Identity Theft Resource Center (ITRC) reported that 820,000 people were affected by the Zacks Investment Research breach in its Q1 2023 data-breach analysis. Zacks’ sample notice describes unauthorized access to an older customer database, says the access likely occurred between November 2021 and August 2022, and lists contact details and Zacks.com passwords among the information believed accessed. The 820,000 figure comes from ITRC—not from Zacks’ sample notice.
What happened in the Zacks breach?
Zacks Investment Research said it learned of unauthorized access on December 28, 2022. The company believed the access took place sometime between November 2021 and August 2022 and involved an older database of customers who signed up for Zacks Elite from November 1999 through February 2005. The notice does not describe how the third party gained access.
The notice is reproduced in a sample letter filed with the Delaware Department of Justice.
What does “820,000 impacted” mean?
ITRC listed Zacks Investment Research among the top ten compromises in its Q1 2023 Data Breach Analysis, attributing 820,000 affected people to the incident. ITRC says the data in its analysis were entered into its notified database from January 7 through March 31, 2023, unless otherwise noted. The Zacks sample notice does not state a nationwide affected-person total, so the 820,000 figure should be attributed to ITRC’s report rather than presented as a number Zacks announced in its notice.
Quick wins for a faster PC:
Repair Windows errors before they cause bigger problemsFix Now →Scan for outdated or missing drivers - takes under a minuteDriver Scan →Clear out junk files and repair common Windows errorsFree Scan →#1 Best Overall
Delaware’s breach database separately lists 2,159 potentially affected Delaware residents, a breach period of November 2021–August 2022, and a report date of February 24, 2023. That is a state-specific notification count, not a competing estimate of the national figure.
What information was believed accessed?
Zacks’ notice lists names, mailing addresses, phone numbers, email addresses, and passwords used for Zacks.com as information believed to have been accessed. The company said it had no reason to believe credit-card details, other customer financial information, or other personal information were accessed. These are statements in the company’s notice, not an independently verified inventory of everything taken.
Was your Zacks account affected?
The notice connects the older database to Zacks Elite signups from November 1999 through February 2005. It does not establish that every person in that signup group was affected, whether every affected person received a notice, or how to verify an individual account’s status from the information in the sample letter. If you received a direct notice, follow its instructions; if you are unsure, contact Zacks using contact details obtained independently from its official site rather than replying to an unsolicited message.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What should affected customers do?
- Change the Zacks.com password. Zacks said it established a process to prevent the compromised password from being used to access a Zacks account and require a password change at the next login. Follow the account prompt and choose a new, unique password.
- Change reused passwords elsewhere. If you used the same email address and password on another service, change that password there too. Reuse can make an exposed credential useful beyond the account named in the notice.
- Monitor financial accounts and credit reports. Zacks recommended monitoring financial accounts and consumer credit reports. Review account activity and reports for unfamiliar changes or activity; the notice does not promise that monitoring will prevent misuse.
- Be cautious with breach-related messages. The notice warned recipients not to provide personal information in response to electronic communications about security breaches. Do not click unexpected links or share credentials in response to an unsolicited message.
Zacks wrote: “While we have found no indication that your personal information has been used inappropriately, we are providing you with this notice and steps you can take to help protect your information.” That is the company’s statement at the time of the notice, not a guarantee that information was never misused or cannot be misused later.
Do these 3 things before closing this tab:
1Scan for outdated or missing drivers - takes under a minute2Repair Windows errors before they cause bigger problems3Fix the driver behind crashes, sound loss and screen glitchesQuick Recap
Best Value
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




