ConfirmedData breach

Betterment: a data breach

In January 2026, the automated investment platform Betterment confirmed it had suffered a data breach attributed to a social engineering attack . As part of the incident, Betterment customers received fraudulent crypto-related messages promising high returns if funds were sent to an attacker-controlled cryptocurrency wallet. The breach exposed 1.4M unique email addresses, along with names and geographic location data. A subset of records also included dates of birth, phone numbers, and physical addresses. In its disclosure notice , Betterment stated that the incident did not provide attackers with access to customer accounts and did not expose passwords or other login credentials.

The record

Organisation
Betterment
Identity
Bettermentidentified by its domain in a verified breach record
Records affected
1,435,174 records
Data exposed
Dates of birth, Device information, Email addresses, Employers, Geographic locations, Job titles, Names, Phone numbers, Physical addresses
Sector
Not recorded
Occurred
2026-01-09
Disclosed
2026-02-05
First recorded here
2026-09-09

Sources (1)

One source so far.

  1. Have I Been PwnedFirst reported

    2026-02-05

Betterment: a data breach | NexaPulse