In late January 2025, a hacker using the name Jurak posted on a cybercrime forum that Zacks Investment Research, a US stock research company, had been breached in June 2024, and offered data on millions of its customers. On 13 February 2025, Have I Been Pwned (HIBP) added the leaked database after verifying it: 12 million unique email addresses with names, usernames, phone numbers, physical addresses, IP addresses and unsalted SHA-256 password hashes. HIBP noted that about 93% of the email addresses were already in its database. Jurak told BleepingComputer they had reached Zacks' Active Directory as a domain administrator and stolen source code for Zacks.com and 16 other sites. Zacks has not confirmed the breach or responded to press questions. If genuine, it would be the company's third major data breach in about four years.
Key takeaways
- A hacker called Jurak claimed a June 2024 breach of Zacks and leaked customer data in late January 2025; Zacks has not confirmed it.
- Have I Been Pwned verified 12 million unique email addresses with names, addresses, phone numbers and unsalted SHA-256 password hashes.
- Jurak claimed domain admin access to Zacks' Active Directory and theft of source code for 17 websites; these claims are unconfirmed.
- Zacks previously disclosed a breach affecting 820,000 customers in 2023, and HIBP validated an 8.8 million record database the same year, according to BleepingComputer.
- The identity lesson: weak password storage and, if the claim is true, a compromised domain admin account turn one intrusion into exposure of every customer account.
At a glance
| Organisation | Zacks Investment Research |
|---|---|
| When | Breach claimed to have occurred in June 2024; data leaked late January 2025; added to Have I Been Pwned 13 February 2025 |
| Attacker | Jurak, with a second hacker named StableFish, according to the forum post (claimed) |
| Entry point | Not disclosed; the attacker claims domain admin access to Zacks' Active Directory |
| Identities abused | Claimed domain admin access; customer account credentials stored as unsalted SHA-256 hashes |
| Impact | 12 million unique email addresses and related customer data leaked, verified by HIBP; source code theft claimed; Zacks has not confirmed |
| Category | Human identity (not listed as an NHI or AI agent breach). Incident class: claimed customer data breach |
What happened
According to Malwarebytes, Jurak's forum post read: "In June 2024, Zacks Investment Research suffered a data breach exposing their source code and their databases containing 15M lines of their customers and clients." The post named "@Jurak and @StableFish" as responsible and included a sample of customer records with password, username and customer ID fields. The data was available to forum members for a small cryptocurrency payment, BleepingComputer reported.
Jurak told BleepingComputer that "they gained access to the company's active directory as a domain admin and then stole source code for the main site (Zacks.com) and 16 other websites, including some internal websites," and shared source code samples as proof. BleepingComputer contacted Zacks several times without a response. Zacks has not confirmed the breach.
On 13 February 2025, Have I Been Pwned added the database. It confirmed "12 million unique email addresses, along with IP addresses, names, passwords in the form of unsalted SHA-256 hashes, phone numbers, physical addresses, and usernames," and noted that roughly 93% of the addresses were already in its database from earlier breaches. BleepingComputer said HIBP had verified the data with "a very high degree of confidence that it comes from a new incident," while cautioning that scraped or compiled data could not be fully ruled out. The company had previously disclosed, in January 2023, that attackers accessed data on 820,000 customers between November 2021 and August 2022.
Timeline
| Date | Event |
|---|---|
| June 2024 | The breach is claimed to have taken place, according to the attacker. |
| January 2025 | Jurak publishes samples and offers the data on a hacking forum. |
| 13 February 2025 | Have I Been Pwned adds 12 million email addresses from the leak. |
How it happened: the identity attack path
- Initial access. Not disclosed; Zacks has not described any intrusion.
- Domain admin claimed. The attacker says they gained domain admin rights in Zacks' Active Directory.
- Data and code theft claimed. The attacker says they took customer databases and source code for 17 websites.
- Leak. Customer data was published and sold on a hacking forum, then verified by HIBP.
Impact
- Verified by HIBP: 12 million unique email addresses with names, addresses, phone numbers, usernames, IP addresses and unsalted SHA-256 password hashes.
- Claimed, unconfirmed: domain admin access and source code theft for Zacks.com and 16 other sites.
- Customer risk: unsalted SHA-256 hashes are fast to crack, raising the risk of password reuse attacks.
What this means for NHI governance
This is a customer data breach, and the verified facts concern human accounts, so it is flagged as a human-identity breach on our hub. It is included because of what the attacker claims: domain admin access to Active Directory. Domain admin is the most privileged identity in a Windows estate, and it is often held by service accounts and automation as well as people. If the claim is true, one privileged identity opened the path to every database and codebase the attacker says they took.
The verified data also shows weak credential storage. Unsalted SHA-256 is a fast general-purpose hash, not a password hashing algorithm, so common passwords stored this way can be cracked quickly. See our Password Security Guide and Active Directory and Entra ID Hardening Guide.
Recommendations
- Store passwords with a proper password hashing algorithm. Use Argon2, bcrypt or scrypt with salts, never plain fast hashes. See the Password Security Guide.
- Reduce and protect domain admin accounts. Tier admin access and remove standing domain admin rights from service accounts. See the Active Directory and Entra ID Hardening Guide.
- Respond publicly to credible leak claims. Customers need to know whether to reset passwords.
- Force password resets after a verified leak. Especially where hashes are weak.
- Encourage customers to use MFA. It limits the value of cracked or reused passwords. See the MFA Guide.
Frequently asked questions
Was Zacks Investment Research breached in 2024?
A hacker claims to have breached Zacks in June 2024 and leaked data on 12 million accounts, which Have I Been Pwned verified in February 2025. Zacks has not confirmed the breach.
What data was leaked in the Zacks breach?
Email addresses, names, usernames, phone numbers, physical addresses, IP addresses and passwords stored as unsalted SHA-256 hashes, according to Have I Been Pwned.
Why is this listed as a human identity breach?
The verified data concerns customer accounts. The attacker's claim of domain admin access has not been confirmed, so we do not list it as an NHI breach.
Related NHI Mgmt Group resources
23andMe Credential Stuffing Breach 2023 · Cisco Active Directory Credentials Leak · Password Security Guide · Active Directory and Entra ID Hardening Guide · MFA Guide
How NHI Mgmt Group can help
Privileged directory accounts, whether used by people or automation, are the keys to the kingdom. We help teams find and reduce standing admin rights and protect the accounts that remain. See our NHI and AI agent security training.
References
- BleepingComputer: Hacker leaks account data of 12 million Zacks Investment users (13 February 2025)
- Malwarebytes: 12 Million Zacks accounts leaked by cybercriminal (14 February 2025)
- Infosecurity Magazine: Zacks Investment Research Breach Hits 12 Million (18 February 2025)