Betterment Hacked: Cyberattack Sparks Fake Crypto Scam
Automated investing giant Betterment confirmed on Monday that hackers breached its systems on January 9, compromising customer personal data to launch a fraudulent cryptocurrency scam.
How the Betterment Security Breach Happened
According to an internal email sent to affected users, the security incident stemmed from a sophisticated social engineering attack. The attackers successfully targeted “third-party platforms” that Betterment utilizes for its daily marketing and operational activities.
During the intrusion, unauthorized external actors managed to access sensitive customer details. The compromised data includes:
- Full names
- Email addresses
- Physical postal addresses
- Phone numbers
- Dates of birth
Inside the Fraudulent Crypto Phishing Scheme
Armed with access to Betterment’s operational systems, the hackers dispatched a highly deceptive notification to users. The fraudulent message falsely promised to triple the value of users’ cryptocurrency holdings if they transferred $10,000 to an external digital wallet controlled by the attackers, as first reported by The Verge.
Betterment, which officially allows customers to invest in digital assets, subsequently published an announcement regarding the breach on its website. However, the robo-advisor firm did not disclose the exact number of customers targeted by the phishing campaign, nor did it specify how many profiles were accessed or stolen during the incident.
Immediate Response and Damage Control
Betterment stated that its security team detected the intrusion on the same day it occurred. The company immediately revoked the unauthorized access and initiated a comprehensive investigation alongside an unnamed external cybersecurity firm.
The fintech company has since contacted the targeted customer segment, advising them to completely disregard the fraudulent transaction request. Betterment also emphasized that the core financial systems remain secure.
“Our ongoing investigation has continued to demonstrate that no customer accounts were accessed and that no passwords or other log-in credentials were compromised,” Betterment assured customers in the email.
Controversy Over Hidden “Noindex” Search Tags
Despite the company’s efforts to notify affected users, the transparency of its public disclosure has raised questions. Representatives for Betterment did not immediately respond to requests for additional comments regarding the specifics of the cyberattack.
Furthermore, analysis of Betterment’s public security incident page reveals that the site contains a hidden “noindex” tag within its HTML source code. This specific directive instructs search engines like Google to ignore the page, effectively preventing the data breach notice from appearing in public search results and keeping the incident out of the mainstream spotlight.</
