Malicious Code Injected into Robinhood’s Official Domain to Send Phishing Emails
Robinhood is a U.S. FinTech platform offering trading in stocks, ETFs, futures and crypto assets. It previously suffered a data breach affecting about 7 million customers in November 2021. The latest attack went beyond merely spoofing a domain: it abused email sent from Robinhood’s officially registered domain, allowing messages to pass SPF and DKIM authentication and sharply increasing the risk that users would trust them and surrender their login credentials.
On the evening of April 26, 2026, some users received alerts about unusual login activity from noreply@robinhood.com. The attackers used Gmail’s dot-alias feature to register duplicate accounts and injected malicious HTML into a device field, redirecting victims to a credential-stealing website. Robinhood said on April 27 that it had patched the vulnerability and confirmed that its systems, personal data and customer funds were unaffected. It did not disclose any financial losses.
All Coverage
2 original reportsThe Backstory
The history behind this eventNo historical echoes for this signal
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.