Gandalf_The_Grey

Level 55
Verified
Helper
Top poster
Content Creator
Well-known
Apr 24, 2016
4,448
Stock trading platform Robinhood has disclosed a data breach after their systems were hacked and a threat actor gained access to the personal information of approximately 7 million customers.

The attack occurred on November 3rd after a threat actor called a customer support employee and used social engineering to obtain access to customer support systems.

After accessing the support systems, the threat actor was able to access customer information, including full names, email addresses, and for a limited number of people, data of birth, and zip codes.

"At this time, we understand that the unauthorized party obtained a list of email addresses for approximately five million people, and full names for a different group of approximately two million people," disclosed a blog post published today about the security incident.

"We also believe that for a more limited number of people—approximately 310 in total—additional personal information, including name, date of birth, and zip code, was exposed, with a subset of approximately 10 customers having more extensive account details revealed."

In summary, the data breach exposed:
  • Email addresses for 5 million customers.
  • Full names for 2 million.
  • Name, date of birth, and zip code for 300 people.
  • More extensive account information for 10 people.
The company states that they do not believe any Social Security numbers, bank account numbers, or debit card numbers were exposed in the attack.
What should Robinhood customers do?
If you are affected by this data breach or are simply concerned about the safety of your account, Robinhood suggests you take the following steps:
  • Be on the lookout for phishing emails designed to steal your login credentials. Instead, check for messages in the Robinhood app after logging into your account.
  • If you need help, request a phone call from within the app at Account > Help > Contact Us. Robinhood users should never call other numbers you find in emails or the Internet.
  • Only interact with the authorized Robinhood social apps. You can find these social accounts within the app at Help Center > General Questions > Robinhood Social Media.
  • Report suspected phishing scams to reportphishing@robinhood.com
  • Enable 2-factor authentication for Robinhood accounts within the app at Accounts > Security and Privacy > Two-Factor Authentication.
With this latest incident, passwords were not exposed, as the threat actor had access to internal systems, it would not hurt to change your password to be extra cautious.
 

silversurfer

Level 78
Verified
Helper
Top poster
Content Creator
Malware Hunter
Well-known
Aug 17, 2014
6,778

7 million Robinhood user email addresses for sale on hacker forum​

Two days after Robinhood disclosed the attack, a threat actor named 'pompompurin' announced that they were selling the data on a hacking forum.
In a forum post, pompompurin said he was selling 7 million Robinhood customers' stolen information for at least five figures, which is $10,000 or higher.
 
Top