What happened
On the evening of 3 November 2021 an attacker telephoned a Robinhood customer support employee and socially engineered them into granting access to customer support systems. Email addresses for about five million customers and full names for about two million were exposed, with more detailed information for roughly 310 people and extensive account details for about ten. The attacker then demanded an extortion payment, which Robinhood reported to law enforcement.
How the deception worked
The attack was a phone call, not an email. The caller reached a customer support employee and, over the course of the conversation, obtained access to support tooling, most plausibly by presenting as internal IT or as an authorised colleague needing assistance. Support staff are the ideal target for this because their entire job is to be helpful under time pressure to people they cannot see, and their tooling is broad by design: a single support console can query millions of customer records. Robinhood confirmed no Social Security numbers, bank account numbers or debit card numbers were exposed, but the breadth of the customer list made the extortion attempt credible.
The control that would have caught it· our reading, not a claim from the sources
Support consoles need per-record justification, rate limits and bulk-export alerting, and any inbound request for support access should be verified through an internal directory callback.
Sources (2)
- Robinhood data breach affects 7 million customersFortune·fortune.comOpen ↗
- Robinhood Data Breach Leads Data Events in NovemberIdentity Theft Resource Center·idtheftcenter.orgOpen ↗
This entry summarises public reporting. It is not a legal finding, and details can change as investigations conclude. Found an error? Send a correction.