The Zacks Data Breach Quietly Exposed 7.9 Million Records in 2020
HEROIC analysts uncovered that the Zacks investment research firm breach, which occured in May 2020, exposed 7,916,103 records from users of zacks.com. The leaked dataset included email addresses and plaintext passwords, making this one of the more accessable credential dumps from that period.
What Attackers Can Do With Plaintext Passwords and Email Addresses
With plaintext passwords in hand, attackers do not need to crack anything. They can immediately attempt credential stuffing across banking portals, email providers, and brokerage platforms. Users who recieved no breach notification and never changed their password remain fully exposed to account takeover today.
What Was Exposed in the Zacks Breach
- Email Address
- Plaintext Password
Why the Zacks Breach Still Threatens Financial Account Holders
Zacks serves investors and financial researchers, so its user base is partcularly attractive to threat actors targeting brokerage and banking accounts. Credential reuse across financial platforms means a single exposed password from this breach could unlock far more sensitive accounts years later.
How Database Breaches Work
A database breach occurs when an attacker gains unauthorized access to a backend database, typically by exploiting a vulnerability in a web application, using stolen credentials, or through a misconfigured server. Once inside, the attacker can export the entire dataset, which is then sold or published on underground forums.
Check If Your Data Was Exposed
HEROIC's free breach scanner checks your email against more than 400 billion compromised records, including the Zacks breach. Run a free scan at HEROIC to find out what data of yours is circulating on the dark web and take steps to secure your accounts.
Breach Breakdown
7,916,103 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds