Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
mass-credential-exposurebreach-disclosure-notificationfinancial-sector-threatunderground-data-leak

Betterment and CarGurus Data Breach Claims Involving Stolen Customer and Corporate Records

Updated 3mo agoFirst seen Feb 19, 20263 sources

Fintech platform Betterment reported a January 2026 social-engineering incident in which an employee was tricked into providing credentials that enabled unauthorized access to internal messaging systems via third-party tools. Betterment said it detected and contained the access the same day, launched an external forensic investigation, and later indicated the incident affected roughly 1.4 million customers; exposed data included names, email addresses, and location data broadly, with a smaller subset including phone numbers, physical addresses, dates of birth, job titles, and device details. Betterment stated that no financial accounts, logins, or passwords were accessed, but warned that the stolen PII was used to send crypto-scam messages impersonating Betterment to pressure users into transferring funds.

Separately, the extortion group ShinyHunters claimed it stole 1.7 million CarGurus corporate records and threatened to leak the data if the company did not engage by a stated deadline; the criminals alleged the haul included PII and internal corporate data, and CarGurus had not publicly confirmed the claim at the time of reporting. The same reporting tied the CarGurus claim to a broader run of ShinyHunters-related leak-site postings and extortion threats against other organizations, with at least one victim (Canada Goose) indicating that data recently published online may have been historical rather than from a new intrusion.

Share:
Betterment and CarGurus Data Breach Claims Involving Stolen Customer and Corporate Records
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

7 events from the most recent confirmed update back to the earliest known activity.

7 EVENTS
Feb 20, 20264mo ago

ShinyHunters sets CarGurus extortion deadline

The group threatened to leak the allegedly stolen CarGurus data unless the company engaged by 2026-02-20. This marked the extortion phase of the claimed CarGurus breach.

Feb 19, 20264mo ago

Betterment discloses 1.4 million customers affected

Betterment reported that about 1.4 million customers were impacted, with exposed data including names, email addresses, and locations, and additional PII for a smaller subset. The disclosure was reported publicly in February 2026.

Feb 18, 20264mo ago

ShinyHunters claims breach of CarGurus and theft of 1.7M records

On 2026-02-18, ShinyHunters claimed it had breached CarGurus and stolen 1.7 million corporate records, including personally identifiable information and internal company data. CarGurus did not immediately respond to media inquiries.

ShinyHunters lists Figure Technology Solutions on leak site

Figure Technology Solutions was named on ShinyHunters' leak site, and the company said the incident began after an employee was socially engineered. Figure said it blocked the activity, hired a forensic firm, and offered credit monitoring.

Jan 9, 20266mo ago

Attackers send Betterment-branded crypto scam messages

Using the compromised Betterment access, the attackers sent fraudulent Betterment-branded notifications urging users to transfer funds to attacker-controlled cryptocurrency wallets. Betterment warned customers to ignore the scam messages and to monitor for suspicious activity and use MFA.

Betterment detects intrusion and revokes access

On 2026-01-09, Betterment detected the unauthorized access, revoked the compromised permissions the same day, and began an external forensic investigation. The company later said no financial accounts, logins, or passwords were accessed.

Jan 1, 20266mo ago

Betterment employee socially engineered in January 2026 breach

In January 2026, attackers tricked a Betterment employee into providing credentials, enabling unauthorized access to internal messaging systems through third-party tools. The intrusion was described as social-engineering-driven and later linked in reporting to ShinyHunters' broader activity.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

23 LINKEDOpen in app
Threat actors
1 linked
Affected products
3 linked
TelegramWhatsappSpotify
Organizations
19 linked
BettermentHave I Been PwnedMailchimpCrunchbaseOkcupidOktaCarMaxMicrosoft CorporationCarvanaMatch.comEdmundsHingeMatch GroupPanera BreadFigureCanada GooseMercer AdvisorsCarGurusBeacon Pointe Advisors
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.