Callback Phishing Campaign Impersonates Robinhood With Fake Sign-In Alerts (LevelBlue SpiderLabs)

Callback Phishing Campaign Impersonates Robinhood With Fake (TL-2026-1171), also tracked as Robinhood Fake Sign-In Alert Callback Scam, is a high-severity phishing campaign, first published 2026-07-10. It has no confirmed attribution, affects Robinhood Markets, Inc. Robinhood brand (impersonated in phishing, maps to 12 MITRE ATT&CK techniques (T1056.002, T1078, T1111), and is covered by 9 detection rules and 16 indicators of compromise.

Key facts for TL-2026-1171

Threat ID
TL-2026-1171
Also known as
Robinhood Fake Sign-In Alert Callback Scam, Robinhood TOAD Campaign
Severity
HIGH
Status
ACTIVE
Category
PHISHING
First published
2026-07-10
Last reviewed
2026-07-10
Attribution confidence
LOW
Motivation
FINANCIAL
Target sectors
financial services, retail investment brokerage, consumer individual investors
Target regions
united states of america
Detection rules
9
Indicators of compromise
16

LevelBlue SpiderLabs identified an active callback-phishing (TOAD) campaign impersonating Robinhood security sign-in alerts, pressuring recipients to call one of 14 attacker-controlled toll-free numbers where operators pose as Robinhood support to harvest credentials and one-time codes, request remote-access software installation, or push through unauthorized transactions.

How Callback Phishing Campaign Impersonates Robinhood With Fake works

This campaign follows the Telephone-Oriented Attack Delivery (TOAD) / callback-phishing pattern first popularized by BazarCall in 2020 and since adopted by groups including Silent Ransom Group (Luna Moth) and 3AM ransomware operators. Victims receive a message spoofing a Robinhood security notification claiming an unrecognized sign-in, but instead of a malicious link or attachment, the message directs the recipient to call one of 14 toll-free (877/888) numbers. This design deliberately evades automated email defenses: URL scanners have nothing to scan and sandboxes have no attachment to detonate, shifting the entire attack into a voice channel with far less security visibility. Once the victim calls, an attacker-controlled operator impersonates Robinhood support/security staff and applies urgency and authority pressure ("protecting your account") to extract login credentials, harvest one-time passcodes/MFA approvals, socially engineer the victim into installing remote-access software, or talk the victim through approving fraudulent transactions or withdrawals in real time. LevelBlue SpiderLabs, the same research team that has separately tracked a related callback-phishing campaign abusing Microsoft Azure Monitor alert notifications with fake invoice/unauthorized-payment lures, surfaced this Robinhood-themed wave in early July 2026. The campaign lands amid a broader wave of Robinhood-brand phishing activity in 2026, including an unrelated April 2026 incident in which a Robinhood account-creation flaw was abused to send phishing emails from noreply@robinhood.com (patched April 28, 2026) and ongoing 'fake security alert' scam reports tracked by Malwarebytes throughout 2025-2026 — underscoring Robinhood as a persistently attractive impersonation target for financially motivated social engineers because its users hold liquid, transferable brokerage and crypto assets.

MITRE ATT&CK techniques used in TL-2026-1171

Collection

T1056.002 GUI Input Capture

Initial Access

T1078 Valid Accounts; T1566.004 Spearphishing Voice

Persistence

T1078 Valid Accounts

Privilege Escalation

T1078 Valid Accounts

Defense Evasion

T1078 Valid Accounts

Credential Access

T1111 Multi-Factor Authentication Interception

Execution

T1204 User Execution; T1204.002 Malicious File

Command and Control

T1219 Remote Access Tools

Resource Development

T1583 Acquire Infrastructure; T1585.002 Email Accounts

Reconnaissance

T1598.004 Spearphishing Voice

Impact

T1657 Financial Theft

stealth

T1684.001 Impersonation

Affected products and versions in Callback Phishing Campaign Impersonates Robinhood With Fake

  • Robinhood Markets, Inc. — Robinhood brand (impersonated in phishing lures; no product vulnerability)
    Vulnerable versions: N/A - brand impersonation, not a software flaw
    Fixed in: N/A

Remediation for Callback Phishing Campaign Impersonates Robinhood With Fake

Immediate actions

  • Block/flag the 14 confirmed attacker-controlled phone numbers in telephony/UCaaS abuse filters and security-awareness alerts
  • Add detection rules for inbound email/SMS containing Robinhood brand references plus an embedded phone number and no links or attachments
  • Instruct users never to call phone numbers embedded in unsolicited 'security alert' messages; verify only via the official Robinhood app or robinhood.com
  • Review recent Robinhood account activity and disable/rotate credentials for any user who called one of the listed numbers

Workarounds

  • Independently contact Robinhood support via the verified in-app channel or the number printed on official Robinhood correspondence rather than any number in the alert itself

Longer-term hardening

  • Deploy behavioral email analytics tuned to detect link-less, attachment-less urgency-lure messages (a hallmark of TOAD/callback phishing)
  • Establish organization-wide 'Designated Verification Numbers' and pre-shared code words for validating any inbound support/security call
  • Expand security-awareness training to include voice-channel social engineering scenarios, not just email-link phishing
  • Deploy phishing-resistant MFA (FIDO2/passkeys) to reduce the value of harvested OTPs/passwords

Timeline of Callback Phishing Campaign Impersonates Robinhood With Fake

  • Callback-phishing (TOAD) technique pioneered at scale by the BazarCall campaign, delivering the BazarLoader/BazarBackdoor malware via attacker-controlled call centers.
  • Ryuk-affiliated operators adopt callback phishing as an initial-access vector, guiding victims to install remote access tools such as AnyDesk or TeamViewer before deploying ransomware.
  • Royal ransomware operators refine callback phishing, substituting phone-number-driven lures for traditional malicious payloads to reach victims via voice social engineering.
  • Conti ransomware group dissolves; its callback-phishing playbook and operator tradecraft are inherited by successor/splinter groups including Quantum and Royal.
  • Malwarebytes reports continued waves of fake Robinhood security-alert scams targeting users.
  • A separate Robinhood account-creation flaw abused to send phishing emails from noreply@robinhood.com is patched by Robinhood; the associated phishing domain goes offline (unrelated infrastructure to this callback campaign).
  • Trend Micro publishes analysis on the ongoing Robinhood impersonation scam trend.
  • LevelBlue SpiderLabs publicly reports a related callback-phishing campaign abusing Microsoft Azure Monitor alert notifications with fake invoice/unauthorized-payment lures, demonstrating the same operator tradecraft pattern.
  • Cyber Security News and Fox News publish public coverage warning Robinhood users not to call numbers in unsolicited sign-in alert messages.
  • LevelBlue SpiderLabs identifies and reports the Robinhood-themed callback-phishing campaign, cataloguing 14 attacker-controlled callback numbers.
  • Cyber Security News publishes its full write-up quoting LevelBlue SpiderLabs on the observed increase in Robinhood-themed callback phishing activity.

Sources cited for Callback Phishing Campaign Impersonates Robinhood With Fake

Threats related to Callback Phishing Campaign Impersonates Robinhood With Fake

Detection coverage for TL-2026-1171

As of 2026-07-10, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1171 across Splunk SPL, Microsoft KQL and Sigma, covering 16 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats