logo

Hackers Abuse Robinhood Signup Process to Deliver Phishing Emails

ID: 66e5184d-71d8-5845-a0ef-8919a12eb9ad

STIX ID: report--66e5184d-71d8-5845-a0ef-8919a12eb9ad

Feed Name: TechRepublic Security

Threat Score
65/100

Date Published: 2026-04-29

Date Updated: 2026-05-05

Author: Aminu Abdullahi

...
...

Over a weekend, attackers exploited an unsanitized "device name" field in Robinhood's account signup flow to inject HTML into automated login-notification emails, causing authentic-looking messages from [email protected] (which passed SPF/DKIM) to include phishing links that led to credential theft sites; attackers reportedly used Gmail dot-aliasing and possibly leaked email lists to reach victims, and Robinhood has since removed the vulnerable field and urged users to delete any suspicious emails.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.