Hackers Use Robinhood Email Pipeline for Authenticated Phishing Emails

robot
Abstract generation in progress

Hackers used Robinhood’s own notification pipeline to send phishing emails that appeared to come from [email protected] and passed standard email authentication checks. Gmail routed some of the messages into the same threads as legitimate Robinhood security alerts. The exploit combined Gmail’s dotted-address behavior with unsanitized HTML in a Robinhood email template, according to security researcher Abdel Sabbah.

This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • Comment
  • Repost
  • Share
Comment
Add a comment
Add a comment
No comments
  • Pin