Robinhood community suffered from a data breach incident after the unauthorized party received a list of full names for a different group of about two million persons and a list of email addresses for about five million people.
The compromised information did not include Social Security numbers, bank account numbers, or debit card numbers, and there has been no financial loss to any customers as a result of the incident.
Additional personal information, including name, date of birth, and zip code, was exposed.
The Unauthorized party sought money as ransom.
They immediately notified law police, and with the assistance of Mandiant, a preeminent outside security company, we are still looking into the matter.
Source: https://blog.robinhood.com/news/2021/11/8/data-security-incident
TPRM report: https://scoringcyber.rankiteo.com/company/robinhood
"id": "rob2342101122",
"linkid": "robinhood",
"type": "Breach",
"date": "11/2021",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization's existence"
{'affected_entities': [{'customers_affected': ['2 million', '5 million'],
'industry': 'Financial Services',
'name': 'Robinhood',
'type': 'Company'}],
'data_breach': {'number_of_records_exposed': ['2 million', '5 million'],
'personally_identifiable_information': ['Full names',
'Email addresses',
'Name',
'Date of birth',
'Zip code'],
'type_of_data_compromised': ['Full names',
'Email addresses',
'Name',
'Date of birth',
'Zip code']},
'description': 'Robinhood community suffered from a data breach incident '
'after the unauthorized party received a list of full names '
'for a different group of about two million persons and a list '
'of email addresses for about five million people. The '
'compromised information did not include Social Security '
'numbers, bank account numbers, or debit card numbers, and '
'there has been no financial loss to any customers as a result '
'of the incident. Additional personal information, including '
'name, date of birth, and zip code, was exposed. The '
'Unauthorized party sought money as ransom. They immediately '
'notified law police, and with the assistance of Mandiant, a '
'preeminent outside security company, we are still looking '
'into the matter.',
'impact': {'data_compromised': ['Full names',
'Email addresses',
'Name',
'Date of birth',
'Zip code']},
'investigation_status': 'Ongoing',
'motivation': 'Financial Gain',
'ransomware': {'ransom_demanded': True},
'response': {'law_enforcement_notified': True,
'third_party_assistance': 'Mandiant'},
'title': 'Robinhood Data Breach',
'type': 'Data Breach'}