Mark RadarMARK RADAR
EN

Malicious Code Injected into Robinhood’s Official Domain to Send Phishing Emails

2 reports · First detected 2026-04-28 · Last active 2026-04-28

Robinhood is a U.S. FinTech platform offering trading in stocks, ETFs, futures and crypto assets. It previously suffered a data breach affecting about 7 million customers in November 2021. The latest attack went beyond merely spoofing a domain: it abused email sent from Robinhood’s officially registered domain, allowing messages to pass SPF and DKIM authentication and sharply increasing the risk that users would trust them and surrender their login credentials.

On the evening of April 26, 2026, some users received alerts about unusual login activity from noreply@robinhood.com. The attackers used Gmail’s dot-alias feature to register duplicate accounts and injected malicious HTML into a device field, redirecting victims to a credential-stealing website. Robinhood said on April 27 that it had patched the vulnerability and confirmed that its systems, personal data and customer funds were unaffected. It did not disclose any financial losses.

All Coverage

2 original reports

The Backstory

The history behind this event

No historical echoes for this signal

Mark Radar|MARK RADAR