attack roughly I believe is along the lines of the following:
attacker registers email under your email with a . Or similar which many emails (e.g. gmail forward seamlessly to you)
they log in with injected html to user agent header to send a fake message as seen in image (notice how it’s after the device)
impossible to report to support, on hold for 30+ mins
@RobinhoodApp@AskRobinhood your domain is compromised and being used to send phishing emails. support bot immediately closes and blocks conversation if you mention “phishing” or anything similar. explanation below