Robinhood
Disclosed Nov 8, 20214 years ago7,000,000 affectedConfirmed
Social engineering of support agent exposes 7 million Robinhood customers
An attacker socially engineered a Robinhood support employee by phone and obtained email addresses for about five million people and full names for about two million others, with more details for about 310 people, then demanded an extortion payment.
What is known
| People affected | 7,000,000 (as reported by the organization) |
|---|---|
| Disclosed | Nov 8, 2021 |
| Discovered | Nov 3, 2021 |
| Happened | Nov 3, 2021 |
| Attack | Phishing |
| Data exposed | Emails, Names, Dates of birth |
| Sector | Finance · US |
| Status | Confirmed |
| Check your email | Have I Been Pwned |
Sources
| Source | |
|---|---|
| Have I Been Pwned: Robinhoodhaveibeenpwned.com · Aggregator | Aggregator |
| Robinhood Announces Data Security Incident (8-K Ex. 99.1)sec.gov · SEC filing | SEC filing |
Notices filed
| Where | Filed | People |
|---|---|---|
| Researchtotal | Nov 8, 2021 | 7,000,000 |
| Have I Been Pwnedaccounts in the data | Mar 3, 2022 | 5,003,937 |
History of this record
- 2026-09-25 · source_type: aggregator to filing · seed source
- 2026-09-25 · source_url: https://haveibeenpwned.com/Breach/Robinhood to https://www.sec.gov/Archives/edgar/data/1783879/000178387921000073/exhibit991november82021blo.htm · seed source
- 2026-09-25 · status: disclosed to confirmed · seed source
- 2026-09-25 · verified_by: empty to research · seed source
- 2026-09-25 · verified: 0 to 1 · seed source
- 2026-09-25 · country: empty to US · seed source
- 2026-09-25 · sector: tech to finance · seed source
- 2026-09-25 · attack: unknown to phishing · seed source
- 2026-09-25 · data_types: ["emails"] to ["emails","names","dob"] · seed source
- 2026-09-25 · records_basis: hibp to organization · seed source
- 2026-09-25 · records: 5003937 to 7000000 · seed source
- 2026-09-25 · disclosed: 2022-03-03 to 2021-11-08 · seed source
- 2026-09-25 · discovered: empty to 2021-11-03 · seed source
- 2026-09-25 · summary: In November 2021, the online trading platform Robinhood suffered a data breach after a customer service representative was socially engineered. The incident exposed over 5M customer email addresses and 2M customer names. to An attacker socially engineered a Robinhood support employee by phone and obtained email addresses for about five million people and full names for about two million others, with more details for about 310 people, then demanded an extortion · seed source
- 2026-09-25 · title: empty to Social engineering of support agent exposes 7 million Robinhood customers · seed source
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (Have I Been Pwned), confirmed by Research. Record counts are as reported. Not legal advice.