12 million hit in Zacks Investment data breach — how to protect yourself now

An open lock depicting a data breach
(Image credit: Shutterstock)

If you’re a customer of Zacks Investment Research, the financial data, stock research and analysis company, you should probably start investing in the best identity theft protection software while making sure you’re keeping a close eye on your credit reports.

As reported by Bleeping Computer, an underground hacking forum thread from January has been discovered which claims that Zacks has fallen victim to yet another data breach.

This latest breach, the third since 2022, is said to be the largest yet – with the personal information of 12 million people being leaked online.

Names, usernames, email addresses, postal addresses, IP addresses and phone numbers are said to have been stolen in a cyber attack and are now up for sale as a full set for “a small cryptocurrency amount.” However, Have I Been Pwned? points out that 93% of those email addresses had been exposed in previous attacks.

The December 2022 breach similarly exposed names, addresses, phone numbers, email addresses and passwords from 820,000 customers off an older database. Those customers had signed up for a Zacks Elite product between November 1999 and February 2005.

In June 2023 though, there was a second breach where a database of over 8.8 million users showed up on a hacking forum; this breach leaked names, addresses, phone numbers, email addresses, usernames, and passwords up to May 2020.

This latest breach occurred when an attacker gained access by acting as a domain admin, then they stole source code for the main site and 16 additional assets, which included internal websites.

How to stay safe after a data breach

A shocked couple realizing they've been scammed

(Image credit: Shutterstock)

Since data breaches have now become an everyday occurrence, it’s up to you to keep yourself – and your devices – safe.

Start by making sure you’ve got one of the best antivirus software programs running on your PC or one the best Mac antivirus software on your Apple computer. You also want to regularly check that your antivirus is up to date and install new updates as soon as they become available.

While both Windows and Mac come with their own built-in protection, one reason you might want to upgrade to a paid antivirus is that many of them include useful extras like a password manager or VPN for additional protection.

In this case, you're going to want to be on the lookout for suspicious emails and messages. Since all of that personal data from Zacks is available for purchase on the dark web, hackers can use it to create messages tailored specifically to you in targeted phishing attacks. Don't respond, click on any links or download any attachments when you do get one of these messages as that's exactly what the hackers behind them want you to do.

If you’re also concerned about where your personal information has ended up online, consider using a data removal service like Incogni to help scrub your personal details from the web. This will ensure that less info about you is available online overall while an identity theft protection service can keep you safe if someone does track down enough data on you to steal your identity.

While Zacks hasn't officially confirmed this data breach, it's still cause for concern regardless. I wouldn't cancel your account just yet but it might be time to start shopping around for alternatives.

More from Tom's Guide

Amber Bouman
Senior Editor Security

Amber Bouman is the senior security editor at Tom's Guide where she writes about antivirus software, home security, identity theft and more. She has long had an interest in personal security, both online and off, and also has an appreciation for martial arts and edged weapons. With over two decades of experience working in tech journalism, Amber has written for a number of publications including PC World, Maximum PC, Tech Hive, and Engadget covering everything from smartphones to smart breast pumps. 

You must confirm your public display name before commenting

Please logout and then login again, you will then be prompted to enter your display name.

Read more
A picture showing different credit cards stacked on top of each other on a table
5 million Americans just had their credit card details leaked online — what to do now
An open lock depicting a data breach
3.5 million hit in major law firm data breach — full names, SSNs, dates of birth, addresses and more exposed
An open lock depicting a data breach
More than 3.3 million people hit by employee screening data hack — what you need to know
An open lock depicting a data breach
Massive healthcare data breach just exposed the personal info of 1 million Americans — what to do now
Globe Life insurance company logo on a cell phone in front of a monitor display the About page for the company. Shadowy hand holds the phone.
850,000 people exposed in massive insurance data breach — full names, dates of birth and SSNs
Surfshark graphic of 2024 data breaches
Nearly 700 million American records were leaked in 2024
Latest in Online Security
A person on a laptop converting a PDF to a DOC
FBI issues warning over free online file converters that infect your PC with malware
A hacker typing quickly on a keyboard
New MassJacker malware is hijacking digital wallets to steal large sums from users
A woman using her laptop securely with a cup of coffee in hand
5 common mistakes people make when shopping for antivirus software
Windows
240 million Windows 10 users are vulnerable to six different hacker exploits — protect yourself now
Victims of Identity Theft
FTC says Americans lost $12 billion to scams last year and these were the worst ones — here's how to stay safe
Apple iPhone 16 Plus Review.
Apple just released an emergency security update for a flaw used in an ‘extremely sophisticated attack’ — update your devices right now
Latest in News
3D printed model of alleged iPhone 17 Air design
iPhone 17 Air — these 5 big revelations have me excited for the first truly new iPhone in years
NYTimes Connections
NYT Connections today hints and answers — Tuesday, March 18 (#646)
A person on a laptop converting a PDF to a DOC
FBI issues warning over free online file converters that infect your PC with malware
The Find my People feature
Android Find My can now track your friends and family — here's how to use it
Foldable iPhone concept image
Are you sitting down? Here’s what the foldable iPhone could cost
Samsung HW-Q990D soundbar
Samsung’s flagship 2024 soundbar just got bricked by a new firmware update — don’t update