“They are relentless”: A scammer is trying to change the email on my empty Robinhood account. What do they have to gain?
Short answer: more than you think. Even a “zero-balance” brokerage login can be valuable to criminals. If they can switch your email and lock you out, they can mine your identity, monetize your linked bank details, use your account as a money mule, or weaponize features like instant deposits and margin. They can also resell the account access to others. Here’s why your empty account is a target, how attackers try to take it over, and what to do right now.
What attackers can gain from an “empty” brokerage account
– Your identity data: Brokerage accounts typically contain full legal name, address, date of birth, and taxpayer ID details (often the last four digits of your SSN; some tax PDFs may display more). That’s prime fuel for identity theft, loan/credit fraud, new-account openings, and social-engineering attacks.
– Linked bank leverage: If a bank account is already linked, a hijacker may try withdrawals, add new bank destinations, or move stolen funds through your account (money-mule activity). Even failed attempts can trigger headaches like ACH disputes and account holds.
– Instant deposit or margin abuse: If your account has access to instant deposits or margin, an attacker could try to trade on credit, potentially leaving the account with a negative balance and you with the fallout. They can also place trades that benefit positions they hold elsewhere (pump/prop-up illiquid names, options maneuvers).
– Laundering and evasion: Verified, KYC’d brokerage logins are useful to criminals because they’ve already cleared identity checks. That makes them valuable for obfuscating flows of stolen funds and harder for automated systems to flag than a brand-new fraudulent account.
– Resale value: Access to a U.S. brokerage account with identity data is sold on criminal marketplaces. Even if the buyer can’t pull cash immediately, they’ll use it for the reasons above or pair it with other stolen data later.
– Platform abuse and lockout leverage: Changing your email (and phone) lets them silence alerts, add mail filters, and request other sensitive changes while you’re in the dark. Sometimes the first goal is simply to take quiet, durable control now and monetize later.
How they try to pull it off
– Credential stuffing: They test username/password combos from old data breaches. If you reused a password anywhere, you’re at risk.
– Phishing: “Confirm your email change” or “suspicious login” messages that send you to a fake Robinhood page. The goal is to capture your login and 2FA code.
– SIM swapping and SMS interception: If your 2FA is by text, a phone-number takeover lets them receive your codes.
– Account recovery and social engineering: They contact support claiming to be you, say they lost access to the old email/phone, and push to change contacts.
– Malware and session theft: Stealing saved passwords or session cookies from your browser can bypass even good passwords.
What to do now (priority checklist)
1) Do not click links in any “email change” message. Open the Robinhood app or type the site address yourself to verify account settings.
2) Lock down your email first. Your email inbox is the master key to every reset link.
– Turn on strong 2FA (preferably an authenticator app or security key, not SMS).
– Change to a long, unique password (use a password manager).
– Check for suspicious forwarding rules/filters and remove any you didn’t create.
3) Secure your Robinhood login.
– Change the password to a unique one you’ve never used elsewhere.
– Enable 2FA with an authenticator app or security key; avoid SMS if possible.
– Review active devices/sessions and log out of all others.
– Verify contact info (email/phone) is yours; add a PIN or extra verification if offered.
4) Reduce the blast radius.
– Remove any bank accounts you don’t need linked.
– If you won’t use the account, consider formally closing it with support.
– Turn on every available account alert (logins, transfers, changes).
5) Hardening outside Robinhood.
– Set a number-port freeze/port-out PIN with your mobile carrier to deter SIM swaps.
– Freeze your credit with Equifax, Experian, TransUnion, and ChexSystems (for bank-account openings).
– If your SSN may have been exposed previously, get an IRS IP PIN to block tax-refund fraud.
– Check if your email/passwords appear in known breaches (e.g., haveibeenpwned) and rotate any reused credentials.
6) Contact support through the official app or site.
– Report the takeover attempts, confirm no changes were made, and ask them to note your account for heightened verification.
– Document everything. If you see unauthorized activity or identity misuse, file a report at IdentityTheft.gov and with your bank.
How to recognize the “relentless” attempts as phishing
– The sender domain is slightly off (e.g., roblnhood.com). The message urges urgent clicks or asks for your 2FA code.
– Links don’t go to the official domain. Hover to inspect, or better, don’t click at all—go directly to the official app/site.
– Unexpected attachments, requests for your full SSN, or “refunds” you didn’t request are red flags.
Bottom line
Your empty account isn’t empty to a thief. The identity details, bank links, trading features, and resale value make it worth repeated attempts to hijack. If attackers are trying to change your email, treat it as an account-takeover attempt in progress. Lock down your email, enable strong 2FA, rotate your passwords, restrict or close the account if you don’t need it, and set carrier and credit freezes. Quick, layered defenses will turn “relentless” into “unsuccessful.”
