Robinhood phishing attack exploits Gmail's "dot alias" feature to forge official emails and trick users into logging in

Deep Tide TechFlow News, April 28 — According to Cointelegraph, Robinhood users recently experienced a phishing attack. The attackers exploited Gmail’s disregard for the “.” in email usernames and a vulnerability in Robinhood’s account creation process to register accounts with email addresses very similar to the target’s, thereby causing Robinhood’s official email servers to send forged alert emails containing phishing links to victims’ inboxes. Cybersecurity researcher Alex Eckelberry stated that these emails could pass SPF, DKIM, and DMARC verification and appeared to come from official addresses.

Robinhood stated that this incident was not due to a system or customer account breach, and user funds and personal information were not affected. However, they advised users to delete the relevant emails and avoid clicking on suspicious links.

View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • Comment
  • Repost
  • Share
Comment
Add a comment
Add a comment
No comments