Summary
- Environment: Not publicly identified
- Operational impact: No outage or recovery duration quantified
- Financial impact: No public cost estimate
- Record status: Developing record. Reviewed August 9, 2026; updated as evidence emerges.
What happened
A threat actor used social engineering to access a Betterment employee account and marketing and operations applications on January 9, 2026. [1]
Impact
The incident exposed data associated with customers and business contacts, primarily names and email addresses. [1][2]
Documented data types include:
- Contact information — Email addresses and, for a subset, physical addresses and phone numbers. [1][2][3]
- Geographic location information — General geographic locations listed for the HIBP incident corpus; no precise geolocation claim is made. [1][2][3]
- Employment information — Employer names and job titles listed for the HIBP incident corpus. [1][2][3]
- Dates of birth — Dates of birth for a subset of affected data. [1][2][3]
- Device information — Device information listed for the HIBP incident corpus. [1][2][3]
- Names — Names; Betterment said most records were name only or name with email address, and HIBP also lists names. [1][2][3]
A cited record reports 1,400,000 individuals (Betterment’s approximate organization-reported population of customers and business contacts whose associated data was obtained; as of 2026-03-30). [1]
A cited record reports 1,435,174 records (Unique email addresses represented in the HIBP incident corpus; a corpus-record count, not an independently verified person count; as of 2026-02-05). [1][2][3]
Betterment said data originating from the incident was temporarily published to a since-removed leak site on January 23, 2026. [1]
Timeline
Activity began
Initial compromise time reported by Betterment in Eastern Standard Time.
[1]Documented activity ended
Time Betterment said all activity was suspended after access was revoked; not a claim that later extortion-related activity ended then.
[1]Public disclosure
Initial customer communication warning recipients about the fraudulent offer.
[1]Public disclosure
Email to all customers and launch of the incident-update page.
[1]Public disclosure
Publication of Betterment’s completed post-incident report.
[1]Briefing updated
This briefing was last reviewed and updated on August 9, 2026.
Threat Group & Attack Vector
Betterment reported that falsified caller ID and a voice-phishing kit were used to obtain employee credentials and a multi-factor authentication one-time passcode, register a new device, and access its Okta single-sign-on portal and several marketing and operations applications. [1]
Betterment said the threat actor did not establish persistence, move laterally, escalate privileges, or affect system integrity during the January 9 access. [1]
Actors
- No threat actor group has been identified in the reviewed public evidence.
TTPs
Response
On January 12, Betterment received communications from a criminal group demanding a cryptocurrency payment; Betterment said it consulted professional advisers and law enforcement and decided not to engage with the group. The threat actor sent a fraudulent crypto offer to approximately 460,000 customers by email and mobile push notification; Betterment said it alerted recipients and made those who suffered losses from the offer whole. Betterment strengthened MFA by retiring remaining non-hardware methods, tightened authenticator enrollment, enhanced monitoring and alerting, reinforced phishing training, and deployed additional denial-of-service protection. Betterment said customer-account and transaction systems were not impacted and that no customer accounts, passwords, or login information were compromised. No access path, attribution, scale, or recovery detail is inferred beyond the cited claims. [1]
