Fintech platform Betterment reported a January 2026 social-engineering incident in which an employee was tricked into providing credentials that enabled unauthorized access to internal messaging systems via third-party tools. Betterment said it detected and contained the access the same day, launched an external forensic investigation, and later indicated the incident affected roughly 1.4 million customers; exposed data included names, email addresses, and location data broadly, with a smaller subset including phone numbers, physical addresses, dates of birth, job titles, and device details. Betterment stated that no financial accounts, logins, or passwords were accessed, but warned that the stolen PII was used to send crypto-scam messages impersonating Betterment to pressure users into transferring funds.
Separately, the extortion group ShinyHunters claimed it stole 1.7 million CarGurus corporate records and threatened to leak the data if the company did not engage by a stated deadline; the criminals alleged the haul included PII and internal corporate data, and CarGurus had not publicly confirmed the claim at the time of reporting. The same reporting tied the CarGurus claim to a broader run of ShinyHunters-related leak-site postings and extortion threats against other organizations, with at least one victim (Canada Goose) indicating that data recently published online may have been historical rather than from a new intrusion.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
7 events from the most recent confirmed update back to the earliest known activity.
The group threatened to leak the allegedly stolen CarGurus data unless the company engaged by 2026-02-20. This marked the extortion phase of the claimed CarGurus breach.
Betterment reported that about 1.4 million customers were impacted, with exposed data including names, email addresses, and locations, and additional PII for a smaller subset. The disclosure was reported publicly in February 2026.
On 2026-02-18, ShinyHunters claimed it had breached CarGurus and stolen 1.7 million corporate records, including personally identifiable information and internal company data. CarGurus did not immediately respond to media inquiries.
Figure Technology Solutions was named on ShinyHunters' leak site, and the company said the incident began after an employee was socially engineered. Figure said it blocked the activity, hired a forensic firm, and offered credit monitoring.
Using the compromised Betterment access, the attackers sent fraudulent Betterment-branded notifications urging users to transfer funds to attacker-controlled cryptocurrency wallets. Betterment warned customers to ignore the scam messages and to monitor for suspicious activity and use MFA.
On 2026-01-09, Betterment detected the unauthorized access, revoked the compromised permissions the same day, and began an external forensic investigation. The company later said no financial accounts, logins, or passwords were accessed.
In January 2026, attackers tricked a Betterment employee into providing credentials, enabling unauthorized access to internal messaging systems through third-party tools. The intrusion was described as social-engineering-driven and later linked in reporting to ShinyHunters' broader activity.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
thecyberthrone.in
Open sourcego.theregister.com
Open sourceinfosec.pub
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.