Betterment A.I CyberSecurity Scoring
Betterment
Company Information
Website:http://www.betterment.com
Employees number:670
Number of followers:50,813
NAICS:52
Industry Type:Financial Services
Homepage:betterment.com
Betterment Risk Score (AI oriented)
Between 0 and 549
BettermentFinancial Services
Updated:
27/07/2026
27/07/2026
289/1000
Critical
C
Betterment Global Score (TPRM)
xxxx
BettermentFinancial Services
Score locked

BettermentCritical
Current Score
289C (CRITICAL)
01000
5 incidents
-105.8 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
AUGUST 2026
296
JULY 2026
285
JUNE 2026
276
MAY 2026
268
APRIL 2026
261
MARCH 2026
449
Breach
01 Mar 2026 • Betterment
Betterment, Substack, ADT, Amtrak, Hallmark, CarGurus, Panera Bread and McGraw Hill: Sextortion scammers are exploiting ShinyHunters data leaks
Sextortion Scammers Exploit ShinyHunters Data Leaks in $2,000 Bitcoin Scheme
242
CRITICAL-207
MCGSUBAMTADTHALPANCARBET1785169886
Sextortion Scammers Exploit ShinyHunters Data Leaks in $2,000 Bitcoin Scheme
Cybercriminals are leveraging email addresses from past ShinyHunters data breaches to lend false credibility to a new wave of sextortion scams, demanding $2,000 in Bitcoin from victims. The campaign, reported by BleepingComputer, targets individuals whose personal data was exposed in breaches of companies like Amtrak, Hallmark, ADT, Substack, Betterment, CarGurus, Panera Bread, and McGraw Hill, as well as those affected by the Canvas data breach at a California community college.
The scam emails falsely claim to be from ShinyHunters, alleging that the group has compromised victims’ devices, recorded explicit content via webcams, and threatens to leak the footage unless payment is made within 48 hours. A sample email includes a Bitcoin wallet address currently showing no transaction activity and falsely asserts access to browsing history, contacts, and other sensitive data.
Despite the threats, no evidence supports the claims. ShinyHunters has denied involvement, and security experts confirm the emails are bluffs, relying on psychological manipulation rather than actual malware or recordings. The scammers likely obtained the email lists from publicly leaked data after ShinyHunters’ failed extortion attempts.
The $2,000 demand marks an increase from typical sextortion scams, possibly indicating the scammers acquired the data through purchase or direct download. While the emails vary in sophistication some appearing AI-polished they uniformly lack verifiable proof. Security researchers emphasize that responding to such emails can confirm an active account, leading to further targeting.
Victims are advised to ignore the threats, avoid engaging with the scammers, and report the emails as spam. If the message includes a previously used password, users should change it immediately and enable two-factor authentication (2FA). The campaign underscores how leaked data continues to fuel cybercrime, even when the original breach has been addressed.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
FEBRUARY 2026
542
Breach
14 Feb 2026 • Betterment
Betterment, Match Group and Mercer Advisors: Canada Goose says ShinyHunters only breached old data
Canada Goose Historical Data Leak
444
CRITICAL-98
MATBETMER1771266248
Canada Goose Dismisses Recent Data Leak as Old Breach, No Signs of New Compromise
Canada Goose has confirmed that a recently advertised data leak involving over 600,000 customer records stems from a historical breach, with no evidence of a new system compromise. The luxury apparel company acknowledged the publication of an old dataset containing past customer transaction details but stated that its review found no unmasked financial data included.
The leaked records, posted by the cybercriminal group ShinyHunters on February 14, reportedly contain personally identifiable information (PII), partial payment details, and order data such as prices and delivery addresses. A preliminary analysis suggests the affected individuals are primarily based in North America and Europe.
ShinyHunters, which has launched its own data leak site in 2026, has been active in targeting high-profile organizations. Recent victims include Crunchbase, Betterment, SoundCloud, Match Group, Panera Bread, Harvard University, and Mercer Advisors. The group has previously exploited Okta accounts through voice phishing and was linked to attacks on Salesforce and its integrations, resulting in the theft of data from over 200 customers.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
JANUARY 2026
606
Breach
09 Jan 2026 • Betterment
Betterment: Betterment Data Breach Exposes Customer Information In 2026
Betterment Data Breach Exposes Customer Information
537
CRITICAL-69
BET1768259382
Betterment Data Breach Exposes Customer Information in 2026 Social Engineering Attack
On January 9, 2026, Betterment, a leading automated investment and personal finance platform, disclosed a cybersecurity incident in which hackers exploited third-party marketing and operational tools to access customer data. The attackers employed social engineering tactics deception and impersonation to infiltrate systems, bypassing Betterment’s core security infrastructure.
The breach exposed personal information, including names, email and postal addresses, phone numbers, and dates of birth for an undisclosed number of customers. While Betterment confirmed that no account credentials or financial data were compromised, the attackers used the stolen information to send fraudulent cryptocurrency scam messages to some users, promising to triple their holdings in exchange for a $10,000 payment to a hacker-controlled wallet.
Betterment detected the breach the same day, revoking unauthorized access and launching an investigation with an unnamed cybersecurity firm. The company stated that no customer accounts were accessed, and login credentials remained secure. However, the incident has raised concerns about the risks posed by third-party integrations in financial services, as the attack did not target Betterment’s internal systems directly but rather exploited vulnerabilities in external platforms.
Betterment’s response has drawn criticism for its lack of transparency, including the use of a "noindex" tag on its security incident webpage, preventing search engines from indexing the details. As of January 12, 2026, the company had not disclosed the number of affected customers or further specifics about the attack. The ongoing investigation, along with regulatory scrutiny, may provide additional clarity in the coming weeks.
Cybersecurity experts note that social engineering attacks on financial platforms are increasing, emphasizing the need for stronger oversight of third-party vendors and employee training. The breach underscores the broader challenge of securing interconnected digital ecosystems, where even robust internal defenses can be undermined by external vulnerabilities.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
DECEMBER 2025
635
Cyber Attack
28 Dec 2025 • Betterment
Canva, Adyen, Atlassian, HubSpot, Epic Games, Moderna, GameStop, ZoomInfo, WeWork, Halliburton, Betterment, Sonos and Telstra: Over 100 Organizations Targeted in ShinyHunters Phishing Campaign
ShinyHunters-Linked Cybercrime Campaign Targets Over 100 Major Organizations
605
CRITICAL-30
CANADYATLHUBEPIMODGAMZOOWEWHALBETSONTEL1769527593
ShinyHunters-Linked Cybercrime Campaign Targets Over 100 Major Organizations
A recent cybercrime campaign attributed to the ShinyHunters group has targeted at least 100 organizations across multiple sectors, including software, finance, healthcare, and energy, according to cybersecurity firm Silent Push. Over the past 30 days, threat actors registered fake domains impersonating high-profile companies such as Atlassian, Adyen, Canva, Epic Games, HubSpot, Moderna, ZoomInfo, GameStop, WeWork, Halliburton, Sonos, and Telstra.
The attackers employed voice phishing (vishing) tactics to compromise single sign-on (SSO) accounts, particularly those using Okta and other identity platforms. Using specialized phishing kits, they intercepted credentials and manipulated victims into bypassing multi-factor authentication (MFA) by convincing them to approve push notifications or submit one-time passcodes (OTPs). Okta described the attacks as involving real-time session orchestration, where threat actors guided victims through the authentication process via verbal instructions.
While Silent Push identified the infrastructure used in the campaign, it remains unclear whether the attacks successfully breached any systems. However, ShinyHunters has claimed responsibility for data breaches at companies like Betterment, Crunchbase, and SoundCloud, all of which confirmed incidents. The group allegedly stole millions of records from these organizations as part of the Okta SSO vishing campaign.
Silent Push attributes the campaign to Scattered LAPSUS$ Hunters, a collective formed last year by members of Lapsus$, Scattered Spider, and ShinyHunters, based on observed tactics, techniques, and procedures (TTPs). The incident follows recent warnings from Google and others about rising vishing and phishing attacks targeting identity platforms.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
DECEMBER 2025
759
Breach
12 Dec 2025 • Betterment
SoundCloud confirms breach after member data stolen, VPN access disrupted
SoundCloud Security Breach and Data Theft
634
CRITICAL-125
SOU1765850792
SoundCloud Confirms Security Breach Impacting 28 Million Users
SoundCloud has confirmed that recent outages and VPN connectivity issues were caused by a security breach in which threat actors stole a database containing user information. The incident, detected over the past four days, led to widespread reports of users encountering 403 "forbidden" errors when accessing the platform via VPN.
In a statement to BleepingComputer, SoundCloud revealed that unauthorized activity was detected in an ancillary service dashboard, prompting the activation of its incident response procedures. While the company acknowledged that a threat actor accessed limited data, it clarified that no sensitive information—such as financial details or passwords—was compromised. The exposed data included only email addresses and publicly visible profile information.
The breach is estimated to affect approximately 20% of SoundCloud’s user base, translating to roughly 28 million accounts based on publicly reported figures. The company stated that all unauthorized access has been blocked and that no ongoing risk to the platform exists.
In response, SoundCloud has implemented additional security measures, including enhanced monitoring, improved threat detection, and a review of identity and access controls. However, a configuration change made during the response disrupted VPN access to the site, with no confirmed timeline for full restoration.
Following the breach, SoundCloud also faced denial-of-service (DoS) attacks that temporarily disabled its web availability. While the company has not identified the threat actor, BleepingComputer sources indicate that the ShinyHunters extortion gang is likely responsible. The group, which also claimed responsibility for a recent PornHub data breach, is reportedly attempting to extort SoundCloud after allegedly stealing user data. Further updates are expected as the investigation continues.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
NOVEMBER 2025
759
OCTOBER 2025
759
SEPTEMBER 2025
759
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for Betterment ??
What was Betterment's A.I Rankiteo Cyber Score in July 2026 ??
What was Betterment's A.I Rankiteo Cyber Score in June 2026 ??
What was Betterment's A.I Rankiteo Cyber Score in May 2026 ??
What was Betterment's A.I Rankiteo Cyber Score in April 2026 ??
What was Betterment's A.I Rankiteo Cyber Score in March 2026 ??
What was Betterment's A.I Rankiteo Cyber Score in February 2026 ??
What was Betterment's A.I Rankiteo Cyber Score in January 2026 ??
What was Betterment's A.I Rankiteo Cyber Score in December 2025 ??
What was Betterment's A.I Rankiteo Cyber Score in November 2025 ??
What was Betterment's A.I Rankiteo Cyber Score in October 2025 ??
What was Betterment's A.I Rankiteo Cyber Score in September 2025 ??
What is the average per-incident point impact on Betterment's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with Betterment ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view Betterment's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?