2021 Robinhood Markets — vishing of support staff; millions of emails/names from support systems
Data compromised
Email addresses and names at scale; limited DOB/ZIP fields for a small subset per Robinhood and press summaries
Technical writeup
Robinhood disclosed a November 2021 incident in which an attacker socially engineered a customer-support employee by phone (~3 Nov 2021 in contemporaneous reporting) to obtain access to customer support tools, exfiltrating more than five million customer email addresses and roughly two million customer names, with a smaller subset (~310 consumers in early summaries) seeing full names, dates of birth, and ZIP codes, and ten accounts described as having more extensive exposure—while Robinhood’s public statements emphasized no bank account, debit card, or SSN exposure in the same narrative. The company engaged Mandiant and law enforcement and described an extortion demand it did not pay.
Root cause
Social engineering (vishing) of customer support enabling access to internal customer-support systems