- A hacker posted a new thread on an underground forum
- They claim to have stolen data about 12 million people from Zacks Investment Research
- Zacks have not yet responded to media queries
Zacks Investment Research, a financial data, stock survey and analysis company based in Chicago apparently suffered a cyberattack where it lost sensitive data on millions of people.
A report from Bleeping computer Quotes a thread sent on an underground hacking forum that claims to have violated zacks in June 2024, and get sensitive information about 12 million people, including names, usernames, E email addresses, postal addresses and telephone numbers.
The forum wire contained a small sample and an offer for the whole batch in exchange for a “small cryptocurrency amount”.
Postpon E emails
In a speech with the striker, the publication found that the striker gained access to Zacks’ Active Directory as a domain administrator, after which they stole the source code for the main place and 16 other assets. Zacks have not yet responded to media queries.
Have I been pwned at the same time, a site that collected E -email addresses postponed in data violations, the new batch added, but said that almost everyone (93%) was postponed in previous attacks.
Zacks does not yet comment on the requirements of a data violation. However, it is no stranger to cyber-incidents. In December 2022, the company identified unauthorized access to certain customer items. The violation affected approximately 820,000 customers who had signed up for the Zacks Elite product between November 1999 and February 2005. Exposed information included names, addresses, telephone numbers, e -mail addresses and passwords from an older database.
In June 2023, a database containing personal information appeared over 8.8 million zacks users on a hacking forum. The data, dated until May 2020, included names, addresses, phone numbers, email addresses, usernames and passwords stored as unsalted SHA-256 hash.
Via Bleeping computer