Skip to main content
Breach Signal

Breach report

Financial Services

Robinhood

Robinhood discloses data breach impacting 7 million customers

A caller talked a Robinhood support employee into granting access to internal tools, letting the attacker pull email addresses and names for about 7 million users of the trading app and then demand an extortion payment.

Reported by BleepingComputer

Records exposed

7M

About 7 million customers

Scale vs. largest on file

When
2021
How they got in
Social engineering of customer support employee by phone
Sector
Financial Services

On November 8, 2021, retail trading app Robinhood disclosed that an unauthorized party had obtained personal information on about 7 million people. The intrusion occurred on the evening of November 3, and the company said it had contained it before announcing the incident publicly five days later.

Robinhood said the attacker phoned a customer support employee and used social engineering to gain access to certain customer support systems. The company did not describe the exact pretext, but the technique of manipulating help-desk staff into handing over access has become a favored method among financially motivated hacking groups, because it bypasses technical defenses entirely. Once inside the support tools, the intruder could view whatever customer records those tools exposed to staff.

For most victims the exposure was limited. About 5 million people had their email addresses taken, and a separate group of about 2 million had their full names exposed. Roughly 310 people had additional information such as dates of birth and ZIP codes compromised, and about 10 of those had more extensive account details revealed. Robinhood said it did not believe Social Security numbers, bank account numbers or debit card numbers were exposed, and that no customers had suffered financial losses as a result.

After the attacker was cut off, they demanded an extortion payment. Robinhood notified law enforcement and brought in incident response firm Mandiant to investigate. Within days, the stolen data was advertised for sale on a hacking forum. The breach came at a sensitive moment for the company, which had gone public in July 2021 and was still facing scrutiny over its role in the meme-stock trading frenzy earlier that year.

Although the data taken was mostly contact information, the incident illustrated a broader risk for fintech platforms. A list of email addresses known to belong to active brokerage customers is valuable for targeted phishing, since recipients are more likely to believe a fake message about their trading account. The case also added to a growing record of breaches that began not with malware but with a convincing phone call, pushing companies to tighten verification procedures and limit what support agents can see and export.

More from the wire

More in Financial Services.

All 107 reports

Private AI for Life

Live your best life with Thinkspan: the all-in-one smart solution for organizing, securing, and accessing personal information. With Thinkspan, your life’s most important information stays protected and accessible.