Zacks Investment hit in data breach - 12 million users potentially at risk

A computer being guarded by cybersecurity.
(Image credit: iStock)

  • A hacker posted a new thread on an underground forum
  • They claim to have stolen data on 12 million people from Zacks Investment Research
  • Zacks hasn't responded to media inquiries yet

Zacks Investment Research, a financial data, stock research, and analysis company based in Chicago, apparently suffered a cyberattack in which it lost sensitive data on millions of people.

A report by BleepingComputer cites a thread posted on an underground hacking forum claiming to have breached Zacks in June 2024, gaining sensitive information on 12 million people, including names, usernames, email addresses, postal addresses, and phone numbers.

The forum thread contained a small sample, and an offer for the entire batch in exchange for a “small cryptocurrency amount”.

Exposing the emails

Speaking to the attacker, the publication found that the attacker gained access to Zacks’ active directory as a domain admin, after which they stole the source code for the main site and 16 other assets. Zacks hasn’t responded to media inquiries yet.

At the same time, Have I Been Pwned?, a website aggregating email addresses exposed in data breaches, added the new batch, but said almost all (93%) were exposed in previous attacks.

Zacks is yet to comment on the claims of a data breach. However, it is no stranger to cyber-incidents. In December 2022, the company identified unauthorized access to certain customer records. The breach affected approximately 820,000 customers who had signed up for the Zacks Elite product between November 1999 and February 2005. Exposed information included names, addresses, phone numbers, email addresses, and passwords from an older database.

In June 2023, a database containing personal information of over 8.8 million Zacks users emerged on a hacking forum. The data, dated up to May 2020, included names, addresses, phone numbers, email addresses, usernames, and passwords stored as unsalted SHA-256 hashes.

Via BleepingComputer

You might also like

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

You must confirm your public display name before commenting

Please logout and then login again, you will then be prompted to enter your display name.

Read more
Someone holding a passport with two boarding passes inside it
Top digital loan firm security slip-up puts data of 36 million users at risk
A digital themed isometric showing a neon padlock in the foreground, and a technological diagram of a processor logic board in the background.
Major breach hits employee screening firm - 3.3 million affected as hackers steal DISA data
A man looking at a tablet with a brown Best Buy package on the desk in front of him
Huge Christmas data breach - 14 million shipping records leaked, putting shoppers at risk
Security
American National Insurance Company breach data found online
ID theft
Over a million patients potentially hit after another US healthcare provider hit by cyberattack
Security padlock and circuit board to protect data
Foh&Boh data leak leaves millions of CVs exposed - KFS, Taco Bell, Nordstrom applicants at risk
Latest in Security
A graphic showing someone on a tablet working through a supply chain.
Security issue in open source software leaves businesses concerned for systems
ransomware avast
One of the most powerful ransomware hacks around has been cracked using some serious GPU power
person at a computer
Infamous ransomware hackers reveal new tool to brute-force VPNs
person at a computer
Many workers are overconfident at spotting phishing attacks
A fish hook is lying across a computer keyboard, representing a phishing attack on a computer system
Microsoft 365 accounts are under attack from new malware spoofing popular work apps
Data Breach
Thousands of healthcare records exposed online, including private patient information
Latest in News
Metroid Prime 4
I reckon the Nintendo Switch 2 could launch with Metroid Prime 4 – here’s why
Pebble smartwatch countdown
Pebble confirms its smartwatch announcement is just hours away
Logo of YouTube Shorts
Is YouTube auto-playing Shorts when you open the app? Well, you’re not alone - here’s how to fix it
Google DeepMind panel discussion
“More sovereignty and protection” - Google goes all-in on UK AI with data residency, upskilling projects, and startup investments
Nintendo Switch 2
Nintendo Switch 2 expected to have AI upscaling and I can't wait to finally play Tears of the Kingdom with upgraded graphics
PowerColor Red Devil AMD RX 9070 XT graphics card shown side-on
Your next GPU could be from AMD, not Nvidia, if Team Red’s success with PC gamers continues