Robinhood confirmed earlier this week that it suffered a “data security incident” allowing hackers to obtain millions of email addresses and full names. It now appears that the hackers may have also gained access to an internal tool that they can use to change account settings remotely.
Screenshots proving that hackers got into a Robinhood internal tool that can tweak user accounts were obtained by Motherboard a few days after the company confirmed the data breach. The publication says the screenshots came from someone claiming to be a “proxy” for the hackers. One of the screenshots attached in the report, though most of its content was redacted for obvious reasons, shows a panel of “Login Controls” with options to use for altering account settings.
The tool shows the user’s preferred method of login authentication. Based on the obtained screenshot, anyone who has access to the Robinhood internal tool in question can use it to disable MFA or multi-factor authentication, add a trusted device, log out an account, or even “revoke” a password.
The page also contains detailed user activity with lists of the token hash, device ID, device type, location, and IP addresses used per session. The same screenshot shows that the tool could give remote access to other sensitive information, such as a Robinhood user’s buying power, balances, and tax info. The same page also contains an account holder’s username, email address, and phone number with indicators if they have been verified.
“Certain authorized Robinhood employees have the ability to update accounts as necessary to provide customer support or service accounts, as is standard at most financial institutions and platforms,” the company told Motherboard. Robinhood also said its investigation shows the hackers did not use the hacked tool to tweak any user account.
The release of the screenshots happened just a few days after Robinhood confirmed the hacking incident. The data breach occurred “late in the evening” on Wednesday, Nov. 3, by using a “socially engineered” customer support staff, which was then used to access the company’s customer support systems.
In an announcement on Monday, Robinhood said the hackers obtained five million email addresses and two million full names. “We also believe that for a more limited number of people—approximately 310 in total—additional personal information, including name, date of birth, and zip code, was exposed, with a subset of approximately 10 customers having more extensive account details revealed.”
Photo by Andrew Neel on Unsplash


SpaceX Prioritizes Moon Mission Before Mars as Starship Development Accelerates
Global PC Makers Eye Chinese Memory Chip Suppliers Amid Ongoing Supply Crunch
SpaceX Updates Starlink Privacy Policy to Allow AI Training as xAI Merger Talks and IPO Loom
Elon Musk’s Empire: SpaceX, Tesla, and xAI Merger Talks Spark Investor Debate
Tencent Shares Slide After WeChat Restricts YuanBao AI Promotional Links
SpaceX Seeks FCC Approval for Massive Solar-Powered Satellite Network to Support AI Data Centers
Sony Q3 Profit Jumps on Gaming and Image Sensors, Full-Year Outlook Raised
Nvidia Confirms Major OpenAI Investment Amid AI Funding Race
Nvidia, ByteDance, and the U.S.-China AI Chip Standoff Over H200 Exports
SoftBank Shares Slide After Arm Earnings Miss Fuels Tech Stock Sell-Off
Jensen Huang Urges Taiwan Suppliers to Boost AI Chip Production Amid Surging Demand
AMD Shares Slide Despite Earnings Beat as Cautious Revenue Outlook Weighs on Stock
Nintendo Shares Slide After Earnings Miss Raises Switch 2 Margin Concerns
Nvidia CEO Jensen Huang Says AI Investment Boom Is Just Beginning as NVDA Shares Surge
TSMC Eyes 3nm Chip Production in Japan with $17 Billion Kumamoto Investment
Anthropic Eyes $350 Billion Valuation as AI Funding and Share Sale Accelerate 



