Callback Phishing Campaign Impersonates Robinhood With Fake Sign-In Alerts (LevelBlue SpiderLabs)
Callback Phishing Campaign Impersonates Robinhood With Fake (TL-2026-1171), also tracked as Robinhood Fake Sign-In Alert Callback Scam, is a high-severity phishing campaign, first published 2026-07-10. It has no confirmed attribution, affects Robinhood Markets, Inc. Robinhood brand (impersonated in phishing, maps to 12 MITRE ATT&CK techniques (T1056.002, T1078, T1111), and is covered by 9 detection rules and 16 indicators of compromise.
Key facts for TL-2026-1171
- Threat ID
- TL-2026-1171
- Also known as
- Robinhood Fake Sign-In Alert Callback Scam, Robinhood TOAD Campaign
- Severity
- HIGH
- Status
- ACTIVE
- Category
- PHISHING
- First published
- 2026-07-10
- Last reviewed
- 2026-07-10
- Attribution confidence
- LOW
- Motivation
- FINANCIAL
- Target sectors
- financial services, retail investment brokerage, consumer individual investors
- Target regions
- united states of america
- Detection rules
- 9
- Indicators of compromise
- 16
LevelBlue SpiderLabs identified an active callback-phishing (TOAD) campaign impersonating Robinhood security sign-in alerts, pressuring recipients to call one of 14 attacker-controlled toll-free numbers where operators pose as Robinhood support to harvest credentials and one-time codes, request remote-access software installation, or push through unauthorized transactions.
How Callback Phishing Campaign Impersonates Robinhood With Fake works
This campaign follows the Telephone-Oriented Attack Delivery (TOAD) / callback-phishing pattern first popularized by BazarCall in 2020 and since adopted by groups including Silent Ransom Group (Luna Moth) and 3AM ransomware operators. Victims receive a message spoofing a Robinhood security notification claiming an unrecognized sign-in, but instead of a malicious link or attachment, the message directs the recipient to call one of 14 toll-free (877/888) numbers. This design deliberately evades automated email defenses: URL scanners have nothing to scan and sandboxes have no attachment to detonate, shifting the entire attack into a voice channel with far less security visibility. Once the victim calls, an attacker-controlled operator impersonates Robinhood support/security staff and applies urgency and authority pressure ("protecting your account") to extract login credentials, harvest one-time passcodes/MFA approvals, socially engineer the victim into installing remote-access software, or talk the victim through approving fraudulent transactions or withdrawals in real time. LevelBlue SpiderLabs, the same research team that has separately tracked a related callback-phishing campaign abusing Microsoft Azure Monitor alert notifications with fake invoice/unauthorized-payment lures, surfaced this Robinhood-themed wave in early July 2026. The campaign lands amid a broader wave of Robinhood-brand phishing activity in 2026, including an unrelated April 2026 incident in which a Robinhood account-creation flaw was abused to send phishing emails from noreply@robinhood.com (patched April 28, 2026) and ongoing 'fake security alert' scam reports tracked by Malwarebytes throughout 2025-2026 — underscoring Robinhood as a persistently attractive impersonation target for financially motivated social engineers because its users hold liquid, transferable brokerage and crypto assets.
MITRE ATT&CK techniques used in TL-2026-1171
Collection
Initial Access
T1078 Valid Accounts; T1566.004 Spearphishing Voice
Persistence
Privilege Escalation
Defense Evasion
Credential Access
T1111 Multi-Factor Authentication Interception
Execution
T1204 User Execution; T1204.002 Malicious File
Command and Control
Resource Development
T1583 Acquire Infrastructure; T1585.002 Email Accounts
Reconnaissance
Impact
stealth
Affected products and versions in Callback Phishing Campaign Impersonates Robinhood With Fake
- Robinhood Markets, Inc. — Robinhood brand (impersonated in phishing lures; no product vulnerability)
Vulnerable versions: N/A - brand impersonation, not a software flaw
Fixed in: N/A
Remediation for Callback Phishing Campaign Impersonates Robinhood With Fake
Immediate actions
- Block/flag the 14 confirmed attacker-controlled phone numbers in telephony/UCaaS abuse filters and security-awareness alerts
- Add detection rules for inbound email/SMS containing Robinhood brand references plus an embedded phone number and no links or attachments
- Instruct users never to call phone numbers embedded in unsolicited 'security alert' messages; verify only via the official Robinhood app or robinhood.com
- Review recent Robinhood account activity and disable/rotate credentials for any user who called one of the listed numbers
Workarounds
- Independently contact Robinhood support via the verified in-app channel or the number printed on official Robinhood correspondence rather than any number in the alert itself
Longer-term hardening
- Deploy behavioral email analytics tuned to detect link-less, attachment-less urgency-lure messages (a hallmark of TOAD/callback phishing)
- Establish organization-wide 'Designated Verification Numbers' and pre-shared code words for validating any inbound support/security call
- Expand security-awareness training to include voice-channel social engineering scenarios, not just email-link phishing
- Deploy phishing-resistant MFA (FIDO2/passkeys) to reduce the value of harvested OTPs/passwords
Timeline of Callback Phishing Campaign Impersonates Robinhood With Fake
- Callback-phishing (TOAD) technique pioneered at scale by the BazarCall campaign, delivering the BazarLoader/BazarBackdoor malware via attacker-controlled call centers.
- Ryuk-affiliated operators adopt callback phishing as an initial-access vector, guiding victims to install remote access tools such as AnyDesk or TeamViewer before deploying ransomware.
- Royal ransomware operators refine callback phishing, substituting phone-number-driven lures for traditional malicious payloads to reach victims via voice social engineering.
- Conti ransomware group dissolves; its callback-phishing playbook and operator tradecraft are inherited by successor/splinter groups including Quantum and Royal.
- Malwarebytes reports continued waves of fake Robinhood security-alert scams targeting users.
- A separate Robinhood account-creation flaw abused to send phishing emails from noreply@robinhood.com is patched by Robinhood; the associated phishing domain goes offline (unrelated infrastructure to this callback campaign).
- Trend Micro publishes analysis on the ongoing Robinhood impersonation scam trend.
- LevelBlue SpiderLabs publicly reports a related callback-phishing campaign abusing Microsoft Azure Monitor alert notifications with fake invoice/unauthorized-payment lures, demonstrating the same operator tradecraft pattern.
- Cyber Security News and Fox News publish public coverage warning Robinhood users not to call numbers in unsolicited sign-in alert messages.
- LevelBlue SpiderLabs identifies and reports the Robinhood-themed callback-phishing campaign, cataloguing 14 attacker-controlled callback numbers.
- Cyber Security News publishes its full write-up quoting LevelBlue SpiderLabs on the observed increase in Robinhood-themed callback phishing activity.
Sources cited for Callback Phishing Campaign Impersonates Robinhood With Fake
- Hackers Impersonate Robinhood With Fake Sign-in Alerts
- Robinhood scam text warning: fake security alert targets users nationwide
- The Robinhood impersonation scam that we should all pay attention to
- Scammers are still sending us their fake Robinhood security alerts
- Robinhood Vulnerability Exploited for Phishing Attacks
- Callback Phishing Via Microsoft Azure Monitor Alert Notifications
- What Is Callback Phishing and How Does It Work?
- What is Callback Phishing (TOAD)?
Threats related to Callback Phishing Campaign Impersonates Robinhood With Fake
- AI-Accelerated Phone Scam (Vishing/TOAD) Campaigns Impersonating Amazon, Microsoft, PayPal, Norton, GitHub, Canva, Geek Squad, Temu, Target and the FTC
- ShipMonk Fulfillment Partner Breach Exposes Data of 13,689 Trezor Customers
- Malwarebytes: Scammers Increasingly Match Scam Type to Platform, Targeting Victims by Channel and Time
- AnonyMousKIT: AI-Enabled Phishing-as-a-Service Platform Automates Apple Activation Lock Bypass
- Malwarebytes Subscription Renewal Scam — Fake-Invoice / Refund-Bait Callback Phishing Campaign ("Account Maintenance Update")
- Microsoft Teams Phishing: Attackers Impersonate IT Helpdesk for Initial Access
Detection coverage for TL-2026-1171
As of 2026-07-10, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1171 across Splunk SPL, Microsoft KQL and Sigma, covering 16 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.