LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › Zacks (2024) Data Breach (2024)

CRITICAL severityConfirmedHow we verify

Zacks (2024) Data Breach (2024): What Was Exposed & What To Do

RBRecent Breaches Breach Intelligence·June 22, 2024

SourceBreach data provided in part by Have I Been Pwned, used under CC BY 4.0.

Zacks (2024) Data Breach (2024)

Reported June 22, 2024. Approximately 12.0M people affected.

CRITICAL
Severity
12.0M
People affected
7
Data types exposed
June 22, 2024
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

The Zacks (2024) Data Breach (2024) (reported June 22, 2024) exposed Email addresses, IP addresses, Names and Passwords belonging to roughly 12.0M people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.

Severity & verification
CRITICAL severityConfirmed
Account credentials exposed.
Corroborated by an official disclosure or a verified breach feed.
Was your email in the Zacks (2024) Data Breach (2024) breach?
12.0M accounts were exposed here. See if yours is one — and every other breach it’s in. 15-sec check, no card.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

For millions of people who have used Zacks investment research services, the practical stakes of a reported 2024 data incident are immediate and personal. Contact details, account credentials and location information that may have been exposed can be reused for phishing, account takeover attempts or identity-related fraud long after the initial event.

Public reporting places the scale at roughly 12 million people and indicates that the material later appeared on a popular hacking forum. Zacks itself has not publicly confirmed or commented on this specific 2024 incident despite outreach, so affected individuals must treat the available details as claims that still require careful personal verification.

Breaking down the breach

According to reports dated 22 June 2024, the investment research company Zacks was allegedly breached and the resulting data was later published on a popular hacking forum. The material is described as containing 12 million unique email addresses together with IP addresses, physical addresses, names, usernames, phone numbers and unsalted SHA-256 password hashes.

This 2024 disclosure is presented as a separate event that followed a confirmed Zacks breach in 2023; the newer dataset is characterised as a superset that includes millions of additional records. No further public detail has been released about the precise method of intrusion, the exact window of access, or any forensic findings. Multiple attempts to obtain a response from Zacks about the 2024 incident went unanswered, leaving the organisation’s own assessment of the event undisclosed.

How a breach like this happens

Incidents that result in large customer databases appearing on forums typically begin with one of several common entry points: stolen or reused credentials, unpatched remote-access software, compromised third-party vendors, or misconfigured cloud storage. Once inside a network, attackers often move laterally to locate databases or backup files that contain user profiles, then extract them for later sale or free publication.

Password data is frequently taken in hashed form. When the hashes are unsalted, as reported here, offline cracking becomes significantly easier because identical passwords produce identical hash values and can be attacked with pre-computed tables. Publication on a public forum accelerates the risk because anyone can download the file and begin testing the credentials against other services. No specific threat group has been attributed to this incident, and the exact technical path used remains undisclosed.

About Zacks (2024)

Zacks is an established investment research firm that supplies equity research, rankings, newsletters and portfolio tools to individual investors and financial professionals. Organisations of this type routinely maintain accounts that include login credentials, contact information, physical addresses for mailing materials, and usage logs that can include IP addresses.

A breach affecting such a company is consequential because the data combines identity elements with financial-interest signals. Investors who rely on Zacks for research may reuse the same email and password combinations on brokerage or banking sites, raising the possibility of credential-stuffing attacks against higher-value accounts. The firm’s scale—evidenced by the reported 12 million unique email addresses—means any exposure reaches a large retail-investor population.

The information in question

The data types named in public reporting for the 2024 incident are email addresses, IP addresses, names, passwords (specifically unsalted SHA-256 hashes), phone numbers, physical addresses and usernames. These categories match the kinds of records an investment-research platform would normally hold for account management, communication and service delivery.

Exact file contents, field completeness and whether every record contained every data type remain unconfirmed beyond the published claims. Organisations in this sector typically also store subscription preferences, research-viewing history or payment-related identifiers, but no such additional fields have been verified for this particular dataset. Readers should therefore treat only the listed categories as the currently reported exposure.

Why it matters

For individuals, the combination of email, password hash, name, phone number and physical address creates a ready-made package for targeted phishing, SIM-swap attempts or social-engineering calls that reference real personal details. Unsalted SHA-256 hashes can be cracked offline; once a password is recovered it can be tested against other sites where the same credentials were reused. Physical addresses raise the additional possibility of mail-based fraud or physical-world social engineering.

For the organisation, the incident carries reputational and regulatory consequences, especially given the earlier 2023 breach and the lack of public response to the 2024 claims. Customers may lose confidence in the security of research accounts, and any subsequent identity-fraud cases linked to the data could generate further scrutiny. Because the dataset is already described as published, containment is no longer possible; mitigation now rests with the people whose records appear in it.

What to do if you're exposed

If you have ever held a Zacks account or received communications from the firm, treat the reported exposure as a prompt for immediate hygiene rather than waiting for official confirmation. Practical first steps include:

You can also run a free exposure scan of your email address to check whether it has already appeared in known breach datasets. Doing so gives a concrete starting point for deciding which accounts need the most urgent attention.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Method

CompanyZacks (2024) security record
73/100
DoxxScan™ · Moderate doxx risk
C- 64Below-average record

1 reported incident on record.

See Zacks (2024)’s full breach history →

More recent breaches

BitView Data Breach (2024)December 14, 2024Yonéma Data Breach (2024)November 21, 20241win Data Breach (2024)November 2, 2024SuperDraft Data Breach (2024)October 27, 2024

Latest breaches

Read GalaxyWarden’s full analysis of the Zacks (2024) Data Breach (2024) →

Verified breach. Breach data provided in part by Have I Been Pwned, used under CC BY 4.0.

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram