leaksear.ch has indexed 8,880,596 records tied to Zacks Investment Research, including names, usernames, email and physical addresses, phone numbers, and unsalted SHA-256 password hashes, with the breach date listed as May 1, 2020 (leaksear.ch metadata). Public reporting later tied the larger Zacks corpus to data that appeared online in June 2023 and was broadly circulated on a hacking forum (haveibeenpwned.com, securityweek.com).
What happened
Zacks Investment Research is an investment research company whose breach history first became public in December 2022, when the company announced an incident later reported as affecting roughly 820,000 customers (haveibeenpwned.com, bleepingcomputer.com). BleepingComputer reported in January 2023 that Zacks determined an unauthorized party had accessed its network sometime between November 2021 and August 2022, exposing names, addresses, phone numbers, email addresses, and Zacks.com passwords for a subset of customers (bleepingcomputer.com).
The larger dataset became public in June 2023. Have I Been Pwned reported that almost 9 million Zacks customer records appeared and were broadly circulated on a popular hacking forum, with the most recent data dated May 2020 (haveibeenpwned.com). SecurityWeek reported that Zacks said the unauthorized third parties also accessed encrypted passwords, while stating it had no reason to believe customer credit card information or other financial information was accessed (securityweek.com).
The public record does not establish the initial intrusion method for the larger corpus. CPO Magazine reported that the identity of the threat actor and the means of the breach had not been disclosed (cpomagazine.com).
What data was exposed
The leaksear.ch indexing metadata lists searchable fields for name, username, email address, physical address, country, phone number, and hashed password (leaksear.ch metadata). The password material is described as unsalted SHA-256 hashes, a detail also reported by Have I Been Pwned and SecurityWeek (haveibeenpwned.com, securityweek.com).
The indexed records also contain account and contact-related metadata such as customer IDs, address IDs and address types, registration dates, display names, firm names, phone extensions, evening phone numbers, fax fields, SMS numbers and opt-in dates, partner codes, and clue or hint fields (leaksear.ch metadata). Those additional fields are present as record context, but they are not listed as direct searchable pivots in the leaksear.ch metadata (leaksear.ch metadata).
Why this matters
The practical risk is highest where Zacks users reused passwords, because exposed usernames, email addresses, and unsalted password hashes can support credential-stuffing attempts against unrelated services. The contact data also gives phishers useful context for targeted emails, calls, or messages that impersonate Zacks or financial-services brands. SecurityWeek reported that Zacks said it had no reason to believe credit card or other financial information was accessed, but exposed identity and contact data can still create fraud and account-takeover risk (securityweek.com). Readers who had a Zacks account should check their exposure and rotate any reused password.
Check your exposure
Vetted researchers and incident-response teams can request access or sign in if they already have access to check this dataset. Searchable pivots for this leak include address, country, email, hashed password, name, phone, and username.