Robinhood Accounts Looted, No Customer Support
bloomberg.com
bloomberg.com
Also, here's some FINRA arbitration information.[2]
Online users are so used to being powerless, facing unreasonable EULAs, that most are unaware they can push back hard. FINRA has the authority to have brokerage employees fired and barred from the securities industry. So brokerages pay attention when a complaint comes in via FINRA.
[1] https://www.finra.org/investors/have-problem/file-complaint/...
[2] https://www.finra.org/arbitration-mediation/resolution-and-r...
https://nclalegal.org/2019/07/finra-is-a-double-delegation-d...
This is patently false. The Securities and Exchange Commission accredits and oversees all national SROs.
If I walk into a bank with a gun and demand money, everyone agrees I am robbing the bank. But if I walk into your bank and claim to be you, suddenly I am not robbing the bank. I am committing "identity theft," and the bank will take no responsibility and do as little as legally possible to help resolve the situation.
It is a neat trick.
Pass all the expense of being a victim of a crime down to your customers.
[1] https://www.nerdwallet.com/article/credit-cards/merchants-vi...
I used to be a bank teller and we were instructed under no uncertain terms to hand over whatever we had and enjoy a week of paid vacation to recover from any potential trauma suffered.
The bank I worked for had a corporate security team who wouldn’t even stop their lunch break to review one isolated robbery, instead they’d look for serial cases, or occasionally assess how likely it was that it had any “inside job” elements if the robbery didn’t fall within standard profiles.
The actual “vault” in most branches is barely bigger than a high school locker inside the room behind the big metal door. Most everything else kept behind that huge metal door is administrative or customer related documents (arguably worth more than the cash itself!).
Lastly, about once a week, I was tasked with filling the ATMs for a branch that was in a downtown office building lobby. The ATMs were in a wall and had a little secret door that I’d access to audit the machines and count the money I’d refill them with. Each machine could hold 200k or so and there were two of them but there was no real clear way to get the $400,000 from our secured vault to the machines without armed security or something. In order to avoid having to order an escort every time, we’d just load the cash into a printer paper box and stealthily walk it across the lobby like I was just carrying actual printer paper (insert your federal reserve jokes here).
It’d take 2-3 hours to audit and refill the machines, meaning I would have had a nice head start if I had the guts and gray morality to make a run for it.
The policies across the board are to just hand over money. As a result, there's essentially zero fatalities from bank robbery. Maybe a few every year, usually the criminal themselves.
However, bank robbers only get away with about 10% of cases. Clearance rates are super, super high now. And because they're usually serial, almost every single bank robber gets caught. There's a whole slew of tactics used.
Makes perfect sense. They lose a few bucks, vs the $$$$ they'd have to pay in the lawsuit. Let the cops deal with the crooks.
I vaguely recall it's part of FDIC even.
That's not how insurance works. If you file claims against the insurance company, they pay the claim, but your rates go up to cover it. YOU wind up paying.
Later on, he got clean and sober and told his sponsor about the episode. Part of recovery is that you're supposed to be willing to make amends for the damage you've done. His sponsor thought about that one, and said, "You know what? I think we're going to let that one pass." Probably a good decision.
I’d guess my average teller drawer value was somewhere between 2-5k “unlocked” and maybe another 5k kept locked below my station. Not exactly “let’s leave the country and live like kings” money.
As a side note, I met him as he was dying of cancer, and my friend would help take care of him. Id pitch in, but it was mostly my friend doing the day-to-day helping. Absolutely f*ing heartbreaking. There was no one else in his life - no friends, no family, nothing. He was bitter and alone. It was brutal watching him die over a few months.
I guess it makes sense that he quit robbing banks once he got caught.
He got out from prison before he died?
How did he spend the days alone before he got cancer
In both cases neither the bank nor I have done anything wrong. We’re both literally victims of a crime. And through the payments system and the justice system we’ll hopefully be made whole in the end. But the difference is the incentives. When I lose the money the bank has less of an incentive to rectify the situation.
But those are pretty much edge cases. Credit builder and secured credit cards exist for people with poor or no credit.
Costco, gas stations, and some mom & pop shops really want to save on that credit card processing fee.
Personally, I consider missing out on the cash discount at a gas station a convenience & fraud protection fee.
They now have a deal with Visa, along with their own branded Visa card but will accept any bank's Visa card.
I wrote about the story here:
https://www.zainrizvi.io/blog/how-banks-help-scammers-with-t...
As cruel as it sounds, your sister performed a legitimate transaction.
It seems to me that a person ought to be able to reasonably rely on a bank acting like a check has cleared, at least after some clearly stated period of time.
There isn’t a dependency.
The legitimate account holder said “Send $x from my account to y” and the bank did.
There was no fraud in that transaction.
As for your second point - funds are required to be available before the check clears by federal law. Complain to your congresscritter, not the bank.
Not sure why I’m getting downvoted for stating simple facts...
Welcome to HN.
Fixing that wouldn't require a change to the funds availability policy, and wouldn't require it to dishonor any transactions. As the original complaint indicated, it would literally just be a UI tweak: the online banking system could highlight provisionally available funds differently from really really available funds, and in that way communicate to customers what is actually cleared and safe to spend. This isn't a big ask.
In addition to protecting account holders from a massive range of fake check scams, that would also protect them from a bunch of other crooked stuff.
For example: did you know an employer can reverse a direct deposit of a paycheck for some amount of time after it seems to go through?[1] Employees get screwed all the time when their employer randomly decides "oops, we paid you too much" after the money is already spent. Which is insane and unfair but---we wouldn't even have to change the system to protect many employees. Just have banks clearly indicate which direct deposits are final and which might still go poof if the employer unilaterally decides.
[1] old example https://www.nytimes.com/1997/03/23/business/turning-direct-d... --- but I know people to whom this has happened this year.
Once the check is disputed, the money gets yanked back from the depositor’s account. That’s why personal checks are just a completely unreliable method of payment and should only be used between trusting parties.
Your card gets stolen.
Scammer empties out the account.
With a credit card, transactions against the card will get declined after it maxes out (if the fraud checks don't kick in sooner). You report the theft. Everything solves itself quickly. A minor inconvenience at worst.
When your debit card gets stolen, that's YOUR money going out, then your rent check bounces, and it takes weeks to get the money back, and in the meantime, YOU HAVE NO MONEY.
1. Not my name for the payer
2. An out-of-state address
3. Check was not on my bank's paper, they did the logo wrong, etc.
4. Signature was someone else's
Essentially, everything was wrong but the account number. The bank cashed the check, and blamed me. I got very angry about that, and basically sat in the manager's office until he agreed to refund my money.
A couple months later, I ran out of blank checks, and went to the bank to order more. They gave me a song-and-dance about the advanced "security paper" for the expensive check blanks they wanted to sell me. I literally laughed, and told them you guys don't check the name, the address, the signature, and certainly not the paper, and walked out and bought more checks from an online company.
Also, the image of the bad check was what got my money refunded. An electronic trail is simply not as good as a paper one when there's a dispute. A cancelled check is gold in a dispute.
The fact “bad checks” can exist is the problem, which necessitates the use of a literal paper trail.
It is insane.
Maybe FedNow will change things?
The real answer is more prevalance of free ACH transfers. Some companies still like to charge the unneeded credit card fee for those too sadly.
There's only one thing I (typically) use them for nowadays but they do occasionally come in handy at times.
"why is this gate here, let's take it down!"
type comment?
Checks are extremely useful to individuals. You can pay for something, it has no overhead, and you have your own audit trail.
You can probably fake a fax machine or a certified letter too, but I think they are useful too.
The US has a ridiculous level of bank/payment fraud compared to Europe (~15x in some areas, according to the fed), who invested in chip+pin, SEPA, IBAN, etc etc. This all lets me pay for something with no overhead and maintain my own audit trail in a way that doesn’t involve a trust-based system from the 1800s.
The US also has strong consumer protection laws.
I remember a friend of mine had a father in mexico and someone misused his bank card and he was SOL.
In the US, there are laws protecting credit card holders. The most that can be lost is $50 (or $500 in cases of extreme negligence).
What is really happening is that with minimized repercussions a lot of things have almost been decriminalized.
Speaking as a citizen of a country with "real" identification laws, how would you like the banks to identify you?
SSN? Absolutely not. That number is not meant to be used as formal identification, it's completely unprotected.
America has a particular weakness to identify fraud because you don't have an identity system.
My ID number is formally defined in law, protected and verified by various check sums built into the number (like so many tokens out there). Banks are required, by law, to ensure they have identified the right individual before transacting and they carry the full burden if they get it wrong.
The SSN in the US is sequential and I never fail to laugh at the idea of forcing your banks to verify you with such a flimsy structure. It's just gonna make the problem worse
These days, you're CUSTOMER #52219945 at SuperUltraMegaBank with such-and-such mother's maiden name. The local bank employees live 80 miles away where there are cheaper houses, and to them you're just one of thousands of customers in their corporate database. But, you never even see each other because almost all of the banking you do is via their web site, with the occasional telephone call that gets answered by a teller in southeast Asia. It's totally impersonal.
> Rao said he had previously set up two-factor authentication to access his account, and Bagheri said she’s certain her Robinhood password is unique from all others, including her email. Neither believed they had been duped by phishing scams or malware. Both said they use the same email for Robinhood and other accounts, and that only Robinhood has been affected.
Usually, these situations can be at least partially blamed on credential stuffing, but claims such as these warrant further investigation. Credential stuffing isn't supposed to work if 2FA is properly configured, and phishing shouldn't work if something like TOTP is implemented correctly--although it quite often isn't.
TOTP codes can be phished. Hardware-based 2FA is a different matter, but SMS and TOTP 2FA doesn't fully protect against phishing.
The complex attack you are probably thinking of is sim swapping which is a bit different than phising.
Of course, if you're a high-value target or work for a company that's likely to be targeted by spear-phishing campaigns, you should be using FIDO2. (Don't target U2F, as there are newer, backward-compatible specifications.)
If you get a message indicating your password was invalid, you're probably not going to pay a whole lot of attention to it--even with a password manager, it's a common message to receive on financial sites. Some go out of their way to impede password managers because they think that's a good security practice.
If you get a message indicating the 6-digit code you entered is invalid, that should be a lot more concerning to you, and you should immediately ensure that nobody has logged into your account. If you can hold out for however long the site will accept the code (usually 60 seconds, but some sites have a larger window), you're good.
Of course, none of these "ifs" exist with FIDO2 and U2F, which is what everyone should be using instead. If you're in charge of security for a website, please offer FIDO2 and/or U2F.
I could type the 6-digit code incorrectly just as well as I could type the password incorrectly.
Additionally, some sites might check both the password and the 2FA code simultaneously as a security mechanism to prevent attackers learning if the password is correct.
Additionally, the phishing page could simply redirect the user to the real site. The user is likely already logged in to the real site, so it will appear to the user as if the user just performed a successful login. If the user isn't logged in, it will seem like some type of site glitch, and I've experienced glitches like that myself.
I also had an electronic payment made for $700 to the utility company. They said they never got it, but my account was debited. They said take it up with your bank, the bank said take it up with the utility company. After quite a bit of wrangling, I finally demanded to the bank manager that the debit be labelled as "fraudulent" and it be clawed back.
Wonder of wonders, this caused the utility company to magically find the money.
Now I send them paper checks. I also pay my credit card with paper checks, as one time they moved the decimal point over two places (!), and the cancelled check saved me a * lot* of hassle.
Decimal places can't shift with electronic payments.
All B2C debits (SDD Core) have the right to be reversed within 55 days for specific reasons; this can be done online by the account holder and they are instantly refunded.
This is all across Europe, and has been for years now.
Only after living in USA for some time do you realize that many corporations here actually use cheap labor to read electronically submitted information, and then type it back into a computer.
I've had my name misspelled on utility accounts where I signed up online, and damn sure did not misspell it like that.
Yes, USA is stuck in the 70s.
In eastern Germany they skipped checks for cards and it catapulted their payment systems to transcend the first world payment systems within the decade.
Please correct me if I'm wrong.
I think great depressions in tech yield necessary solutions; necessity and invention...
You'd think, right? But the utility company said they never got it, talk to the bank, the bank said they delivered it, talk to the utility company.
> Decimal places can't shift with electronic payments.
When they're OCR'd, yes they can and did. I had to present an image of the check before they would fix it.
There was a physical check? I wouldn't call that an electronic payment.
Robinhood worked well for bootstrapping my portfolio with free trades, but after a certain point it got big enough for me to worry about other factors like this.
Example: I accidentally deposited a check into my IRA once. I called and explained I wasn't sure what to do because 1) the check was post-tax money and 2) if I tried to fix it myself, would it count as an early withdrawal?.
The guy picked up almost immediately, said yep lemme transfer you, the <something> department has a button for that. I got transferred, still to a native english speaker, who sorted me out. A couple days later it was all fixed in my account. 10/10.
I do all my banking with them and if they offered a 2% cashback credit card, I'd move that to them too.
Speaking of which, Citi (I have the doublecash) has been dreadful - my card # got stolen once, and they sent the new credit cards to my old address (that I still - for a bit longer - owned, thankfully) even after I specifically stressed, and confirmed multiple times, that I was 300 miles away from the address and if they sent them there, they'd sit in my porch for 1-2 weeks before I could get to them, and I would also not have a credit card to use.
They reassure me, even getting a bit snippy at the end of the call, that they're sending them to the address I gave them (my parents' house) on the call. And since I'm such an important customer, they're overnighting the cards.
Sure enough, the next day, I check my security camera and see a dang cardboard envelope that says CITICARDS all over it sitting on my old porch 300 miles away.
So I call them up, explain that they did exactly what I asked them not to do, and if they could cancel those cards and try sending them again, because I don't have a credit card right now, and I'm trying to furnish and move into a new house and need to put about $10k of appliances purchases through the cards ASAP. They explain that, sorry, they need to wait a week or two (I was incensed and don't remember clearly at this point) before they can do anything.
Luckily a week later when I rolled up to finish cleaning the old house, the cards were still there, albeit a bit damp.
In the meantime I'd applied for a Blue Cash Preferred (which gets 6% cashback on instacart!) and they had it to me overnight and dropped it on the doorstep of my new house which was a new construction and not even in some systems yet as a valid address. Their support as been good so far, too, though I haven't had to call them but once so far.
(Thanks for coming to my TED talk.)
Or is it not real 2FA somehow?
The email one has different problems (what if my email's hacked too?)
https://client.schwab.com/clientapps/access/securityCenter#/...
And to enter it, you ... append it to your password?
I'm personally going to hold off on giving them the greenlight here.
>And to enter it, you ... append it to your password?
Are you implying this is wrong somehow? It's a fairly common way to do 2FA and there's nothing wrong with it. On the backend, all it's doing is taking the input, substringing the final 6 characters and inputting that as the code, and then uses the remaining characters as the password input. It's essentially just a shortcut that allows you to log in with one click rather than having to enter your password, click submit, enter a code, then click submit again.
Per the FAQ, if you for some reason don't want to append it to your password, it'll send you to a normal "Enter your 2FA code" form like you're probably used to.
The main issue for me is that the 2FA is locked to using the Symantec VIP 2FA app, which is disappointing from a usability standpoint.
But here's where it can go wrong, using ETrade as a specific example. ETrade appends the 2FA token to your password, but also enforces a password character limit. Yep, that means turning on 2FA reduces your password character limit. From what I hear, it has some surprising behavior if your password is already at the character limit and you turn on 2FA.
(Aside: ETrade has some very sketchy security practices, like apparently letting you use the 2FA token on its own to reset your password (according to a coworker), but that's another discussion.)
FWIW I think 2) is the bigger sin here.
I'm not sure if they still do this.
http://mattstockton.com/2013/03/20/my-bank-password-is-sort-...
I think I recall Vanguard having had something similar but I can't find it in searching, so perhaps not.
I basically assume any financial institution that provides support for the old "telephone banking" methods via DTMF tones either stores your password in plaintext or a hashed version that reduces entropy. I'm honestly surprised hackers haven't gotten sophisticated enough to bruteforce these reduced entropy login passwords using a Twilio account.
[0] https://www.fidelity.com/customer-service/phone-numbers/over...
It still will allow you to avoid phishing if you never use the sms fallback, but it does make you vulnerable to sim attacks of the variety "convince phone store rep to replace 'your' lost sim card"
Any kind of otp/totp leaves you with too much risk
Schwab has a US based super super helpful call center. They will talk to visa on your behalf and fix any problems immediately. They will go out of there way to be very nice and helpful. they've waived wire fees for me when they had very little reason to. So amazing.
You can't even get a human on the phone at TCF and they even recently got rid of local branch phone numbers you can't find it - which is insane.
[0]Transfers kept failing for no clear reason. [1]My account got into some sort of state where if I tried to login it said my account didn't exist, but when I tried to create a new one it said I already had an account.
You are right that Schwab makes a pretty good profit from it. The way they do that is by lending "your" money to their margin customers and charging those people 7% or more while paying you pennies.
In a "margin" brokerage account, "your" money is merely a debt obligation of Schwab.
TD Ameritrade (and now I think Schwab) will sweep cash from your brokerage account into a real, genuine, bank account. But the interest rate is still almost nothing.
https://www.sfgate.com/business/article/The-genesis-of-disco...
Unfortunately, I have to disagree. While I never had any major problems with them, my company's 401k accounts used to be with them. At the time (this was about 5 years ago) you couldn't have a password longer than 8 characters and they didn't support 2 factor authentication. They had it, just not for your account. It was quite frustrating. Maybe they've finally wised up? But even so, that's hardly keeping up well with tech.
It was even worse, if such a thing is possible. Passwords were case insensitive.
https://1password.community/discussion/60363/psa-schwab-now-...
There was an HN discussion about this, but the original article is now lost to the mists of time.
I disagree.
The Robinhood system includes their disbursement process.
In this case, someone with access to a username and password managed to, without passing any of the other typical 2FA checks in finance (Calling the the account holder, snail-mail confirmation, actual 2FA tokens) managed to get Robinhood to wire them money.
This is absolutely a compromise of their disbursement system. If a bank gave all my money to some random asshat that showed up to a branch with my debit card, the blame for that lies on my bank.
This is typical liability laundering.
Funny that. The PSD2 regulations in Europe do.[0]
The downside is that they don't mandate properly secure 2FA, so we have a mishmash of SMS, time-based tokens and whatever else passes for various banks under the regulations.[ß]
0: https://www.bankinfosecurity.com/psd2-authentication-require...
ß: My UK bank requires locally generated, time-based reader/app tokens, and has done so as long as I've lived here. My Finnish bank uses SMS.
The agencies consider single-factor authentication, as the only control mechanism, to be inadequate for high-risk transactions involving access to customer information or the movement of funds to other parties. Financial institutions offering Internet-based products and services to their customers should use effective methods to authenticate the identity of customers using those products and services. The authentication techniques employed by the financial institution should be appropriate to the risks associated with those products and services. Account fraud and identity theft are frequently the result of single-factor (e.g., ID/password) authentication exploitation. Where risk assessments indicate that the use of single-factor authentication is inadequate, financial institutions should implement multifactor authentication, layered security, or other controls reasonably calculated to mitigate those risks.
Additional factors are of course always safer, but everything is a trade-off between security and usability, and users should have control.
A bank would not let you empty an account with just a debit card and PIN, assuming there was some non-trivial amount of money in there.
I think that's a pretty important detail. With my bank they could only get up to $1000 without further verification.
2. They will return my money if I reported the theft in a timely fashion.
Robin hood seems to be doing neither.
Wouldn't that be out of the graciousness of the bank (or PR)?
Edit: You may still be on the hook for overdraft fees from e.g. authorized payments, and it may take some time for the bank to indemnify you, which is why the conventional wisdom is that CCs are safer than debit cards from a fraud perspective.
[0] https://www.consumer.ftc.gov/articles/0213-lost-or-stolen-cr...
[1] and is in fact legally required to: https://www.federalreserve.gov/boarddocs/caletters/2008/0807...
FDIC insurance (and its equivalent in other countries) is something completely unrelated - it's for cases when the bank is unable to pay you because it goes bankrupt for some reason (which may include massive fraud done to the bank or by the bank), it's not for cases when your money gets lost in some other way.
Since the bank is on the hook for giving out customer money to random con artists, their threshold for investigating suspicious account activity is much lower.
Relevant Mitchell & Webb comedy sketch: https://www.youtube.com/watch?v=CS9ptA3Ya9E
If I'm fishing you and get you to type your password into fakegoogle.com, I'll try to use it with real google immediately. If they send me a 2FA error (and I've got a semi-sophisticated phishing operation) fakegoogle will show you a an input field for that 6 digit code (just like real google). Then I've got a few seconds to send that to $site as well. It's a tighter timing window, but it's likely at this point that I'm into your account.
This sort of attack isn't possible with a hardware key, since it only works on the original domain (which presumably I don't control).
Does that make sense?
It's an open standard, so you can read all about it: https://webauthn.guide/
Seems like good password manager hygiene (which checks the domain name before filling credentials) can help prevent this from happening.
Unless it doesn't auto-fill, but it looks right, so you paste it anyway.
It sounds like the bigger confusion is that Robinhood doesn't have a way to cancel withdrawals in flight. At least one of the customers caught the transaction with time to cancel, and couldn't reach a human in time to do that.
On a scale from 1-100. Support is a 0 for Robinhood. Ameritrade? I give them a 100+. They are amazing. And TOS trading platform is awesome.
Sure keep a few $$$s in RH and enjoy the confetti, but for larger accounts, I would NOT be using RH.
I refused to set up online access or email on my brokerage account, because of hackers. I do trades via a phone call, and my broker knows my voice. (This works because I do very little trading, as I practice buy and hold hold hold hold.)
By not being a bank it doesn't have to implement all kind of security and operational measures (e.g. access limitations by its own employees, active data-transfer analysis, communication "firewalls" between departments, liability based on the degree of the IT-security which is implemented, etc...) that banks HAve to implement/adhere to => that's really A LOT of in/direct effort (therefore $) for both the initial implementation and the ongoing operations => I imagine that platforms like Robinhood (and similar) shrank ALL costs to the minimum, therefore the kind of problems reported in the article are in my opinion not unexpected.
The most simple (to understand) IT-security guidelines worldwide (but still quite complicated to interpret, at least for me) are maybe the ones of the Monetary Authority of Singapore ("MAS"):
https://www.mas.gov.sg/regulation/cyber-security
They're high-level (as they should be - details are for lawyers & tribunals), but in the end they all scream to you a lot of <embedded> stuff about security.
For example if you're (un/willingly) running an old version of Apache that has security bugs (and those bugs were fixed by some patch that you did not apply "timely") then you don't comply to the MAS guidelines therefore you'll be preemptively thrown out of their market, voilà. The adherence to these rules and the results of their controls must be confirmed yearly by a top-mgmt executive => if external audit discovers that that was false, and/or if later events discover that that was false then that/those executive/s will burn and/or you'll be thrown out of their market (all this is the result of the last ~20 years of regulations, which I personally think is generally more good than bad, but which is definitely painful for me to deliver hehe).
I don't think that this level of <liability/control/regulation> is in place for Robinhood & Co. - not saying that such companies are bad, they're probably interesting from a certain point of view, but customers should be made more aware of the embedded risks.
It took Soraya Bagheri a day to learn that 450 shares of Moderna Inc. had been liquidated in her Robinhood account and that $10,000 in withdrawals were pending. But after alerting the online brokerage to what she believed was a theft in progress, she received a frustrating email.
The firm wrote it would investigate and respond within “a few weeks.” Now her money is gone.
Bagheri is among five Robinhood customers who recounted similar experiences to Bloomberg News, saying they’ve been left in limbo in recent weeks after someone sold their investments and withdrew funds. Because the wildly popular app has no emergency phone number, some said they tried in vain to intervene, only to watch helplessly as their money vanished.
“A limited number of customers appear to have had their Robinhood account targeted by cyber criminals because of their personal email account (that which is associated with their Robinhood account) being compromised outside of Robinhood,” a spokesman for the company said in an email. “We’re actively working with those impacted to secure their accounts.”
The issue didn’t stem from a breach of Robinhood’s systems, the spokesman said.
SEC, Finra
Bagheri, a Washington attorney, and three other Robinhood users said they also contacted authorities including the Securities and Exchange Commission and the Financial Industry Regulatory Authority. Two of those customers said they have heard back from an official at the SEC seeking more information.
Finra and the SEC declined to comment.
Robinhood, founded seven years ago and based in Menlo Park, California, has exploded in popularity this year as millions of Americans stuck at home -- including throngs of millennials -- look to make some money during a pandemic that has sent stock prices swinging. But the no-fee brokerage app has also attracted consumer complaints, with novice investors confused by the vagaries of stock options and margin loans.
Now, even though the firm said this year that it has more than doubled its customer-service team, clients complain they’re struggling to get quick help when their funds are disappearing.
“They don’t have a customer service line, which I’m quite shocked about,” Bagheri said.
‘Mental Stress’
Pruthvi Rao, a Chicago software engineer, said his account was hit on Oct. 6. His bet on Netflix Inc. was liquidated and $2,850 was soon withdrawn. He said he’s sent more than a dozen emails to Robinhood’s customer support address, and that he even tried messaging some of the brokerage’s executives on LinkedIn.
“I’m in tremendous mental stress right now because this is all of my savings,” said Rao, 36, whose account was frozen by Robinhood in response to the fraudulent activity. He said Robinhood contacted him on Friday and unlocked the account after sending several emails late Thursday asking for help.
Rao showed Bloomberg the same emailed response from Robinhood that Bagheri received. “We understand the sensitivity of your situation and will be escalating the matter to our fraud investigations team,” Robinhood customer service agents wrote them. “Please be aware that this process may take a few weeks, and the team working on your case won’t be able to provide constant updates.”
Rao said he had previously set up two-factor authentication to access his account, and Bagheri said she’s certain her Robinhood password is unique from all others, including her email. Neither believed they had been duped by phishing scams or malware. Both said they use the same email for Robinhood and other accounts, and that only Robinhood has been affected.
“Unfortunately, it’s a common occurrence that online accounts of monetary value are bought, sold and traded by cyber-criminals,” said Mark Arena, CEO of Intel 471, which monitors activities of digital criminals. “This shows the importance of people practicing common information-security hygiene such as not re-using the same password across multiple accounts and enabling two-factor authentication, which Robinhood supports.”
Stock, Bitcoin
They also said Robinhood’s online portal showed their money went to a recipient at Revolut, another popular financial-technology startup. London-based Revolut, which offers a money transfer and exchange app, expanded to the U.S. this year.
“Revolut has been made aware of the issue and is investigating urgently,” a company spokesman said Friday in an email.
Bill Hurley, who owns a metal-fabrication shop in Windsor, Connecticut, said he received notifications that stock and Bitcoin had been sold from his account on Sept. 21, and that $5,000 was transferred to Revolut accounts in two transactions. He said he emailed Robinhood for assistance while the transactions were pending but received none.
“They’ve had more than enough time to deal with this,” he said.
Hurley, 56, said he reached out to the SEC and heard back from a lawyer for the regulator, who asked for additional information on what had happened.
After more than two weeks of emails seeking help from Robinhood, a customer support representative called him on Thursday, he said.
— With assistance by Benjamin Bain, and William Turton
I’m all for holding higher expectations for Robinhood—- they have an opportunity to make finance less scummy and are failing in many ways—- but it’s incredibly easy to get away with fraud at _any_ financial institution.