Close Menu
    Facebook X (Twitter) Instagram
    Wifi PortalWifi Portal
    • Blogging
    • SEO & Digital Marketing
    • WiFi / Internet & Networking
    • Cybersecurity
    • Tech Tools & Mobile / Apps
    • Privacy & Online Earning
    Facebook X (Twitter) Instagram
    Wifi PortalWifi Portal
    Home»Cybersecurity»Robinhood account creation flaw abused to send phishing emails
    Cybersecurity

    Robinhood account creation flaw abused to send phishing emails

    adminBy adminApril 28, 2026No Comments3 Mins Read
    Facebook Twitter LinkedIn Telegram Pinterest Tumblr Reddit WhatsApp Email
    Robinhood
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Robinhood

    Online trading platform Robinhood’s account creation process was exploited by threat actors to inject phishing messages into legitimate emails, tricking users into believing their accounts had suspicious activity.

    Starting last night, Robinhood customers began receiving “Your recent login to Robinhood” emails stating that an “Unrecognized Device Linked to Your Account” was detected, containing unusual IP addresses and partial phone numbers.

    “We detected a login attempt from a device that is not recognized,” reads the phishing email. “If this was not you, please review your account activity immediately to secure your account.”

    image

    Included in the email was a button titled “Review Activity Now”, which led to a phishing site at robinhood[.]casevaultreview[.]com, which is now down. 

    However, screenshots on Reddit indicate that the site was likely used to try to steal Robinhood credentials.

    What made the emails convincing is that they came from the legitimate Robinhood email address noreply@robinhood.com and passed SPF and DKIM email security checks.

    Exploiting Robinhood account creation onboarding flaw

    Attackers abused Robinhood to generate phishing emails by exploiting a flaw in the company’s onboarding process that allowed them to inject arbitrary HTML into its account confirmation emails.

    BleepingComputer confirmed that when a new Robinhood account is registered, the company automatically sends a “Your recent login to Robinhood” email to the associated address, containing the registration time, IP address, device information, and approximate location.

    To inject the phishing message, threat actors modified their device metadata fields to include embedded HTML, which Robinhood did not properly sanitize.

    This HTML was then injected into the Device: field of the account creation email, causing it to render as a fake “Unrecognized Device Linked to Your Account” message.

    To target Robinhood customers, attackers likely used lists of known customer email addresses from previous data breaches. In November 2021, Robinhood suffered a data breach impacting 7 million customers, with the data later offered for sale on a hacking forum.

    The attackers also used Gmail’s dot aliasing behavior, where adding periods to an address does not change its destination, allowing them to register accounts using variations of real email addresses while still delivering the messages to the intended recipients.

    As a result, recipients received what appeared to be a standard login alert, but with an embedded phishing section warning of “unrecognized activity” and urging them to review their account.

    Robinhood confirmed the incident in a statement posted to X.

    “On Sunday evening, some customers received a falsified email from noreply@robinhood.com with the subject line ‘Your recent login to Robinhood.’,” posted RobinHood.

    “This phishing attempt was made possible by an abuse of the account creation flow. It was not a breach of our systems or customer accounts, and personal information and funds were not impacted.”

    BleepingComputer has confirmed that Robinhood has fixed this flaw by removing the Device: field that was previously abused from their account creation emails.

    Robinhood advises users who received the message to delete it and avoid clicking any links.


    article image

    AI chained four zero-days into one exploit that bypassed both renderer and OS sandboxes. A wave of new exploits is coming.

    At the Autonomous Validation Summit (May 12 & 14), see how autonomous, context-rich validation finds what’s exploitable, proves controls hold, and closes the remediation loop.

    Claim Your Spot

    abused Account creation emails Flaw Phishing Robinhood send
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email
    Previous ArticleHow to summarize your AI visibility
    Next Article Bing Previews AI Citation Share For Webmaster Tools
    admin
    • Website

    Related Posts

    20-Year-Old Malware Rewrites History of Cyber Sabotage

    April 28, 2026

    Mythos Changed the Math on Vulnerability Discovery. Most Teams Aren’t Ready for the Remediation Side

    April 28, 2026

    Malicious AI Prompt Injection Attacks Increasing, but Sophistication Still Low: Google

    April 27, 2026
    Add A Comment
    Leave A Reply Cancel Reply

    Search Blog
    About
    About

    At WifiPortal.tech, we share simple, easy-to-follow guides on cybersecurity, online privacy, and digital opportunities. Our goal is to help everyday users browse safely, protect personal data, and explore smart ways to earn online. Whether you’re new to the digital world or looking to strengthen your online knowledge, our content is here to keep you informed and secure.

    Trending Blogs

    20-Year-Old Malware Rewrites History of Cyber Sabotage

    April 28, 2026

    Pete Bowen talks about why Google Ads is not just about clicks

    April 28, 2026

    Mythos Changed the Math on Vulnerability Discovery. Most Teams Aren’t Ready for the Remediation Side

    April 28, 2026

    Congress Must Reject New Insufficient 702 Reauthorization Bill

    April 28, 2026
    Categories
    • Blogging (69)
    • Cybersecurity (1,546)
    • Privacy & Online Earning (186)
    • SEO & Digital Marketing (945)
    • Tech Tools & Mobile / Apps (1,796)
    • WiFi / Internet & Networking (247)

    Subscribe to Updates

    Stay updated with the latest tips on cybersecurity, online privacy, and digital opportunities straight to your inbox.

    WifiPortal.tech is a blogging platform focused on cybersecurity, online privacy, and digital opportunities. We share easy-to-follow guides, tips, and resources to help you stay safe online and explore new ways of working in the digital world.

    Our Picks

    20-Year-Old Malware Rewrites History of Cyber Sabotage

    April 28, 2026

    Pete Bowen talks about why Google Ads is not just about clicks

    April 28, 2026

    Mythos Changed the Math on Vulnerability Discovery. Most Teams Aren’t Ready for the Remediation Side

    April 28, 2026
    Most Popular
    • 20-Year-Old Malware Rewrites History of Cyber Sabotage
    • Pete Bowen talks about why Google Ads is not just about clicks
    • Mythos Changed the Math on Vulnerability Discovery. Most Teams Aren’t Ready for the Remediation Side
    • Congress Must Reject New Insufficient 702 Reauthorization Bill
    • Bing Previews AI Citation Share For Webmaster Tools
    • Robinhood account creation flaw abused to send phishing emails
    • How to summarize your AI visibility
    • Malicious AI Prompt Injection Attacks Increasing, but Sophistication Still Low: Google
    © 2026 WifiPortal.tech. Designed by WifiPortal.tech.
    • Home
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer

    Type above and press Enter to search. Press Esc to cancel.