Security News > 2023 > June > Have I Been Pwned warns of new Zacks data breach impacting 8 million

Zacks Investment Research has reportedly suffered an older, previously undisclosed data breach impacting 8.8 million customers, with the database now shared on a hacking forum.
Data breach notification service Have I Been Pwned listed an additional Zacks breach this weekend after being sent a database containing 8.8 million user records.
Zacks had previously initiated a password reset procedure for the breach disclosed in January, but it can be assumed that the remaining 90% of breached accounts that weren't identified as such were not included in the measure, leaving them exposed to account hijacking, credential stuffing, and SIM swapping.
While Zacks did not respond to questions from BleepingComputer, Hunt told us that Zacks plans on notifying impacted users, but there is no timeline for when this will be done.
Have I Been Pwned users can now enter their email address on the site and be notified if it was found in the newly leaked Zacks data.
Soon after adding the data breach to Have I Been Pwned, the Zacks database was posted on the Exposed hacking forum, a site used to share and sell stolen data.
News URL
Related news
- Wolf Haldenstein law firm says 3.5 million impacted by data breach (source)
- Otelier data breach exposes info, hotel reservations of millions (source)
- PayPal to pay $2 million settlement over 2022 data breach (source)
- UnitedHealth now says 190 million impacted by 2024 data breach (source)
- PowerSchool starts notifying victims of massive data breach (source)
- US healthcare provider data breach impacts 1 million patients (source)
- US healthcare provider data breach impacts 1 million patients (source)
- Globe Life data breach may impact an additional 850,000 clients (source)
- GrubHub data breach impacts customers, drivers, and merchants (source)
- HPE notifies employees of data breach after Russian Office 365 hack (source)