aaron perry: you You're listening to another episode of Don't Get Got. Everything you're about to hear is based on verified reporting, court documents, company disclosures, and cybersecurity research. The facts are real, but to put you inside the experience, we dramatize certain moments. The person at the center of the story was never publicly identified. So we've created a character to bring it to life. We do this because cybercrime isn't just about the data. Security awareness is about the people. Eric had been a betterment for a little over two years now. He liked the job. There was good people and it had good benefits. He felt it was the kind of company that genuinely believed it was helping regular people build wealth. And it was. Betterment managed billions of dollars for millions of Americans. They handle investment portfolios and retirement accounts. People trust them with their financial futures. Eric worked on the marketing operations side. His job was making sure the right messages got to the right customers at the right time. He dealt with tax season reminders, product launch emails, and year-end portfolio summaries. He wasn't writing code or building investment algorithms. He was the connective tissue between the brand and the people who used it. It was a normal Thursday morning, January 9th, 2026. There was nothing special about the day. Eric got to his desk a little after nine. He opened his laptop, checked Slack, scanned his email, and started working on a customer segment list for an upcoming campaign. He had a meeting at two, so he was rushing to have everything ready. Around 1130, he walked to the kitchen, made a second cup of coffee, talked to some of his coworkers, and then went back to his desk. He was eating lunch halfway through a turkey sandwich when his phone began to ring. The caller ID simply said IT. So he picked it up. The voice on the other end was upbeat and casual. They said, Hey, this is Marcus from IT. How's it going? Eric leaned back in his chair and said, good man. What's up? Marcus told them that they were rolling out an update to the company's multifactor authentication settings. He said, it's a company wide thing. It shouldn't take more than a couple of minutes. I just need you to verify the login so that the new protocol could sync with your account. Eric didn't think twice about it. IT called about stuff like this all the time. They handle password resets and software updates. And plus, what do I know about IT? Let me just let the professionals do their job. So Eric responded, yeah, sure. What do need me to do? Marcus said he was going to send him a link. Just open it up and log in like you normally would. It should be the same login page that you use every day. A moment later, a link appeared in Eric's text messages. He clicked it and a login page opened up in his browser. It looked exactly like the one that he used every morning. He the same layout, the same logo, all the same fields. So he typed in his username and his password. A push notification popped up on his phone. Marcus, still on the line, said, just go ahead and approve that and we'll be all set. So Eric tapped approve. Marcus quickly wrapped up the phone call. He said, all right, I'm all good. Thanks for your time. Have a good one. And then he hung up. Eric set his phone down, took another bite of a sandwich and went back to work. The whole thing had taken less than three minutes. The next few hours went by normally. Eric finished his segment list and then he went to his two o'clock meeting. He came back to his desk around 3 15. He answered a few Slack messages and started drafting an email that was supposed to go out to customers the following week. Around four o'clock, he noticed something in his sent folder. There was a message that he didn't recognize. It had gone out through one of the marketing platforms that he used every day, but he didn't write it. He didn't even schedule it. He'd never seen it before. Eric opened up the message. It was a customer facing notification. It looked like every other message that Betterment sent. had the same formatting, the same branding, the same little icon. It said that the company was celebrating its best performing year and it was running a limited time promotion. And if you deposit up to $10,000 in Bitcoin or Ethereum to this wallet address provided, your holdings will be tripled within hours. Eric stared at it. He read it again. And then he read it again. He felt a cold prickle at the back of his neck. He hadn't sent this. Nobody on his team had sent this. He checked the platform's activity logs. The message had been sent at 2 47 PM, but he was in his meeting at 2 47 PM. Still, the system showed that it was sent from his account. He quickly walked over to his manager's desk. He said, Hey, did anyone on the team send a crypto promo today? His manager looked at him and said, what crypto promo? Eric showed him the message on his phone and his manager's face changed. Within 20 minutes, Eric was sitting in a conference room that he'd never been in before. Two people from the security team were across the table. One of them had a laptop open and one had a notepad. They weren't angry. They were calm, but they were very, very specific. They asked him to walk him through his entire day. Every call, every email, every link that he clicked. They wanted timestamps and thorough details. Eric told them about his entire morning, the email segment list that he was working on. the coffee that he made himself, the meeting at two. And then he told them about the phone call that he had, you know, the one from Marcus and IT. He told them about the link, the login page, the verification prompt. But while explaining that, the room got really quiet. One of the security team members asked him to describe the login page. Eric said it looked exactly like the one that he used every day. It had the same layout, the same fields, same everything. The security team member nodded slowly and typed something into his laptop. And then he looked up and said something that made Eric's stomach drop. Eric, we don't have anyone named Marcus in IT. More people came in, someone from legal, someone he'd never met who introduced herself as being from the incident response team. At some point, someone mentioned the name CrowdStrike and Eric realized that they were bringing in outside forensic investigators. They told him what they knew so far. Someone called him and personated an IT employee and then walked him through entering his real credentials into a fake login page. When he approved the push notification on his phone, The attacker captured a fully authenticated session. They used that session to access every marketing communication platform connected to his account. They pulled customer data, names, emails, phone numbers, addresses, dates of birth. Eric felt sick. He kept replaying the phone call on his head. Marcus had sounded so normal, so casual. The whole thing felt like nothing. It was a two minute interruption in his afternoon. He was eating a sandwich while it all happened. He asked the security team if there was something he should have noticed, some red flag that he missed. They were honest with him. They told him that the login page was a near perfect replica. They told him that the caller ID had been spoofed. They said it wasn't a random attack. Whoever did this had done their homework and they knew what login system Betterment used. They probably knew Eric's name and role before they ever picked up the phone. None of this made Eric feel better. He went home that night and could barely sleep. By January 10th, Betterment had a public statement on their website telling customers to ignore the crypto message. By the 12th, they put out a more detailed update confirming that it was a social engineering attack. Someone had tricked one of their employees, but no investment accounts were accessed and no passwords were compromised. They didn't name Eric, but Eric knew. His manager kept assuring him and telling him that it wasn't his fault. and Eric nodded, but the nod felt hollow. He started reading everything that he could find online. The Reddit threads where Betterment customers were furious, the tweets asking if the platform was safe. He even started researching the group that did this, Shiny Hunters. He'd never heard of them before. He was reading about how they'd been on a tear, hitting company after company with the same playbook. SoundCloud, Panera, Crunchface, Harvard, the University of Pennsylvania, Match Group, and even Canada Goose. A hundred organizations in a matter of weeks. They used the same playbook, the phone call, the fake login page and the push notifications. So he wasn't the only person that had fallen for it, but that didn't make him feel any different. On January 23rd, two weeks after the phone call, Shiny Hunters published the data. They demanded a ransom and Betterment refused to pay. So Shiny Hunters followed through with their threat. They put Betterment stolen data on the dark web. alongside data from Crunchbase and SoundCloud. A total of 1.4 million customer records were leaked. Eric read the number and closed his laptop. His head began to swim. 1.4 million people. 1.4. All of these people's personal information was now floating in databases that would be bought and sold and used for years. Not because of a software vulnerability, not because someone wrote bad code, but because of a phone call during lunch, all because he tapped approve on his phone. Eric still works in the industry, just not at Betterment. He left a few months after the breach. And not because he was fired, but because he couldn't sit at that desk anymore. He told a friend later that the thing that haunts him isn't the phone call itself. It's how normal it felt. How completely routine the whole thing was. He said, if you replayed that phone call for a hundred people, half of them probably would have did the same thing. And he's probably right. That's what makes this kind of attack so dangerous. It doesn't need you to be stupid. It just needs you to be busy and cooperative and trusting. When someone calls you and claims to be in a position of authority, whether it's IT or your bank or police officer, most of us default to cooperation. We've been trained our entire lives to be helpful when someone sounds official and asks us to do something. It's not a flaw in our character. It's just human nature. So here's the one thing I need you to remember about this story. If someone contacts you by phone, text or email, and they claim to be from any organization that has your money or your data, and they're asking you to do something, just stop. Hang up, find the real number yourself, and call back through a channel that you verified independently. It doesn't matter how real they sound or what the caller ID says. None of that proves anything. The reason these people create urgency, the reason that they say that they need you to act now, is because every second you spend thinking about it is a second you might decide to verify through a different channel. Now, if your data has been exposed and a breach, here's what you do. Go to have I been pawned.com, type in your email, and it'll tell you where your information has shown up. It's free and it takes about 10 seconds. If you're in there, change your password for that service immediately. If you use that same password anywhere else, change it everywhere. You should also think about getting a password manager. Bitwarden is free. ⁓ One password is great, but Apple's built-in one works fine. I use it myself. The point is to never reuse a password again. If your real name, address, and date of birth have been exposed, freeze your credit. You can do it for free at Equifax, Experian, and TransUnion. Doing this means that nobody can open a new account in your name. If you want to stay up to date on stories like this, we send a free newsletter every week at don'tgetgot.co. And if you run a company or a team and you want your employees to actually engage with security awareness, not just click through boring compliance modules, check out don'tgetgot.co slash training. That's don'tgetgot.co slash training. We built it around stories exactly like this one, because we learn from stories and we forget slideshows. If this episode meant something to you, please leave a rating and a review wherever you're listening. It's the single biggest thing that you can do to help other people find the show. That's all I got for you. Thanks for listening and don't get got. ⁓ you ⁓