Skip to content
NetarxImpact Database
Vishing (Voice Phishing)UnknownReported

Betterment named among victims of the January 2026 real-time vishing wave

Betterment · Financial Services · United States · January 9, 2026

What happened

Betterment, a US digital investment adviser, was named by researchers as a victim of the real-time voice-phishing campaign that also hit SoundCloud, with the attack dated 9 January 2026. The campaign targeted single sign-on accounts across education, real estate, energy, financial services and retail, using phishing kits that impersonated Google, Microsoft, Okta and cryptocurrency provider sign-in flows. At least three organisations appeared on a ShinyHunters leak site that has since gone offline.

How the deception worked

The technique was identical across the campaign: a caller reaches an employee, presents as support, and pushes the target's browser through a cloned SSO flow whose pages the operator controls in real time. Because the pages advance under the operator's hand, the spoken script and the on-screen prompt stay in lockstep, and the multi-factor challenge arrives exactly when the caller has told the victim to expect it. Approving a prompt you were just warned about feels like confirmation rather than compromise.

AI involvement · Unknown

No synthetic voice was reported for this campaign; the calls were described as live operators.

The control that would have caught it· our reading, not a claim from the sources

Phishing-resistant, origin-bound authentication plus device-trust checks on SSO would have stopped the relayed session even after a successful call.

Sources (1)

  1. A new wave of 'vishing' attacks is breaking into SSO accounts in real time
    CyberScoop·cyberscoop.comOpen ↗

This entry summarises public reporting. It is not a legal finding, and details can change as investigations conclude. Found an error? Send a correction.