Robinhood Markets Incorporations warned customers that a third party had obtained access to the email addresses of about five million of its customers.
The fee-free broker said the full names of a different group of about two million people were also exposed in the breach, while 310 people had more personal information, including names, birth, dates and zip codes, compromised.
Hackers may use the stolen data to attempt to trick Robinhood members with ruses comparable to “phishing” emails pretending to be the corporate.
Robinhood said it believed no social security numbers, bank account numbers or debit card numbers were exposed and that no customers suffered any financial loss as a result of the November 3 incident.
"The unauthorized party socially engineered a customer support employee by phone and obtained access to certain customer support systems," the company said in a blog post, adding that the third party had demanded an extortion payment.
The company's shares fell about 3% in extended trading.
Sundar N Balasubramanian, Managing Director, Check Point Software Technologies, India & SAARC said on what users can do to stay protected:
“ Robinhood Data Leak: What Users can do to Stay Protected :
• Change passwords immediately
• Enable two-factor authentication
• Watch out for suspicious emails
Socially engineered attacks are becoming more mainstream. In these cyber-attacks, hackers use human interactions to carry out their malicious activities, psychologically manipulating people into making security mistakes or giving away sensitive information. The information leaked here is sensitive and bad news for the Robinhood community. Malicious hackers can use the information leaked to carry out more attacks against the victims, like targeted phishing emails, as names and dates of birth can often be used to verify a person’s identity. We urge Robinhood users to change their passwords immediately, enable two-factor authentication, and to watch out for any suspicious emails in their inboxes. According to our research, 95% of malicious files in India are delivered via email.”





