What happened
Betterment, a US digital investment adviser, was named by researchers as a victim of the real-time voice-phishing campaign that also hit SoundCloud, with the attack dated 9 January 2026. The campaign targeted single sign-on accounts across education, real estate, energy, financial services and retail, using phishing kits that impersonated Google, Microsoft, Okta and cryptocurrency provider sign-in flows. At least three organisations appeared on a ShinyHunters leak site that has since gone offline.
How the deception worked
The technique was identical across the campaign: a caller reaches an employee, presents as support, and pushes the target's browser through a cloned SSO flow whose pages the operator controls in real time. Because the pages advance under the operator's hand, the spoken script and the on-screen prompt stay in lockstep, and the multi-factor challenge arrives exactly when the caller has told the victim to expect it. Approving a prompt you were just warned about feels like confirmation rather than compromise.
AI involvement · Unknown
No synthetic voice was reported for this campaign; the calls were described as live operators.
The control that would have caught it· our reading, not a claim from the sources
Phishing-resistant, origin-bound authentication plus device-trust checks on SSO would have stopped the relayed session even after a successful call.
Sources (1)
This entry summarises public reporting. It is not a legal finding, and details can change as investigations conclude. Found an error? Send a correction.