Robinhood said an unauthorized person accessed customer-support systems late on November 3, 2021, after socially engineering a support employee by phone. The company reported that email-address entries for about five million people and full names for a different group of about two million people were accessed, alongside smaller groups with additional details. Those figures describe separate data categories; Robinhood did not give one definitive total of unique people affected.
How the Robinhood data-security incident happened
Robinhood’s November 8, 2021 disclosure said the incident took place late on November 3. An unauthorized third party used a phone-based social-engineering attack to obtain access to certain customer-support systems. Social engineering means manipulating a person into providing access or information, rather than necessarily breaking through a technical barrier.
Robinhood said it contained the intrusion and that the intruder then demanded an extortion payment. The company said it informed law enforcement and was investigating with outside security firm Mandiant. Its disclosure did not say whether it paid the demand. Robinhood’s November 8 statement
What information was exposed in the Robinhood breach?
Robinhood’s November 8 disclosure listed several categories and approximate counts. It described the email-address and full-name groups separately, without saying whether they overlapped. Do not add them together as a count of unique customers.
#1 Best Overall
| Robinhood’s disclosure | Information reported accessed | Company-reported scale |
|---|---|---|
| November 8, 2021 | Email-address list | Approximately five million people |
| November 8, 2021 | Full names, in a different group | Approximately two million people |
| November 8, 2021 | Additional information, including name, date of birth, and ZIP code | Approximately 310 people |
| November 8, 2021 | More extensive account details | A subset of approximately 10 customers |
| November 16, 2021 update | Phone numbers in entries | Several thousand entries |
The November 16 update said Robinhood was continuing to analyze other text entries. The company did not provide a definitive unique-person total across these categories. Robinhood’s November 16 update
What Robinhood said was not exposed
Robinhood said it believed the accessed list did not contain Social Security numbers, bank-account numbers, or debit-card numbers. It also reported that there had been no customer financial loss as a result of the incident. These are the company’s stated findings; they do not establish that exposed contact details could not be used in phishing or other misuse attempts.
What affected customers were told to do
In its 2021 disclosure, Robinhood directed customers to its Help Center account-security guidance and advised them to log in to view messages from the company. It said it would never include a link for accessing an account in a security alert. That is guidance from the incident disclosure, not a guarantee that the company’s current alert practices are identical. Robinhood Help Center account-security guidance
If you received an alert claiming to be about the incident, avoid using links in the message to reach your account. Navigate to Robinhood directly using your usual trusted method and check account messages there. This is consistent with the company’s 2021 advice and helps avoid acting on an unverified message.
Later regulatory context
Robinhood’s FY24 regulatory filing says a January 2025 SEC settlement resolved investigations that included cybersecurity issues and the November 2021 data-security incident. The filing also describes a failure to implement adequate policies and procedures designed to detect, prevent, and mitigate identity theft in connection with customer accounts from April 2019 through June 2022. That regulatory finding provides broader context; it does not establish that customers suffered financial loss from the November 2021 incident. Robinhood FY24 regulatory filing
Quick Recap
Best Value
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




