Betterment and CarGurus Data Breach Claims Involving Stolen Customer and Corporate Records
Fintech platform Betterment reported a January 2026 social-engineering incident in which an employee was tricked into providing credentials that enabled unauthorized access to internal messaging systems via third-party tools. Betterment said it detected and contained the access the same day, launched an external forensic investigation, and later indicated the incident affected roughly 1.4 million customers; exposed data included names, email addresses, and location data broadly, with a smaller subset including phone numbers, physical addresses, dates of birth, job titles, and device details. Betterment stated that no financial accounts, logins, or passwords were accessed, but warned that the stolen PII was used to send crypto-scam messages impersonating Betterment to pressure users into transferring funds.
Separately, the extortion group ShinyHunters claimed it stole 1.7 million CarGurus corporate records and threatened to leak the data if the company did not engage by a stated deadline; the criminals alleged the haul included PII and internal corporate data, and CarGurus had not publicly confirmed the claim at the time of reporting. The same reporting tied the CarGurus claim to a broader run of ShinyHunters-related leak-site postings and extortion threats against other organizations, with at least one victim (Canada Goose) indicating that data recently published online may have been historical rather than from a new intrusion.

Get ahead of threats like this
Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
How this story unfolded
7 events from the most recent confirmed update back to the earliest known activity.
ShinyHunters sets CarGurus extortion deadline
The group threatened to leak the allegedly stolen CarGurus data unless the company engaged by 2026-02-20. This marked the extortion phase of the claimed CarGurus breach.
Betterment discloses 1.4 million customers affected
Betterment reported that about 1.4 million customers were impacted, with exposed data including names, email addresses, and locations, and additional PII for a smaller subset. The disclosure was reported publicly in February 2026.
ShinyHunters claims breach of CarGurus and theft of 1.7M records
On 2026-02-18, ShinyHunters claimed it had breached CarGurus and stolen 1.7 million corporate records, including personally identifiable information and internal company data. CarGurus did not immediately respond to media inquiries.
ShinyHunters lists Figure Technology Solutions on leak site
Figure Technology Solutions was named on ShinyHunters' leak site, and the company said the incident began after an employee was socially engineered. Figure said it blocked the activity, hired a forensic firm, and offered credit monitoring.
Attackers send Betterment-branded crypto scam messages
Using the compromised Betterment access, the attackers sent fraudulent Betterment-branded notifications urging users to transfer funds to attacker-controlled cryptocurrency wallets. Betterment warned customers to ignore the scam messages and to monitor for suspicious activity and use MFA.
Betterment detects intrusion and revokes access
On 2026-01-09, Betterment detected the unauthorized access, revoked the compromised permissions the same day, and began an external forensic investigation. The company later said no financial accounts, logins, or passwords were accessed.
Betterment employee socially engineered in January 2026 breach
In January 2026, attackers tricked a Betterment employee into providing credentials, enabling unauthorized access to internal messaging systems through third-party tools. The intrusion was described as social-engineering-driven and later linked in reporting to ShinyHunters' broader activity.
Related entities
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Sources
3 references tracked. Mallory keeps watching after this page renders.
Betterment Suffers a Data Breach - TheCyberThrone
thecyberthrone.in
Open sourceShinyHunters allegedly drove off with 1.7M CarGurus records • The Register
go.theregister.com
Open sourceSecurity Incident Report: January 2026 - Betterment - Infosec.Pub
infosec.pub
Open sourceSee the full picture, correlated to your attack surface.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.


