{"meta":{"database":"Global Social Engineering Impact Database","license":"CC BY 4.0 — attribute to Netarx Social Engineering Incident Database","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2021-robinhood-support-employee-socially-engineered-by-phone-7-million-custom"},"incident":{"slug":"2021-robinhood-support-employee-socially-engineered-by-phone-7-million-custom","title":"Robinhood support employee socially engineered by phone; 7 million customers exposed","date":"2021-11-03","date_precision":"day","year":2021,"victim_org":"Robinhood Markets","sector":"Financial Services","country":"United States","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Help Desk Impersonation"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Data Breach","Extortion"],"loss_usd":null,"loss_kind":null,"loss_note":"An extortion demand was made; Robinhood said it reported the demand to law enforcement rather than paying.","records_affected":7000000,"threat_actor":null,"summary":"On the evening of 3 November 2021 an attacker telephoned a Robinhood customer support employee and socially engineered them into granting access to customer support systems. Email addresses for about five million customers and full names for about two million were exposed, with more detailed information for roughly 310 people and extensive account details for about ten. The attacker then demanded an extortion payment, which Robinhood reported to law enforcement.","how_it_worked":"The attack was a phone call, not an email. The caller reached a customer support employee and, over the course of the conversation, obtained access to support tooling, most plausibly by presenting as internal IT or as an authorised colleague needing assistance. Support staff are the ideal target for this because their entire job is to be helpful under time pressure to people they cannot see, and their tooling is broad by design: a single support console can query millions of customer records. Robinhood confirmed no Social Security numbers, bank account numbers or debit card numbers were exposed, but the breadth of the customer list made the extortion attempt credible.","lessons":"Support consoles need per-record justification, rate limits and bulk-export alerting, and any inbound request for support access should be verified through an internal directory callback.","confidence":"Confirmed","sources":[{"title":"Robinhood data breach affects 7 million customers","url":"https://fortune.com/2021/11/08/robinhood-data-breach-7-million-customers","publisher":"Fortune"},{"title":"Robinhood Data Breach Leads Data Events in November","url":"https://www.idtheftcenter.org/post/robinhood-data-breach-leads-data-events-november-number-data-compromises-reaches-all-time-high/","publisher":"Identity Theft Resource Center"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2021-robinhood-support-employee-socially-engineered-by-phone-7-million-custom"}}