9 November 2021

Robinhood discloses data security incident impacting millions of customers


Robinhood discloses data security incident impacting millions of customers

Mobile stock trading platform Robinhood disclosed a security incident that exposed names and email addresses of nearly 7 million customers, as well as “extensive account details” of a small portion of its users.

The data breach took place on November 3, when a hacker obtained access to certain customer support service by tricking a customer support employee using social engineering techniques. While the company said that the attacker got access only “to a limited amount of personal information for a portion of our customers”, it admitted that stolen information included email addresses for approximately 5 million people, and full names for a different group of approximately 2 million people.

The hacker also stole names, email addresses, dates of birth, zip codes and additional personal information for 310 customers, and “more extensive account details” for approximately 10 people.

“We believe that no Social Security numbers, bank account numbers, or debit card numbers were exposed and that there has been no financial loss to any customers as a result of the incident,” the company said in a blog post revealing the data breach.

Robinhood said the attacker “demanded an extortion payment” and that it promptly informed law enforcement.


Back to the list

Latest Posts

OpenJS Foundation reports attempted supply-chain attacks on JavaScript projects

OpenJS Foundation reports attempted supply-chain attacks on JavaScript projects

The attackers attempted to introduce suspicious updates or asked to be made maintainers of the targeted software.
17 April 2024
Multiple botnets are hunting for vulnerable TP-Link routers

Multiple botnets are hunting for vulnerable TP-Link routers

Cybersecurity researchers have observed a surge in attacks targeting CVE-2023-1389.
17 April 2024
Cisco warns of large-scale brute-force attacks targeting VPNs, SSH services

Cisco warns of large-scale brute-force attacks targeting VPNs, SSH services

The consequences of a successful attack can range from unauthorized network access and account lockouts to denial-of-service conditions.
17 April 2024