Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
Betterment

Betterment Vendor Cyber Rating & Cyber Score

betterment.com

Betterment is an investing and savings app that serves one purpose—to help you grow your money, so that you can live better. Sign up effortlessly to get goal-setting and planning tools at no extra cost. For one low, transparent fee, you can invest your money with automatic deposit and trading features that put your money to work. Earn with interest and investment growth—plus maximize your savings with rewards on your everyday spending. Learn more at Betterment.com. Investing involves risk and performance not guaranteed. https://www.betterment.com/social-disclosures/


Betterment A.I CyberSecurity Scoring

Betterment
Company Information
Website:http://www.betterment.com
Employees number:618
Number of followers:48,149
NAICS:52
Industry Type:Financial Services
Homepage:betterment.com
Betterment Risk Score (AI oriented)
Between 0 and 549
logo
BettermentFinancial Services
Updated:
04/04/2026
454/1000
Critical
C
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
Betterment Global Score (TPRM)
xxxx
logo
BettermentFinancial Services
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

Betterment
BettermentCritical
Current Score
454C (CRITICAL)
01000
4 incidents
-80.5 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
468Before Incident
MAY 2026
464Before Incident
APRIL 2026
459Before Incident
MARCH 2026
453Before Incident
FEBRUARY 2026
542Before Incident
Breach
14 Feb 2026Betterment
Betterment, Match Group and Mercer Advisors: Canada Goose says ShinyHunters only breached old data

Canada Goose Historical Data Leak

444After Incident
CRITICAL-98
MATBETMER1771266248
Canada Goose Dismisses Recent Data Leak as Old Breach, No Signs of New Compromise Canada Goose has confirmed that a recently advertised data leak involving over 600,000 customer records stems from a historical breach, with no evidence of a new system compromise. The luxury apparel company acknowledged the publication of an old dataset containing past customer transaction details but stated that its review found no unmasked financial data included. The leaked records, posted by the cybercriminal group ShinyHunters on February 14, reportedly contain personally identifiable information (PII), partial payment details, and order data such as prices and delivery addresses. A preliminary analysis suggests the affected individuals are primarily based in North America and Europe. ShinyHunters, which has launched its own data leak site in 2026, has been active in targeting high-profile organizations. Recent victims include Crunchbase, Betterment, SoundCloud, Match Group, Panera Bread, Harvard University, and Mercer Advisors. The group has previously exploited Okta accounts through voice phishing and was linked to attacks on Salesforce and its integrations, resulting in the theft of data from over 200 customers.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
Data Compromised: 600,000 customer recordsIdentity Theft Risk: HighPayment Information Risk: Partial
DATA BREACH
Personally Identifiable Information (PII)Partial payment detailsOrder data (prices, delivery addresses)Number Of Records Exposed: 600,000Sensitivity Of Data: HighPersonally Identifiable Information: Yes
JANUARY 2026
606Before Incident
Breach
09 Jan 2026Betterment
Betterment: Betterment Data Breach Exposes Customer Information In 2026

Betterment Data Breach Exposes Customer Information

537After Incident
CRITICAL-69
BET1768259382
Betterment Data Breach Exposes Customer Information in 2026 Social Engineering Attack On January 9, 2026, Betterment, a leading automated investment and personal finance platform, disclosed a cybersecurity incident in which hackers exploited third-party marketing and operational tools to access customer data. The attackers employed social engineering tactics deception and impersonation to infiltrate systems, bypassing Betterment’s core security infrastructure. The breach exposed personal information, including names, email and postal addresses, phone numbers, and dates of birth for an undisclosed number of customers. While Betterment confirmed that no account credentials or financial data were compromised, the attackers used the stolen information to send fraudulent cryptocurrency scam messages to some users, promising to triple their holdings in exchange for a $10,000 payment to a hacker-controlled wallet. Betterment detected the breach the same day, revoking unauthorized access and launching an investigation with an unnamed cybersecurity firm. The company stated that no customer accounts were accessed, and login credentials remained secure. However, the incident has raised concerns about the risks posed by third-party integrations in financial services, as the attack did not target Betterment’s internal systems directly but rather exploited vulnerabilities in external platforms. Betterment’s response has drawn criticism for its lack of transparency, including the use of a "noindex" tag on its security incident webpage, preventing search engines from indexing the details. As of January 12, 2026, the company had not disclosed the number of affected customers or further specifics about the attack. The ongoing investigation, along with regulatory scrutiny, may provide additional clarity in the coming weeks. Cybersecurity experts note that social engineering attacks on financial platforms are increasing, emphasizing the need for stronger oversight of third-party vendors and employee training. The breach underscores the broader challenge of securing interconnected digital ecosystems, where even robust internal defenses can be undermined by external vulnerabilities.
INCIDENT DETAILS -
TYPE
Data Breach
MOTIVATION
Financial gain (fraudulent crypto scam)
IMPACT
Data Compromised: Names, email and postal addresses, phone numbers, dates of birthSystems Affected: Third-party marketing and operations platformsOperational Impact: Unauthorized access revoked, ongoing investigationBrand Reputation Impact: Rattled nerves among investors and privacy advocatesIdentity Theft Risk: High (exposure of personal information)
DATA BREACH
Type Of Data Compromised: Personal InformationSensitivity Of Data: High (PII including names, addresses, phone numbers, dates of birth)Personally Identifiable Information: Names, email and postal addresses, phone numbers, dates of birth
DECEMBER 2025
635Before Incident
Cyber Attack
28 Dec 2025Betterment
Canva, Adyen, Atlassian, HubSpot, Epic Games, Moderna, GameStop, ZoomInfo, WeWork, Halliburton, Betterment, Sonos and Telstra: Over 100 Organizations Targeted in ShinyHunters Phishing Campaign

ShinyHunters-Linked Cybercrime Campaign Targets Over 100 Major Organizations

605After Incident
CRITICAL-30
CANADYATLHUBEPIMODGAMZOOWEWHALBETSONTEL1769527593
ShinyHunters-Linked Cybercrime Campaign Targets Over 100 Major Organizations A recent cybercrime campaign attributed to the ShinyHunters group has targeted at least 100 organizations across multiple sectors, including software, finance, healthcare, and energy, according to cybersecurity firm Silent Push. Over the past 30 days, threat actors registered fake domains impersonating high-profile companies such as Atlassian, Adyen, Canva, Epic Games, HubSpot, Moderna, ZoomInfo, GameStop, WeWork, Halliburton, Sonos, and Telstra. The attackers employed voice phishing (vishing) tactics to compromise single sign-on (SSO) accounts, particularly those using Okta and other identity platforms. Using specialized phishing kits, they intercepted credentials and manipulated victims into bypassing multi-factor authentication (MFA) by convincing them to approve push notifications or submit one-time passcodes (OTPs). Okta described the attacks as involving real-time session orchestration, where threat actors guided victims through the authentication process via verbal instructions. While Silent Push identified the infrastructure used in the campaign, it remains unclear whether the attacks successfully breached any systems. However, ShinyHunters has claimed responsibility for data breaches at companies like Betterment, Crunchbase, and SoundCloud, all of which confirmed incidents. The group allegedly stole millions of records from these organizations as part of the Okta SSO vishing campaign. Silent Push attributes the campaign to Scattered LAPSUS$ Hunters, a collective formed last year by members of Lapsus$, Scattered Spider, and ShinyHunters, based on observed tactics, techniques, and procedures (TTPs). The incident follows recent warnings from Google and others about rising vishing and phishing attacks targeting identity platforms.
INCIDENT DETAILS -
TYPE
Phishing (Vishing), Data Breach, Credential Theft
MOTIVATION
Data Theft, Financial Gain, Credential Harvesting
IMPACT
Data Compromised: Millions of records allegedly stolenSystems Affected: SSO accounts (Okta and other identity platforms)Identity Theft Risk: High (PII and credentials compromised)
DATA BREACH
Type Of Data Compromised: Personally Identifiable Information (PII), Credentials, Business DataNumber Of Records Exposed: Millions (alleged)Sensitivity Of Data: High (PII, credentials)Data Exfiltration: Alleged (data sold on dark web)Personally Identifiable Information: Yes
DECEMBER 2025
759Before Incident
Breach
12 Dec 2025Betterment
SoundCloud confirms breach after member data stolen, VPN access disrupted

SoundCloud Security Breach and Data Theft

634After Incident
CRITICAL-125
SOU1765850792
SoundCloud Confirms Security Breach Impacting 28 Million Users SoundCloud has confirmed that recent outages and VPN connectivity issues were caused by a security breach in which threat actors stole a database containing user information. The incident, detected over the past four days, led to widespread reports of users encountering 403 "forbidden" errors when accessing the platform via VPN. In a statement to BleepingComputer, SoundCloud revealed that unauthorized activity was detected in an ancillary service dashboard, prompting the activation of its incident response procedures. While the company acknowledged that a threat actor accessed limited data, it clarified that no sensitive information—such as financial details or passwords—was compromised. The exposed data included only email addresses and publicly visible profile information. The breach is estimated to affect approximately 20% of SoundCloud’s user base, translating to roughly 28 million accounts based on publicly reported figures. The company stated that all unauthorized access has been blocked and that no ongoing risk to the platform exists. In response, SoundCloud has implemented additional security measures, including enhanced monitoring, improved threat detection, and a review of identity and access controls. However, a configuration change made during the response disrupted VPN access to the site, with no confirmed timeline for full restoration. Following the breach, SoundCloud also faced denial-of-service (DoS) attacks that temporarily disabled its web availability. While the company has not identified the threat actor, BleepingComputer sources indicate that the ShinyHunters extortion gang is likely responsible. The group, which also claimed responsibility for a recent PornHub data breach, is reportedly attempting to extort SoundCloud after allegedly stealing user data. Further updates are expected as the investigation continues.
INCIDENT DETAILS -
TYPE
Data Breach
MOTIVATION
Extortion
IMPACT
Data Compromised: Email addresses and public profile informationSystems Affected: Ancillary service dashboard, VPN connectivityDowntime: Temporary web availability disruption due to DDoS attacksOperational Impact: VPN access disruption, temporary platform unavailability
DATA BREACH
Type Of Data Compromised: Email addresses, public profile informationNumber Of Records Exposed: 28 millionSensitivity Of Data: Low (no financial or password data)Personally Identifiable Information: Email addresses
NOVEMBER 2025
759Before Incident
OCTOBER 2025
759Before Incident
SEPTEMBER 2025
759Before Incident
AUGUST 2025
759Before Incident
JULY 2025
759Before Incident

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for Betterment ?
?
What was Betterment's A.I Rankiteo Cyber Score in May 2026 ?
?
What was Betterment's A.I Rankiteo Cyber Score in April 2026 ?
?
What was Betterment's A.I Rankiteo Cyber Score in March 2026 ?
?
What was Betterment's A.I Rankiteo Cyber Score in February 2026 ?
?
What was Betterment's A.I Rankiteo Cyber Score in January 2026 ?
?
What was Betterment's A.I Rankiteo Cyber Score in December 2025 ?
?
What was Betterment's A.I Rankiteo Cyber Score in November 2025 ?
?
What was Betterment's A.I Rankiteo Cyber Score in October 2025 ?
?
What was Betterment's A.I Rankiteo Cyber Score in September 2025 ?
?
What was Betterment's A.I Rankiteo Cyber Score in August 2025 ?
?
What was Betterment's A.I Rankiteo Cyber Score in July 2025 ?
?
What is the average per-incident point impact on Betterment's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with Betterment ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view Betterment's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?
Betterment Cyber Scoring History | Rankiteo