---
title: "Betterment social-engineering data incident"
description: "Evidence-backed account of Betterment social-engineering data incident, covering what happened, impact, timeline, attack vector, technical details, and primary sources."
incident_type: "Data incident"
status: "active"
last_modified: "2026-08-09"
canonical_url: "https://www.ally.security/incidents/betterment-social-engineering-data-incident-2026"
markdown_url: "https://www.ally.security/incidents/betterment-social-engineering-data-incident-2026.md"
stix_url: "https://www.ally.security/incidents/betterment-social-engineering-data-incident-2026/stix.json"
---

# Betterment social-engineering data incident

A threat actor used social engineering to access a Betterment employee account and marketing and operations applications on January 9, 2026. The incident exposed data associated with customers and business contacts, primarily names and email addresses.

Last modified Aug 9, 2026 · 3 sources

## Summary

- **Environment:** Not publicly identified
- **Operational impact:** No outage or recovery duration quantified
- **Financial impact:** No public cost estimate

## What happened

A threat actor used social engineering to access a [Betterment](https://www.betterment.com/) employee account and marketing and operations applications on January 9, 2026. [1](#source-1)

## Impact

The incident exposed data associated with customers and business contacts, primarily names and email addresses. [1](#source-1) [2](#source-2)

Documented data types include:

- Contact information — Email addresses and, for a subset, physical addresses and phone numbers. [1](#source-1) [2](#source-2) [3](#source-3)
- Geographic location information — General geographic locations listed for the HIBP incident corpus; no precise geolocation claim is made. [1](#source-1) [2](#source-2) [3](#source-3)
- Employment information — Employer names and job titles listed for the HIBP incident corpus. [1](#source-1) [2](#source-2) [3](#source-3)
- Dates of birth — Dates of birth for a subset of affected data. [1](#source-1) [2](#source-2) [3](#source-3)
- Device information — Device information listed for the HIBP incident corpus. [1](#source-1) [2](#source-2) [3](#source-3)
- Names — Names; Betterment said most records were name only or name with email address, and HIBP also lists names. [1](#source-1) [2](#source-2) [3](#source-3)

A cited record reports 1,400,000 individuals (Betterment's approximate organization-reported population of customers and business contacts whose associated data was obtained; as of 2026-03-30). [1](#source-1)

A cited record reports 1,435,174 records (Unique email addresses represented in the HIBP incident corpus; a corpus-record count, not an independently verified person count; as of 2026-02-05). [1](#source-1) [2](#source-2) [3](#source-3)

Betterment said data originating from the incident was temporarily published to a since-removed leak site on January 23, 2026. [1](#source-1)

## Timeline

### January 9, 2026 — Activity began

Initial compromise time reported by Betterment in Eastern Standard Time. [1](#source-1)

### January 9, 2026 — Documented activity ended

Time Betterment said all activity was suspended after access was revoked; not a claim that later extortion-related activity ended then. [1](#source-1)

### January 9, 2026 — Public disclosure

Initial customer communication warning recipients about the fraudulent offer. [1](#source-1)

### January 12, 2026 — Public disclosure

Email to all customers and launch of the incident-update page. [1](#source-1)

### March 30, 2026 — Public disclosure

Publication of Betterment's completed post-incident report. [1](#source-1)

### August 9, 2026 — Briefing updated

This briefing was last reviewed and updated on August 9, 2026.

## Threat Group & Attack Vector

Betterment reported that falsified caller ID and a voice-phishing kit were used to obtain employee credentials and a multi-factor authentication one-time passcode, register a new device, and access its Okta single-sign-on portal and several marketing and operations applications. [1](#source-1)

Betterment said the threat actor did not establish persistence, move laterally, escalate privileges, or affect system integrity during the January 9 access. [1](#source-1)

### Actors

- No threat actor group has been identified in the reviewed public evidence.

### TTPs

- [T1566.004 — Phishing: Spearphishing Voice](https://attack.mitre.org/techniques/T1566/004/) [1](#source-1)

## Response

On January 12, Betterment received communications from a criminal group demanding a cryptocurrency payment; Betterment said it consulted professional advisers and law enforcement and decided not to engage with the group. The threat actor sent a fraudulent crypto offer to approximately 460,000 customers by email and mobile push notification; Betterment said it alerted recipients and made those who suffered losses from the offer whole. Betterment strengthened MFA by retiring remaining non-hardware methods, tightened authenticator enrollment, enhanced monitoring and alerting, reinforced phishing training, and deployed additional denial-of-service protection. Betterment said customer-account and transaction systems were not impacted and that no customer accounts, passwords, or login information were compromised. No access path, attribution, scale, or recovery detail is inferred beyond the cited claims. [1](#source-1)

## Assets

[Download the case-scoped STIX 2.1 bundle](<https://www.ally.security/incidents/betterment-social-engineering-data-incident-2026/stix.json>)

## Sources

Primary source records used to research this incident.

<a id="source-1"></a>

### Security Incident Report: January 2026

official · Betterment · Mar 30, 2026

<https://www.betterment.com/resources/security-incident-report-january-2026>

<a id="source-2"></a>

### Betterment breach record

advisory · Have I Been Pwned · Feb 5, 2026

<https://haveibeenpwned.com/api/v3/breach/Betterment>

<a id="source-3"></a>

### Updates on Betterment — January 9 Security Incident

official · Betterment · Jan 9, 2026

<https://www.betterment.com/customer-update>

<details>
<summary>Evidence ledger</summary>

Review the supporting structured claims.

1. **Resulted In · 100% confidence · current**  
   January 2026 Betterment social-engineering incident: On January 12, Betterment received communications from a criminal group demanding a cryptocurrency payment; Betterment said it consulted professional advisers and law enforcement and decided not to engage with the group.
2. **Resulted In · 100% confidence · current**  
   January 2026 Betterment social-engineering incident: Betterment customer and business-contact data exposure
3. **Resulted In · 100% confidence · current**  
   January 2026 Betterment social-engineering incident: Betterment reported that falsified caller ID and a voice-phishing kit were used to obtain employee credentials and a multi-factor authentication one-time passcode, register a new device, and access its Okta single-sign-on portal and several marketing and operations applications.
4. **Exposed Data Category · 100% confidence · current**  
   Betterment customer and business-contact data exposure: Contact information
5. **Ended At · 100% confidence · current**  
   January 2026 Betterment social-engineering incident: 2026-01-09T18:18:00-05:00
6. **Used Attack Technique · 95% confidence · current**  
   January 2026 Betterment social-engineering incident: https://attack.mitre.org/techniques/T1566/004/
7. **Disclosed At · 100% confidence · current**  
   Betterment January–March 2026 incident communications: 2026-03-30T11:13:32-04:00
8. **Began At · 100% confidence · current**  
   January 2026 Betterment social-engineering incident: 2026-01-09T13:31:00-05:00
9. **Affected Organization · 100% confidence · current**  
   January 2026 Betterment social-engineering incident: Betterment
10. **Affected Organization · 100% confidence · current**  
   Betterment customer and business-contact data exposure: Betterment
11. **Resulted In · 100% confidence · current**  
   January 2026 Betterment social-engineering incident: The threat actor sent a fraudulent crypto offer to approximately 460,000 customers by email and mobile push notification; Betterment said it alerted recipients and made those who suffered losses from the offer whole.
12. **Disclosed At · 100% confidence · current**  
   Betterment January–March 2026 incident communications: 2026-01-09T19:00:00-05:00
13. **Disclosed At · 100% confidence · current**  
   Betterment January–March 2026 incident communications: 2026-01-12T10:00:00-05:00
14. **Resulted In · 100% confidence · current**  
   January 2026 Betterment social-engineering incident: Betterment said data originating from the incident was temporarily published to a since-removed leak site on January 23, 2026.
15. **Resulted In · 100% confidence · current**  
   January 2026 Betterment social-engineering incident: Betterment said the threat actor did not establish persistence, move laterally, escalate privileges, or affect system integrity during the January 9 access.
16. **Exposed Data Category · 100% confidence · current**  
   Betterment customer and business-contact data exposure: Geographic location information
17. **Exposed Data Category · 100% confidence · current**  
   Betterment customer and business-contact data exposure: Employment information
18. **Resulted In · 100% confidence · current**  
   January 2026 Betterment social-engineering incident: Betterment January–March 2026 incident communications
19. **Affected Individual Count · 100% confidence · current**  
   Betterment customer and business-contact data exposure: 1,400,000 individual
20. **Exposed Data Category · 100% confidence · current**  
   Betterment customer and business-contact data exposure: Dates of birth
21. **Exposed Data Category · 100% confidence · current**  
   Betterment customer and business-contact data exposure: Device information
22. **Resulted In · 100% confidence · current**  
   January 2026 Betterment social-engineering incident: Betterment strengthened MFA by retiring remaining non-hardware methods, tightened authenticator enrollment, enhanced monitoring and alerting, reinforced phishing training, and deployed additional denial-of-service protection.
23. **Exposed Data Category · 100% confidence · current**  
   Betterment customer and business-contact data exposure: Names
24. **Resulted In · 100% confidence · current**  
   January 2026 Betterment social-engineering incident: Betterment said customer-account and transaction systems were not impacted and that no customer accounts, passwords, or login information were compromised.
25. **Exposed Record Count · 100% confidence · current**  
   Betterment customer and business-contact data exposure: 1,435,174 record

</details>
