Robinhood account creation flaw abused to send phishing emails

Threat actors used the account creation procedure on the online trading site Robinhood to insert phishing messages into authentic emails, leading customers to believe their accounts had suspicious activity.

Customers of Robinhood started getting “Your recent login to Robinhood” emails yesterday night, informing them that a “Unrecognized Device Linked to Your Account” with odd IP addresses and partial phone numbers had been found.

After reading the phishing email, we discovered an attempt to log in from an unidentified device. Please check your account activity right away to secure your account if this wasn’t you.

The email contained a “Review Activity Now” button that directed users to the now-defunct phishing website at robinhood[.]casevaultreview[.]com.

Reddit screenshots, however, suggest that the website was probably used to attempt to steal Robinhood login details.

The emails were convincing because they passed SPF and DKIM email security checks and originated from the official Robinhood email address read more about Robinhood account creation flaw abused to send phishing emails.

Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.

Leave a Reply

Your email address will not be published. Required fields are marked *