Security News > 2023 > June > Have I Been Pwned warns of new Zacks data breach impacting 8 million
Zacks Investment Research has reportedly suffered an older, previously undisclosed data breach impacting 8.8 million customers, with the database now shared on a hacking forum.
Data breach notification service Have I Been Pwned listed an additional Zacks breach this weekend after being sent a database containing 8.8 million user records.
Zacks had previously initiated a password reset procedure for the breach disclosed in January, but it can be assumed that the remaining 90% of breached accounts that weren't identified as such were not included in the measure, leaving them exposed to account hijacking, credential stuffing, and SIM swapping.
While Zacks did not respond to questions from BleepingComputer, Hunt told us that Zacks plans on notifying impacted users, but there is no timeline for when this will be done.
Have I Been Pwned users can now enter their email address on the site and be notified if it was found in the newly leaked Zacks data.
Soon after adding the data breach to Have I Been Pwned, the Zacks database was posted on the Exposed hacking forum, a site used to share and sell stolen data.
News URL
Related news
- Rhode Island confirms data breach after Brain Cipher ransomware attack (source)
- Texas Tech University System data breach impacts 1.4 million patients (source)
- Ireland fines Meta $264 million over 2018 Facebook data breach (source)
- New fake Ledger data breach emails try to steal crypto wallets (source)
- Meta Fined €251 Million for 2018 Data Breach Impacting 29 Million Accounts (source)
- 46% of financial institutions had a data breach in the past 24 months (source)
- UN aviation agency investigating possible data breach (source)
- Washington state sues T-Mobile over 2021 data breach security failures (source)
- Largest US addiction treatment provider notifies patients of data breach (source)
- STIIIZY data breach exposes cannabis buyers’ IDs and purchases (source)