Skip to content
Tech News
← Back to articles

Robinhood account creation flaw abused to send phishing emails

read original get Robinhood Security Guide → more articles
Why This Matters

The Robinhood account creation flaw highlights a significant security vulnerability that enabled threat actors to inject convincing phishing emails into legitimate communications, risking user credentials and financial security. This incident underscores the importance of rigorous input sanitization and security protocols in online platforms to protect consumers and maintain trust in digital financial services.

Key Takeaways

Online trading platform Robinhood's account creation process was exploited by threat actors to inject phishing messages into legitimate emails, tricking users into believing their accounts had suspicious activity.

Starting last night, Robinhood customers began receiving "Your recent login to Robinhood" emails stating that an "Unrecognized Device Linked to Your Account" was detected, containing unusual IP addresses and partial phone numbers.

"We detected a login attempt from a device that is not recognized," reads the phishing email. "If this was not you, please review your account activity immediately to secure your account."

RobinHood phishing email

Reddit: @OtisAndPeanut

Included in the email was a button titled "Review Activity Now", which led to a phishing site at robinhood[.]casevaultreview[.]com, which is now down.

However, screenshots on Reddit indicate that the site was likely used to try to steal Robinhood credentials.

What made the emails convincing is that they came from the legitimate Robinhood email address [email protected] and passed SPF and DKIM email security checks.

Exploiting Robinhood account creation onboarding flaw

Attackers abused Robinhood to generate phishing emails by exploiting a flaw in the company's onboarding process that allowed them to inject arbitrary HTML into its account confirmation emails.

... continue reading