Fintech firm Betterment confirms data breach after hackers send fake crypto scam notification to users


Automated investment platform Betterment has confirmed that hackers broke into some of its systems last week and accessed the personal information of an undisclosed number of its customers. 

In an email sent on Monday, which TechCrunch has seen, Betterment said that hackers gained access to some company systems on January 9 by way of a social engineering attack, which involved “third-party platforms” that the company uses for marketing and operations. 

The company said customer names, email addresses and postal addresses, phone numbers, and dates of birth were compromised in the attack.

With this access, hackers were able to send a fraudulent notification to users, claiming to triple the value of their crypto by sending $10,000 to a wallet controlled by the attacker, as reported by The Verge. 

Betterment, which allows customers to invest in crypto, also published an announcement about the breach on its website, but did not disclose how many customers were targeted, nor how many had their personal information accessed, stolen, or seen by the hackers. 

Betterment added that it detected the attack on the same day and “immediately revoked the unauthorized access and launched a comprehensive investigation, which is ongoing,” with the help of an unspecified cybersecurity firm. Betterment also said it has reached out to the customers targeted by the hackers and “advised them to disregard the message.”

“Our ongoing investigation has continued to demonstrate that no customer accounts were accessed and that no passwords or other log-in credentials were compromised,” Betterment wrote in the email.

Techcrunch event

San Francisco
|
October 13-15, 2026

Representatives for Betterment did not immediately respond to a request for comment asking for more details about the attack. 

As of the time of publication, Betterment’s security incident web page contains a hidden “noindex” tag in its source code, which tells search engines to ignore the page, making it more difficult for anyone searching the web to discover information about the data breach.



Source link

  • Related Posts

    OpenAI now lets teams make custom bots that can do work on their own

    OpenAI is giving users of its Business, Enterprise, Edu, and Teachers plans access to cloud-based “workspace” agents available in ChatGPT that can perform business tasks. In its blog post, OpenAI…

    Google unveils two new TPUs designed for the “agentic era”

    So the new chips allow for faster training, but Google also says you get more useful computation for every volt you pump into a TPU 8t. The company claims a…

    Leave a Reply

    Your email address will not be published. Required fields are marked *

    You Missed

    Fuel fallout: United has hiked fares 5 times, may not be done

    Fuel fallout: United has hiked fares 5 times, may not be done

    ‘Over Your Dead Body’ Interview: Director Jorma Taccone

    ‘Over Your Dead Body’ Interview: Director Jorma Taccone

    MrBeast’s company sued by former employee over alleged sexual harassment – National

    MrBeast’s company sued by former employee over alleged sexual harassment – National

    D4vd murder case: Teen’s cause of death released in medical examiner report

    D4vd murder case: Teen’s cause of death released in medical examiner report

    2 dead in ‘chemical release’ at West Virginia manufacturing facility

    2 dead in ‘chemical release’ at West Virginia manufacturing facility

    OpenAI now lets teams make custom bots that can do work on their own

    OpenAI now lets teams make custom bots that can do work on their own