web analytics

Zacks Investment Research Breach Hits 12 Million – Source: www.infosecurity-magazine.com

Rate this post

Source: www.infosecurity-magazine.com – Author:

Written by

Photo of Phil Muncaster

A leading stock research and analysis firm appears to have been breached for the third time in just four years, with details from 12 million accounts published on the dark web.

Published on BreachForums at the end of last month by a user with the moniker “Jurak,” the trove dates from an incident in June 2024, according to breach notification site, HaveIBeenPwned.

“The 2024 breach included 12 million unique email addresses along with IP and physical addresses, names, usernames, phone numbers and unsalted SHA-256 password hashes. Zacks did not respond to multiple attempts to contact them about the incident,” it explained.

The breach also included source code from the company, although “specifics on the repository remain undisclosed,” according to threat intelligence experts Dark Web Informer.

“The threat actor invites interested buyers with high reputation scores to contact them for the source code,” it noted, warning that such a leak could lead to the exploitation of further vulnerabilities in the company’s digital infrastructure.

Read more on data breaches: Data on Half a Million Hotel Guests Exposed After Otelier Breach

Dark Web Informer also warned of the potential for the breach to cause significant reputational damage to the company among clients, alongside possible violations of SEC regulations and data privacy laws.

However, this isn’t the first time that Zacks Investment Research has suffered such an incident. Back in January 2023 it was confirmed that a threat actor compromised data on 820,000 customers between 2021 and 2022.

Then just months after that incident, it was revealed that another breach compromised the email addresses, usernames, unsalted SHA256 passwords, addresses, phone numbers and full names of 8.8 million customers.

HaveIBeenPwned explained in a post on X (formerly Twitter) that 93% of the data in the ‘new’ breach was already in its repository.

New breach: Zacks allegedly had 12M email addresses breached last year in a separate incident to their 2022 breach. Date included name, IP and physical address, phone and unsalted SHA-256 password hash. 93% were already in @haveibeenpwned. Read more: https://t.co/J67RqsI1m2

— Have I Been Pwned (@haveibeenpwned) February 12, 2025

Time to Improve Security Awareness

“With this being Zacks Investment’s potential third major data breach in four years, it highlights the ongoing risks organizations face, particularly from threat actors exploiting weak security practices,” argued Huntress senior manager of security operations, Dray Agha.

“This reinforces the need for robust, continuous security awareness training to help employees recognize phishing and social engineering tactics and better protect sensitive data.”

Jawahar Sivasankaran, president of Cyware, suggested that financial services firms would benefit from joining industry groups like the Financial Services Information Sharing and Analysis Center (ISAC).

“They give financial services organizations new visibility into exploited vulnerabilities, threats the sector faces, data protection best practices, issues on emerging risks such as generative AI, and more efficient and effective threat intelligence management and proactive response strategies,” he added.

Original Post URL: https://www.infosecurity-magazine.com/news/zacks-investment-research-breach/

Category & Tags: –

Views: 2

LinkedIn
Twitter
Facebook
WhatsApp
Email

advisor pick´S post