Data breach
Robinhood (2021)
- Records
- 5,003,945
- Breach date
- 3 November 2021Estimated
- Added
- 2 September 2025
What was exposed
2 types of data · 3 more reported
- Email addresses1
- Names1
- Dates of birthReported, not counted
- PostcodesReported, not counted
- Phone numbersReported, not counted
Reported in the breach write-up; not counted in the analysed data.
About this breach
In early November 2021, an intruder tricked a Robinhood customer support employee over the phone into handing over access to internal systems, then walked away with personal data belonging to millions of the trading app's users. This listing contains roughly 5 million records, or 5,003,945 rows, and includes email addresses and names. The estimated attack date is November 3, 2021. Robinhood disclosed the incident five days later, and no individual or group has been identified as claiming the stolen data.
November 3, 2021: An unauthorized party socially engineers a Robinhood customer support employee by phone and gains access to certain customer support systems.
November 8, 2021: Robinhood publicly discloses the breach, says the intrusion has been contained, reports that it rejected an extortion demand, and says it notified law enforcement and hired the security firm Mandiant.
November 16, 2021: Robinhood updates its disclosure, confirming that several thousand entries in the stolen list contained phone numbers.
January 13, 2025: The SEC announces that Robinhood's two broker-dealers agreed to pay $45 million in combined civil penalties over a range of violations, including failures to safeguard customer information connected to the November 2021 incident.
What Information Was Compromised?
Our analysis found the following data types in this breach: email addresses and names.
Robinhood's own security incident notices, published on its newsroom, described additional detail beyond what appears in this listing. The company said the attacker obtained a list of email addresses for approximately five million people and full names for a different group of approximately two million people. For about 310 people, the exposed data also included name, date of birth, and zip code, with roughly 10 customers having more extensive account details revealed. In its November 16 update, Robinhood added that several thousand entries in the list contained phone numbers. The company said it does not believe Social Security numbers, bank account numbers, or debit card numbers were exposed.
Not every individual is affected by every type of data listed here.
What Are the Potential Risks for Affected Individuals?
Robinhood reported no direct financial losses to customers from this breach, and no account passwords or payment details were involved. The risks are still real. A criminal holding a person's email address and name can send convincing phishing emails that impersonate Robinhood or other financial services, asking the recipient to log in to a fake page or hand over additional details. Phone numbers in the stolen list enable smishing (fraudulent text messages) and, in some known cases involving exposed numbers, SIM swapping attempts that can lead to account takeovers. For the small group whose dates of birth and zip codes were exposed, those details can help criminals pass basic identity checks elsewhere.
What Is Robinhood Doing in Response?
Robinhood said it contained the intrusion, refused the attacker's extortion payment, contacted law enforcement, and retained Mandiant to investigate. The company began notifying affected customers and published updates as its investigation progressed. More than three years later, the SEC announced a settlement in which Robinhood Securities and Robinhood Financial agreed to pay $45 million in combined penalties for a range of failures, including inadequate response to a known cybersecurity vulnerability related to remote access to their systems from June through November 2021. As of September 2, 2025, no individual had been publicly identified or charged in connection with the breach, and the identity of the attacker remains unknown based on reporting reviewed.
What Should You Do If You Were Affected?
Watch your email carefully. Delete or report messages claiming to come from Robinhood that ask for passwords, codes, or account details, and reach Robinhood only through its official app or website.
Turn on two-factor authentication for your Robinhood account and for your email account. Prefer an authentication app over text messages where possible.
Contact your mobile carrier and ask about extra protections on your number, such as a port-out freeze, to reduce SIM swapping risk.
Review your account statements for transactions you do not recognize.
Consider a password manager so the same password is never reused across financial and email accounts.
In the news
- Robinhood Announces Data Security Incident (Update), Robinhood Newsroomrobinhood.com (opens in a new tab)
- BBC News, Robinhood trading app hit by data breach affecting seven millionbbc.com (opens in a new tab)
- SEC Press Release 2025-5, Two Robinhood Broker-Dealers to Pay $45 Millionsec.gov (opens in a new tab)
- Barracuda Blog, Robinhood breach illustrates the impact of social engineering attacksblog.barracuda.com (opens in a new tab)
