Apps & Consumer
Betterment confirms data breach after social engineering attack
Betterment confirmed a data breach via social engineering that exposed customer personal information, though the company states no accounts or login credentials were compromised.
Betterment, an automated investment platform, has confirmed that hackers broke into some of its systems last week and accessed the personal information of an undisclosed number of its customers. In an email sent to customers on Monday, Betterment disclosed that hackers gained access to some company systems on January 9. The breach was executed by way of a social engineering attack, which involved third-party platforms that the company uses for marketing and operations.
With this unauthorized access, the hackers were able to send a fraudulent notification to users regarding crypto investments. As reported by the media outlet The Verge, the fraudulent notification claimed to triple the value of users’ cryptocurrency if they sent $10,000 to a wallet controlled by the attacker. Betterment, which allows customers to invest in cryptocurrency, did not disclose the exact number of customers targeted by the notification, nor how many had their personal information accessed, stolen, or seen by the hackers.
The company confirmed that customer names, email and postal addresses, phone numbers, and dates of birth were compromised in the attack. However, Betterment emphasized that the core financial accounts remained secure. In its email sent on Monday, the company stated: “Our ongoing investigation has continued to demonstrate that no customer accounts were accessed and that no passwords or other log-in credentials were compromised.”
Betterment detected the attack on the same day it occurred. The company stated that it immediately revoked the unauthorized access and launched a comprehensive investigation, which is ongoing, with the assistance of an unspecified cybersecurity firm. Betterment has also reached out to the customers targeted by the hackers and advised them to disregard the message. Representatives for Betterment did not immediately respond to a request for comment asking for more details about the attack.
Despite these security communications, observers noted a detail regarding the company’s public transparency. Betterment’s security incident web page contains a hidden “noindex” tag in its source code. This tag instructs search engines to ignore the page, making it more difficult for anyone searching the web to discover information about the data breach.
Why it matters
This incident highlights the persistent risk of social engineering attacks on fintech platforms, where attackers leverage third-party marketing tools to target users with fraudulent financial schemes.