Information Security News mailing list archives

Stock trading app Robinhood says user passwords were readable on internal systems


From: InfoSec News <alerts () infosecnews org>
Date: Fri, 26 Jul 2019 10:30:31 +0000 (UTC)

https://www.cyberscoop.com/robinhood-passwords-internal-system/

By Greg Otto
CYBERSCOOP
July 24, 2019

Stock trading service Robinhood sent an email to users Wednesday informing them that user credentials were stored in an insecure format inside the company’s internal systems.

According to the email obtained by CyberScoop, the problem was discovered Monday night by the company’s security team.

“We resolved this issue, and after thorough review, found no evidence that this information was accessed by anyone outside of our response team,” the email reads.

A Robinhood spokesperson told CyberScoop that the company has no evidence users’ information was accessed, or that the issue meant user information was breached.

[...]

--
Subscribe to InfoSec News
https://www.infosecnews.org/subscribe-to-infosec-news/
https://twitter.com/infosecnews_

Current thread: