logo

Robinhood account creation flaw abused to send phishing emails

ID: e16d6d94-de15-52cd-817a-67c3f8ad307d

STIX ID: report--e16d6d94-de15-52cd-817a-67c3f8ad307d

Feed Name: Bleeping Computer

Threat Score
55/100

Date Published: 2026-04-27

Date Updated: 2026-04-27

Author: Lawrence Abrams

...
...

A phishing campaign exploited an input-sanitization flaw in Robinhood's account-creation emails to inject HTML into the Device field, causing authentic-looking 'Unrecognized Device' alerts sent from [email protected] (passing SPF/DKIM) to deliver credential-stealing links (notably robinhood.casevaultreview.com). Robinhood confirmed no systems breach, removed the abused field, and advised users to delete the messages and avoid clicking links.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.