Monday, April 28, 2025
HomeCyber Security NewsZacks Investment Data Breach Exposes 12 Million Emails and Phone Numbers

Zacks Investment Data Breach Exposes 12 Million Emails and Phone Numbers

Published on

SIEM as a Service

Follow Us on Google News

A cybersecurity incident at Zacks Investment Research has exposed sensitive data belonging to 12 million users, marking the second major breach for the financial services firm since 2022.

The compromised information includes email addresses, phone numbers, names, IP addresses, physical addresses, and weakly protected password hashes, raising concerns about identity theft and credential-stuffing attacks.

Breach Scope and Compromised Data

The breach – Posted by a cybersecurity Firm, Have I Been Pwned in X Platform.

- Advertisement - Google News

Attackers accessed unsalted SHA-256 password hashes, a cryptographic method experts consider inadequate for modern security standards.

Unlike salted hashes, which add random data to passwords before encryption, unsalted hashes enable attackers to use precomputed “rainbow tables” to crack credentials efficiently through brute-force methods.

Physical addresses and IP addresses were also leaked, creating compound risks for victims.

As Hunt noted: “The combination of residential addresses and device identifiers could facilitate highly targeted phishing campaigns or physical security threats”.

Notably, 93% of affected email addresses already appeared in prior breach databases, indicating many users failed to update credentials after previous incidents.

Zacks’ Response and Historical Context

Zacks has not yet released an official breach notification, though independent analysts have verified the dataset’s authenticity through cross-referencing with known customer records.

This incident follows a 2022 breach where hackers compromised 820,000 accounts, suggesting systemic vulnerabilities in the company’s data protection frameworks.

The repetition of similar attack vectors – particularly the continued use of outdated hashing protocols – has drawn criticism from cybersecurity professionals.

John Opdenakker, a penetration tester, stated: “Financial institutions handling sensitive investor data have no excuse for using unsalted hashes in 2024. This represents a fundamental failure in implementing basic security hygiene”.

Risks to Affected Users

Victims face multifaceted threats:

  1. Credential-Stuffing Attacks: Cybercriminals often test leaked email/password combinations across banking platforms and investment services
  2. Sextortion Scams: Leaked phone numbers and physical addresses enable personalized extortion attempts
  3. Identity Theft: Complete personal profiles allow fraudsters to bypass know-your-customer (KYC) checks at financial institutions

The breach may trigger investigations under the FTC’s Safeguards Rule, which mandates rigorous data protection standards for financial institutions.

Potential fines could reach $50,120 per violation under updated FTC penalty guidelines.

As digital transformation accelerates across financial services, this breach underscores the critical need for proactive cybersecurity investments.

Until companies prioritize modern encryption and real-time threat monitoring, consumers remain vulnerable to evolving attack methodologies.

Investigate Real-World Malicious Links & Phishing Attacks With Threat Intelligence Lookup - Try for Free

Divya
Divya
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Latest articles

RansomHub Ransomware Deploys Malware to Breach Corporate Networks

The eSentire’s Threat Response Unit (TRU) in early March 2025, a sophisticated cyberattack leveraging...

19 APT Hackers Target Asia-based Company Servers Using Exploited Vulnerabilities and Spear Phishing Email

The NSFOCUS Fuying Laboratory’s global threat hunting system identified 19 sophisticated Advanced Persistent Threat...

FBI Reports ₹1.38 Lakh Crore Loss in 2024, a 33% Surge from 2023

The FBI’s Internet Crime Complaint Center (IC3) has reported a record-breaking loss of $16.6...

Fog Ransomware Reveals Active Directory Exploitation Tools and Scripts

Cybersecurity researchers from The DFIR Report’s Threat Intel Group uncovered an open directory hosted...

Resilience at Scale

Why Application Security is Non-Negotiable

The resilience of your digital infrastructure directly impacts your ability to scale. And yet, application security remains a critical weak link for most organizations.

Application Security is no longer just a defensive play—it’s the cornerstone of cyber resilience and sustainable growth. In this webinar, Karthik Krishnamoorthy (CTO of Indusface) and Phani Deepak Akella (VP of Marketing – Indusface), will share how AI-powered application security can help organizations build resilience by

Discussion points


Protecting at internet scale using AI and behavioral-based DDoS & bot mitigation.
Autonomously discovering external assets and remediating vulnerabilities within 72 hours, enabling secure, confident scaling.
Ensuring 100% application availability through platforms architected for failure resilience.
Eliminating silos with real-time correlation between attack surface and active threats for rapid, accurate mitigation

More like this

RansomHub Ransomware Deploys Malware to Breach Corporate Networks

The eSentire’s Threat Response Unit (TRU) in early March 2025, a sophisticated cyberattack leveraging...

19 APT Hackers Target Asia-based Company Servers Using Exploited Vulnerabilities and Spear Phishing Email

The NSFOCUS Fuying Laboratory’s global threat hunting system identified 19 sophisticated Advanced Persistent Threat...

FBI Reports ₹1.38 Lakh Crore Loss in 2024, a 33% Surge from 2023

The FBI’s Internet Crime Complaint Center (IC3) has reported a record-breaking loss of $16.6...