesforce, though neither company has confirmed as much.

The fintech has said that the primary impact of the breach was exposure of customer names and email addresses — not customer accounts, passwords or login information. A subset of users also had physical addresses, phone numbers and birth dates exposed, according to Betterment and Have I Been Pwned.

Have I Been Pwned said its 1.4 million figure regarded unique email addresses breached.

The breach is yet another example of the third-party risk facing financial institutions, particularly as threat actors increasingly target the software-as-a-service ecosystems that banks use for customer relationship management and marketing.

See also  What 40 Million Borrowers Should Know

It first became apparent that a problem was brewing on Jan. 9, when I and other Betterment customers received an email with a subject line addressing the customer by name, saying, “we’ll triple your crypto sends!”

The message urged users to send bitcoin or ethereum deposits to two addresses listed in the email, with a promise that Betterment would be “adding tripling (sic) Bitcoin and Ethereum deposits for the next three hours.”

Betterment followed up with an email two hours later saying that attackers used unauthorized access to a third-party platform to send the fraudulent message, and the supposed offer should be disregarded.

The company said the next day that if any customers clicked on the email, it did not compromise their Betterment account, and that it had “no indication” at the time that the unauthorized individual had any access to Betterment customer accounts.

Two days later, on Jan. 12, the company admitted to customers that there had been a breach of certain customer “names, email addresses, physical addresses, phone numbers and birthdates.”

ShinyHunters claims responsibility

Betterment has not explicitly named the compromised vendor, but the details align with a broader campaign targeting users of Salesforce, the customer relationship management giant.

A threat group known as ShinyHunters claimed responsibility for the attack two weeks after the fraudulent email went out to Betterment customers.

On its victim shaming and data leak site, ShinyHunters listed a Betterment database it claimed contained “over 2 million records containing Personally Identifiable Information.” Confusingly, the threat group has also claimed there are 20 million total records.

See also  Citizens downplays interest in participating in M&A boom

ShinyHunters has been targeting Salesforce instances to breach other companies including Crunchbase and SoundCloud, and while Betterment has not confirmed whether Salesforce is involved in this data breach, it has described the entry point as “third-party software platforms” used for marketing and operations.

Google Threat Intelligence first reported in June that a threat group using the ShinyHunters brand was compromising Salesforce instances and making subsequent extortion attempts. The company said threat actors executed these breaches through sophisticated voice phishing, or “vishing,” campaigns rather than technical exploits.

In such attacks, operators impersonate IT support personnel to trick employees into providing credentials or multifactor authentication codes. Once they gain access, the attackers often register a malicious connected app — sometimes disguised as the legitimate Salesforce “Data Loader” tool — to exfiltrate customer data in bulk.

This method allows them to bypass traditional network defenses by leveraging the trust inherent in the identity fabric of the SaaS platform.

Salesforce responds to social engineering campaign

Salesforce has said that these incidents do not stem from a vulnerability in its platform but rather from social engineering tactics. The company also said it actively monitors these campaigns and has alerted potentially affected customers.

Salesforce security teams have updated guidance on defending against identity compromise and vishing. To prevent similar third-party compromises, the company has advised customers to enforce phishing-resistant multifactor authentication, such as FIDO2, particularly for SaaS admin portals.

Other red flags accompany these campaigns. Security teams can watch for large data downloads, bulk exports and the registration of new API tokens or connected apps.

See also  Here’s how to use an extra paycheck this month

Minimizing the amount of sensitive customer data stored in marketing platforms can also reduce the “blast radius” of such an attack.

Source link

Betterment breach Customers data exposes million
Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email
Previous ArticleBitcoin gets slashed in half. What’s behind the crypto’s existential crisis
Next Article What to know about switching plans

Related Posts

Fed ‘skinny accounts’ take early heat from crypto, fintechs | PaymentsSource

February 6, 2026

Visa teams with UnionPay to expand Chinese payments | PaymentsSource

February 6, 2026

Nonbank mortgage companies remain a threat to the financial system

February 6, 2026
Add A Comment
Leave A Reply Cancel Reply

Top Posts

New perks, $795 annual fee

June 18, 2025

How to Get Cheap Harry Styles Tickets – And Whether It’s Actually Possible

February 2, 2026

Trump H-1B visa tech foreign governments

September 20, 2025
Ads Banner

Subscribe to Updates

Subscribe to Get the Latest Financial Tips and Insights Delivered to Your Inbox!

Stay informed with our finance blog! Get expert insights, money management tips, investment strategies, and the latest financial news to help you make smart financial decisions.

We're social. Connect with us:

Facebook X (Twitter) Instagram YouTube
Top Insights

Mortgage Rates Move Back Toward Three-Year Lows as Stock Market Crashes

February 7, 2026

What to know about switching plans

February 7, 2026

Betterment data breach exposes 1.4 million customers

February 7, 2026
Get Informed

Subscribe to Updates

Subscribe to Get the Latest Financial Tips and Insights Delivered to Your Inbox!

© 2026 Smartspending.ai - All rights reserved.
  • Contact
  • Privacy Policy
  • Terms & Conditions

Type above and press Enter to search. Press Esc to cancel.