Zacks Investment Research (Zacks), stock performance assessment tool provider, had a leaked database added to Have I Been Pwned on Wednesday of this week that included 12 million unique records. HIBP confirmed that the file included 12 million unique:
- Email addresses
- IP addresses
- Names
- Passwords in the form of unsalted SHA-256 hashes
- Phone numbers
- Physical addresses
- Usernames
Scammers and other threat actors will have “fun” with all that data…. At your expense if you’re on this list.
Lawrence Pingree, VP, Dispersive had this to say:
“When leaks occur, it allows investigators to determine more quickly where they need to look to investigate. E.g. They normally know at least in theory where the data came from. The important thing is to have zero trust connectivity between systems, isolating them from lateral movements from compromised systems, limiting the blast radius of the breach. In this case, it is most likely an application layer attack or SQL injection into the application that resulted in the database exposure, but I am speculating based on the scenario.”
Jawahar Sivasankaran, President, Cyware follows with this:
“Research shows that 72% of security professionals struggle with prioritizing vulnerabilities, delaying remediation efforts, and 17% of IT assets are invisible to vulnerability scans, leaving them exposed.
“When it comes to cybersecurity, competing financial services organizations are better protected and more resilient when they work together. Joining sector-specific Information Sharing and Analysis Centers (ISACs) such as the Financial Services ISAC ( FS-ISAC) and operational collaboration frameworks that leverage public-private partnerships – gives financial services organizations new visibility into exploited vulns, threats the sector faces, data protection best practices, issues on emerging risks such as generative AI, and more efficient and effective threat intelligence management and proactive response strategies.”
Hopefully the 12 million people on this list have credit monitoring services in place. Because they’re going to need it.
Related
This entry was posted on February 14, 2025 at 1:15 pm and is filed under Commentary with tags Hacked. You can follow any responses to this entry through the RSS 2.0 feed.
You can leave a response, or trackback from your own site.
Zachs Investment Research leaks 12 million unsalted passwords, user names & more
Zacks Investment Research (Zacks), stock performance assessment tool provider, had a leaked database added to Have I Been Pwned on Wednesday of this week that included 12 million unique records. HIBP confirmed that the file included 12 million unique:
Scammers and other threat actors will have “fun” with all that data…. At your expense if you’re on this list.
Lawrence Pingree, VP, Dispersive had this to say:
“When leaks occur, it allows investigators to determine more quickly where they need to look to investigate. E.g. They normally know at least in theory where the data came from. The important thing is to have zero trust connectivity between systems, isolating them from lateral movements from compromised systems, limiting the blast radius of the breach. In this case, it is most likely an application layer attack or SQL injection into the application that resulted in the database exposure, but I am speculating based on the scenario.”
Jawahar Sivasankaran, President, Cyware follows with this:
“Research shows that 72% of security professionals struggle with prioritizing vulnerabilities, delaying remediation efforts, and 17% of IT assets are invisible to vulnerability scans, leaving them exposed.
“When it comes to cybersecurity, competing financial services organizations are better protected and more resilient when they work together. Joining sector-specific Information Sharing and Analysis Centers (ISACs) such as the Financial Services ISAC ( FS-ISAC) and operational collaboration frameworks that leverage public-private partnerships – gives financial services organizations new visibility into exploited vulns, threats the sector faces, data protection best practices, issues on emerging risks such as generative AI, and more efficient and effective threat intelligence management and proactive response strategies.”
Hopefully the 12 million people on this list have credit monitoring services in place. Because they’re going to need it.
Share this:
Like this:
Related
This entry was posted on February 14, 2025 at 1:15 pm and is filed under Commentary with tags Hacked. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.