Hackers Abuse Robinhood Signup Process to Deliver Phishing Emails
ID: 66e5184d-71d8-5845-a0ef-8919a12eb9ad
STIX ID: report--66e5184d-71d8-5845-a0ef-8919a12eb9ad
Feed Name: TechRepublic Security
Over a weekend, attackers exploited an unsanitized "device name" field in Robinhood's account signup flow to inject HTML into automated login-notification emails, causing authentic-looking messages from [email protected] (which passed SPF/DKIM) to include phishing links that led to credential theft sites; attackers reportedly used Gmail dot-aliasing and possibly leaked email lists to reach victims, and Robinhood has since removed the vulnerable field and urged users to delete any suspicious emails.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
