Back Thepaypers Betterment confirms data breach tied to fake crypto alert
Betterment has disclosed that a recent security incident allowed unauthorised parties to access limited customer data and distribute a fraudulent message to users.
The automated investment platform confirmed that the breach occurred on 9 January 2026 and involved systems connected to third-party tools used for marketing and operational purposes.
According to information shared by Betterment, the intrusion was carried out through a social engineering technique rather than a direct compromise of its core infrastructure. As a result, attackers were able to obtain certain personal details, including customer names, email addresses, postal addresses, phone numbers and dates of birth. The company stated that login credentials and account passwords were not affected.
Using the access gained during the incident, the attackers sent messages to users promoting a fake cryptocurrency scheme. The notification falsely suggested that users could significantly increase the value of their crypto holdings by transferring funds to a wallet controlled by the attackers. Reports of the message circulating among customers were first highlighted by external media.
Betterment said it identified the unauthorised activity on the same day it occurred and moved to block further access. Representatives from Betterment indicated that an internal review was launched immediately, with support from an external cybersecurity specialist, and that the investigation remains ongoing. Impacted customers were contacted directly and advised to ignore the fraudulent communication.
The company has not disclosed how many customers were targeted or how many individuals had their information accessed during the incident. A notice outlining the breach was later published on Betterment’s website, although it contained limited detail regarding scale and exposure.
Betterment officials highlighted that customer investment accounts were not accessed and that there is no evidence of unauthorised transactions linked to the breach. Requests for additional clarification on the incident had not been answered at the time of reporting.
Separately, it was observed that the webpage detailing the incident included technical instructions preventing engines from indexing it, reducing its visibility to the wider public.
Betterment confirms data breach tied to fake crypto alert
Revolut rolls out call identification capability to mitigate impersonation scams
HSBC accepts USD 313 million fine to settle France tax-fraud claims
Select ID achieves UK DIATF and ISO 27001 certification
Ubiqu and Thales improve Europe’s digital identity infrastructure
2025 payment fraud retrospective: what did we learn?
How AML de-risking is reshaping correspondent banking: evolution, risk, and the road ahead
Europe’s new digital identity framework: urgency and opportunity for financial institutions
From reimbursement to prevention: why fraud frameworks must evolve for crypto
Securing identity in the age of agentic commerce
The Paypers is the Netherlands-based leading independent source of news and intelligence for professional in the global payment community.
The Paypers provides a wide range of news and analysis products aimed at keeping the ecommerce, fintech, and payment professionals informed the latest developments in the industry.
Crypto, Web3 and CBDC
Payment Orchestration
TradFi and DeFi Convergence
KYC, KYB and Digital Identity
No part of this site can be reproduced without explicit permission of The Paypers (v2.7).
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
