Data breach
Betterment
- Records
- 1,666,053
- Breach date
- 23 January 2026Estimated
- Added
- 24 January 2026
What was exposed
5 types of data
- Email addresses1,666,053
- Phone numbers351,814
- Dates of birth1
- Names1
- Home addresses1
About this breach
Hackers accessed the personal information of Betterment customers in January 2026 after tricking their way into third-party platforms the investment company uses for marketing and customer communications. According to Betterment's own customer update, an unauthorized individual used social engineering, meaning identity impersonation and deception rather than a technical break-in, to gain access on January 9, 2026. The intruder then sent a fraudulent cryptocurrency offer that appeared to come from Betterment to a subset of customers, claiming the company would triple the value of their crypto. Betterment says it revoked the unauthorized access the same day it detected the incident. The investigation team estimates the attack date as January 23, 2026, and indexes roughly 1.67 million email addresses in this listing.
The group ShinyHunters claimed responsibility and, according to MalwareBytes, began publishing the stolen data after Betterment reportedly refused to pay a ransom. Betterment has not publicly confirmed the ransom claims or the number of affected customers.
Breach Timeline
January 9, 2026: An attacker gained access to third-party marketing and operations platforms through social engineering and sent a fraudulent crypto-themed message to customers, per Betterment's customer update.
January 12, 2026: TechCrunch reported that Betterment confirmed the breach and disclosed that names, email and postal addresses, phone numbers, and dates of birth were compromised.
January 13, 2026: Betterment disclosed a distributed denial-of-service attack that disrupted its website and app from 9:04 AM ET, with full service restored by 2:40 PM ET the same day, according to the company's update page.
What Information Was Compromised?
Our analysis found the following data types in this breach: email addresses affecting roughly 1,666,053 people, phone numbers affecting about 351,814 people, names, home addresses, and birthdates.
Betterment's customer notice states that in a subset of cases, contact information was coupled with other customer details, such as physical addresses, phone numbers, or birthdates. The company says its forensic investigation, supported by CrowdStrike, confirmed that no customer accounts, passwords, or login credentials were compromised.
Not every individual is affected by every type of data listed here.
What Are the Potential Risks for Affected Individuals?
Exposed names, emails, phone numbers, addresses, and birthdates give scammers the raw material for targeted phishing. Attackers can reference real details to make fraudulent messages look convincing, and this breach already demonstrated that risk: the intruder used legitimate Betterment channels to push a fake crypto scheme.
Dates of birth and home addresses also support identity fraud, such as opening accounts or answering security questions. Because the attackers' message promised a crypto payout, anyone who replied or clicked may face follow-up scams. Criminals who obtained the full dataset could resell or reuse it indefinitely. The absence of exposed passwords reduces but does not eliminate these risks.
What Is Betterment Doing in Response?
Betterment says it revoked the unauthorized access immediately after detecting the incident and launched an investigation with CrowdStrike's help. The company contacted customers who received the fraudulent message and advised them to disregard it. It also states that an independent data analytics firm is reviewing all accessed data, including material posted online by the group claiming responsibility, to assess privacy risk. The company published a post-incident report, which it describes as the complete source of information on the incident. On January 13, Betterment mitigated a separate DDoS attack that temporarily disrupted its website and app.
What Should You Do If You Were Affected?
Be skeptical of any message claiming to come from Betterment, especially ones offering crypto payouts or asking for money, codes, or credentials. Betterment says it will never call, text, or email you asking for your password or sensitive personal information.
Do not click links or reply to unexpected messages. Verify claims by logging into your Betterment account directly through the official website or app.
Watch for phishing by email, text, and phone. Attackers may reference your name, address, or birthdate to appear legitimate.
Consider placing a fraud alert or credit freeze with the major credit bureaus, since identity details were exposed.
Review your financial accounts for unauthorized activity and report anything suspicious to your bank or broker right away.
