Connect with us
DAPA Banner

Crypto World

Betterment Confirms Data Breach After Crypto Phishing Attack

Published

on

Crypto Breaking News

Betterment has confirmed a security incident in which attackers exploited social engineering to access third-party tools used by the company, exposing customer contact data and enabling a targeted crypto-themed phishing attempt. The breach, detected on January 9, did not involve compromised passwords or customer accounts, according to the firm. Still, the episode highlights how marketing and operations platforms can become a weak link, especially when attackers leverage trusted communication channels to deceive users.

Key takeaways

  • Unauthorized access occurred on January 9 through social engineering targeting third-party platforms used for marketing and operations.
  • Exposed data included names and email addresses, and in some cases postal addresses, phone numbers, and dates of birth.
  • Attackers sent a fraudulent crypto-related message to a subset of customers, attempting to solicit funds.
  • No customer accounts, passwords, or login credentials were accessed, according to the company’s investigation.
  • Betterment engaged CrowdStrike for forensics and plans a post-incident review within 60 days.

Market context: Social engineering and phishing remain among the most common attack vectors in fintech, with third-party SaaS tools increasingly targeted as firms expand digital communications and customer outreach.

Why it matters

The incident underscores the risks associated with outsourced platforms that handle customer communications. Even when core infrastructure remains secure, attackers can exploit peripheral systems to reach users at scale.

For customers, the breach serves as a reminder that legitimate-looking messages can be deceptive, particularly when they reference popular investment themes like crypto. For fintech firms, it reinforces the need to secure not only internal systems but also the broader vendor ecosystem.

What to watch next

  • Publication of Betterment’s post-incident review within the next 60 days.
  • Results from the independent data analytics review assessing potential privacy risks.
  • Any regulatory or customer notifications that follow the final investigation.
  • Changes to Betterment’s controls and training aimed at preventing social engineering.

Sources & verification

  • Betterment customer updates published between January 9 and February 3, 2026.
  • Company statements confirming forensic findings and remediation steps.
  • Details of the phishing message and affected data categories described in official updates.

How the breach unfolded and what it revealed

Betterment disclosed that an unauthorized individual gained access to certain company systems on January 9 by impersonating legitimate users and exploiting trust-based workflows. Rather than breaching core technical infrastructure, the attacker leveraged social engineering tactics against third-party software platforms that support marketing and operational functions.

This access allowed the attacker to view and extract customer contact information. According to the company, the data exposure primarily involved names and email addresses, though in a subset of cases it also included physical addresses, phone numbers, and birthdates. The total number of affected customers has not been disclosed.

Advertisement

Using the compromised access, the attacker distributed a fraudulent message that appeared to originate from Betterment. The notification promoted a fake crypto-related opportunity, claiming that users could triple the value of their holdings by sending $10,000 to a wallet controlled by the attacker. The message was sent to a limited group of customers whose contact details were accessible through the breached systems.

Betterment said it identified the unauthorized activity on the same day and immediately revoked access to the affected platforms. An internal investigation was launched, supported by the cybersecurity firm CrowdStrike, to determine the scope of the intrusion and verify whether customer accounts or credentials were at risk.

Subsequent forensic analysis found no evidence that the attacker accessed Betterment customer accounts, passwords, or login credentials. The company emphasized that multiple layers of security protected account-level systems and that the breach was confined to contact data and communications tooling.

In the days following the incident, Betterment contacted customers who received the fraudulent message and advised them to disregard it. The firm reiterated that it would never request passwords or sensitive personal information via email, text, or phone calls.

Advertisement

The security incident coincided with additional disruptions in mid-January. On January 13, Betterment experienced intermittent outages to its website and mobile app caused by a distributed denial-of-service attack. The company restored partial service within about an hour and full access later that afternoon, stating that the DDoS event did not compromise account security.

By early February, Betterment provided further updates on its investigation. The company confirmed that while some customer data had been accessed, the privacy impact appeared limited to contact information. An independent data analytics firm was engaged to review all accessed data, including information that a group claiming responsibility for the breach alleged it had posted online.

Betterment also noted that it plans to publish a comprehensive post-incident review within 60 days. In parallel, the company said it is strengthening controls and training programs to better defend against social engineering attempts, which rely on deception rather than technical exploits.

One aspect of the disclosure drew scrutiny from security observers. As of publication, Betterment’s security incident webpage included a “noindex” directive in its source code, instructing search engines not to index the page. While such tags are sometimes used during active investigations, they can make it harder for customers and the public to discover information about breaches through web searches.

Advertisement

The incident reflects a broader pattern across the fintech and crypto-adjacent sectors, where attackers increasingly target trusted communication channels instead of core systems. As companies integrate more third-party tools to manage customer relationships, marketing campaigns, and operational workflows, the attack surface expands beyond traditional network defenses.

For Betterment, the episode has so far not resulted in confirmed financial losses or account takeovers. Still, it highlights how quickly trust can be tested when attackers successfully impersonate a well-known financial platform. The company’s forthcoming post-incident review will likely provide further insight into how the breach occurred and what safeguards will be implemented to reduce the risk of similar attacks in the future.

Risk & affiliate notice: Crypto assets are volatile and capital is at risk. This article may contain affiliate links. Read full disclosure

Advertisement

Source link

Continue Reading
Click to comment

You must be logged in to post a comment Login

Leave a Reply

Crypto World

holds near $1.41 as range tightens, breakout setup builds

Published

on

holds near $1.41 as range tightens, breakout setup builds

XRP is holding near $1.41 after a steady session, but price is stuck in a tight range, with neither buyers nor sellers taking control. The longer it stays compressed between support and resistance, the more likely a sharper move becomes.

News Background

  • XRP traded in line with the broader crypto market, with no major token-specific catalyst driving price action.
  • Whale wallets added roughly 40 million XRP over the past week, suggesting accumulation during consolidation.
  • Market sentiment remains tied to macro conditions, with crypto reacting cautiously to interest rate expectations.

Price Action Summary

  • XRP gained about 0.6%, moving from roughly $1.38 to $1.41
  • Price traded within a tight $1.38–$1.43 range
  • Repeated rejection near $1.42 capped upside
  • Buyers defended dips near $1.38, forming higher lows

Technical Analysis

  • XRP is trading in a tightening range, with support near $1.38 and resistance around $1.42.
  • Higher lows suggest buyers are slowly stepping in, but lack of strong follow-through keeps momentum muted.
  • The structure resembles a compression setup, where price coils before a larger move.
  • Volume is slightly elevated but not strong enough yet to confirm a breakout.

What traders say is next?

  • Traders are watching a break above $1.42 for a move toward $1.45–$1.50.
  • If $1.38 support fails, downside could extend toward $1.30.
  • For now, XRP remains range-bound, with the next move likely driven by a break on either side of this tightening range.

Source link

Continue Reading

Crypto World

Robinhood Approves $1.5B Share Buyback

Published

on

Robinhood Approves $1.5B Share Buyback

Stock and crypto trading platform Robinhood has approved to buy back $1.5 billion worth of its shares.

Robinhood said in a Securities and Exchange Commission filing on Tuesday that the company’s board of directors approved the $1.5 billion share repurchase program, which it will carry out over the next three years.

The program includes $1.1 billion in new incremental capacity, with the remainder rolled over from an older repurchase program.

“Robinhood is a generational company with a massive long-term opportunity,” Robinhood financial chief Shiv Verma said in a statement. “This authorization reflects the confidence of our management team and board in our ability to continue delivering innovative products for customers and creating value for shareholders while returning capital over time.”

Advertisement

The stock buyback, typically seen as signaling that a company believes its stock is undervalued, comes as shares in Robinhood (HOOD) have struggled so far this year amid a broad downturn in stocks and crypto.

Robinhood also said that its subsidiary, Robinhood Securities, entered a $3.25 billion revolving credit facility with JPMorgan Chase, replacing the prior $2.65 billion facility. It can expand by up to $1.62 billion, bringing the maximum credit to $4.87 billion. 

Robinhood stock tanks nearly 5%

Shares in Robinhood ended trading on Tuesday, down 4.7% to $69.08, closing at the lowest level this year. The stock slightly recovered to $70.90 after hours.

Robinhood’s stock is down almost 39% so far this year and has lost 54.7% since its October all-time high of $152.46, as broader macroeconomic concerns and the Iran war impact stocks.

Advertisement
HOOD has tanked nearly 39% so far this year. Source: Google Finance 

However, Robinhood’s share price over the past 12 months has seen it gain nearly 43% as its expanded into other products such as prediction markets and banking.

Analyst sentiment aggregator TipRanks puts the 12-month average Robinhood stock price forecast at $123.85 and agrees that the stock is a “strong buy” based on 16 Wall Street analysts.

Related: SEC gives go-ahead to Nasdaq for tokenized trading trial

Robinhood Chain to launch this year 

Despite its share price woes, Robinhood remains committed to crypto and real-world asset tokenization, launching its own Ethereum layer-2 network to testnet in February.

CEO Vlad Tenev said that the network processed 4 million transactions in its first week of public testnet activity.

Advertisement

Robinhood Chain is designed to support tokenized equities, exchange-traded funds (ETFs) and other traditional financial instruments, and the mainnet launch is planned for later this year.

Magazine: Banks want to run Vietnam’s crypto exchanges, Boyaa’s $70M BTC plan: Asia Express