Robinhood breach exposes data on millions of users

Robinhood breach exposes data on millions of users
The online brokerage said an intruder obtained personal information on about 7 million customers and then demanded payment.
NOV 09, 2021
By  Bloomberg

Robinhood Markets Inc. said personal information of about 7 million people -- or roughly a third of its customers -- was compromised in a data breach last week and that the culprit had demanded payment. 

The intruder obtained email addresses of about 5 million people as well as full names for a separate group of about 2 million, Robinhood said Monday in a statement. For some customers, even more personal data was exposed, including names, birth dates and ZIP codes of about 310 people, and more extensive information belonging to a group of about 10.

The Menlo Park, California-based brokerage said it doesn't believe any Social Security, bank account or debit card numbers were exposed during the incident, which occurred last Wednesday, or that any customers incurred financial losses. 

The hacker made threats about what would be done with the compromised information, although it wasn’t a ransomware attack, according to a Robinhood spokesperson, who declined to say whether the firm paid the perpetrator.

Shares of Robinhood fell 3% to $36.84 in extended trading at 5:30 p.m. in New York. The shares were little changed on the year through the close of regular trading.

The attack hinged on a phone call with a customer service representative, whom the intruder used to gain access to support systems, according to the statement. Robinhood said it contained the breach, notified law enforcement and enlisted security firm Mandiant Inc. to investigate the breach.

Charles Carmakal, chief technology officer at Mandiant, said that Robinhood “conducted a thorough investigation to assess the impact” and that his firm expects the intruder to continue to target and extort other organizations over the next several months.

In a separate episode last year, almost 2,000 Robinhood accounts were compromised in a hacking spree in which customer accounts were looted. Some complained there was no one available to call.

Since then, the company has been working to demonstrate that it’s a reliable brokerage for new investors. Executives often repeat the maxim that Robinhood is a “safety first” company.

Robinhood, which helped popularize free trading, went on a hiring binge for customer-service staff, more than tripling the size of that team in 2020. The brokerage opened offices in Arizona, Texas and Colorado as part of its expansion. It unveiled 24/7 phone support last month.

Latest News

Trump not planning to fire Powell, market tension eases
Trump not planning to fire Powell, market tension eases

Futures indicate stocks will build on Tuesday's rally.

From stocks and economy to their own finances, consumers are getting gloomier
From stocks and economy to their own finances, consumers are getting gloomier

Cost of living still tops concerns about negative impacts on personal finances

Women share investing strengths, asset preferences in new study
Women share investing strengths, asset preferences in new study

Financial advisors remain vital allies even as DIY investing grows

Trump vows to 'be nice' to China, slash tariffs
Trump vows to 'be nice' to China, slash tariffs

A trade deal would mean significant cut in tariffs but 'it wont be zero'.

Fed's Kugler warns of worse-than-expected impact of tariffs
Fed's Kugler warns of worse-than-expected impact of tariffs

Inflation, economic risk is greater than previously thought.

SPONSORED Compliance in real time: Technology's expanding role in RIA oversight

RIAs face rising regulatory pressure in 2025. Forward-looking firms are responding with embedded technology, not more paperwork.

SPONSORED Advisory firms confront crossroads amid historic wealth transfer

As inheritances are set to reshape client portfolios and next-gen heirs demand digital-first experiences, firms are retooling their wealth tech stacks and succession models in real time.