Unverified claim — In June 2026, a post on an underground forum alleged that a database containing the personal information of 14.5 million Robinhood users had been leaked or offered for sale. The actor used the handle DuckDB (unrelated to the DuckDB analytics database company). Security researcher Nicolas Krassas (@Dinosn) flagged the listing. Robinhood had not confirmed any new breach or unauthorized access at publication time.
What the Actor Claims
The underground forum listing alleges:
- 14.5 million Robinhood user records
- Personal information offered for sale on a darkweb marketplace
- Posted by an actor operating under the handle "DuckDB"
No independently verified data sample or company acknowledgment had been published at the time this article was written. Darkweb listings frequently recycle old breach data or inflate counts — treat this as unconfirmed until Robinhood or a regulator responds.
Not the 2021 Robinhood Breach
This claim is separate from Robinhood's confirmed November 2021 data security incident, in which a threat actor socially engineered a customer support employee and accessed personal information for approximately 7 million customers (names and email addresses for most; additional phone numbers for a smaller subset). Robinhood disclosed that incident in its newsroom update.
Why This Matters If Verified
Robinhood is one of the largest retail trading platforms in the United States. A confirmed breach affecting 14.5 million users would expose a large pool of investors to:
- Targeted phishing impersonating Robinhood support or tax documents
- Credential-stuffing attacks if emails or password hashes were included
- Social engineering using account or trading metadata
What to Do Now
- Enable two-factor authentication (2FA) on your Robinhood account if not already active.
- Change your Robinhood password — use a unique password not reused elsewhere.
- Watch for phishing — Robinhood will never ask for your password or 2FA code via email or SMS.
- Monitor account activity for unauthorized trades, withdrawals, or linked bank changes.
- Check Have I Been Pwned at haveibeenpwned.com for prior exposures involving your email.
We will update this article if Robinhood issues a statement or if independent researchers validate a sample from the alleged dataset.
Canonical breach record: breachhistory.com/robinhood/robinhood-duckdb-claim2026
Sources: Nicolas Krassas (@Dinosn) — threat intel | Robinhood — 2021 incident disclosure