Late on 3 November 2021, an unauthorized party socially engineered a Robinhood customer support employee by phone and obtained access to certain customer support systems. According to Robinhood’s SEC Exhibit 99.1 filed 8 November 2021, that access yielded approximately five million email addresses and full names for approximately two million people, plus smaller subsets of additional personal information. Robinhood stated it believes no Social Security numbers, bank account numbers, or debit card numbers were exposed and that no customer financial loss occurred. Public reporting does not establish which employee login or recovery controls failed, and it does not name a threat actor group.
If you want the prevention angle on workforce phone social engineering of support identities, read the related article on mfa2point0.com.
FAQ
How did attackers get into Robinhood customer support systems in 2021?
The Robinhood 2021 incident began when an unauthorized party socially engineered a customer support employee by phone and obtained access to certain customer support systems. Robinhood’s 8 November 2021 SEC Exhibit 99.1 states that phone social engineering path in plain terms. Public reporting does not establish employee passwords, OTP codes, push approvals, TAP issuance, AiTM pages, or device-code flows. The documented initial failure is workforce phone social engineering that produced support-console access.
What customer data did the Robinhood support intrusion expose?
According to Robinhood’s 8 November 2021 disclosure, the unauthorized party obtained approximately five million email addresses and full names for approximately two million people. About 310 people had additional personal information, including name, date of birth, and zip code. About ten customers had more extensive account details revealed. Robinhood stated it believes no Social Security numbers, bank account numbers, or debit card numbers were exposed.
Did the Robinhood attackers take over customer trading accounts or reset customer MFA?
Robinhood stated there has been no financial loss to any customers as a result of the incident. Public reporting does not establish customer account password changes, customer MFA resets, or customer financial account takeover. The documented path was unauthorized access to certain customer support systems and the contact and limited personal data reachable from those systems, not mass takeover of end-customer logins.
Is phone-vishing a support employee the same class as helpdesk recovery or fake-login coaching?
Yes. Live coaching of a workforce identity into handing over access is one social-engineering class, whether the target is a support employee on a phone call, helpdesk recovery, or a user on a coached fake login. Robinhood’s disclosure stops at phone social engineering of a customer support employee and support-system access. Public reporting does not name TAP or a spoofed page for this incident. A fix for that transferable-factor class exists; the prevention write-up is on the companion site.
What happened after Robinhood contained the intrusion?
After Robinhood contained the intrusion, the unauthorized party demanded an extortion payment. Robinhood informed law enforcement and engaged Mandiant, then announced the incident publicly on 8 November 2021. Public reporting does not establish the extortion demand amount or attribute the intrusion to a named threat actor group. Once support-system access already existed, reading records reachable from that console was a post-access problem; stopping the workforce compromise was the upstream control point.