Robinhood phishing scam spoofs real emails with Gmail dot alias trick

Robinhood users are facing a phishing scam that uses Gmail’s dot alias behavior and Robinhood’s account creation flow to send fake login alerts from the platform’s real email address. Alex Eckelberry said attackers created Robinhood accounts with dotless Gmail variants of a target’s address and injected a phishing button through the optional device name field. Robinhood said the issue was an abuse of its account creation flow, not a breach, and that personal information and funds were not impacted. Hacken reported earlier this month that phishing and social engineering caused $306 million in losses in the first quarter of 2026.

This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • Comment
  • Repost
  • Share
Comment
Add a comment
Add a comment
No comments