Quick answer: This is the June 18, 2023 edition of Data Privacy Weekly. The week’s biggest story is a data breach at Zacks Investment Research that exposed personal data for 8.8 million customers, found circulating via Have I Been Pwned. If you have a Zacks account, change your password now, and anywhere you reused it.
This week’s stories
- Google Chrome adds biometric login, custom notes, and expanded Password Checkup to its built in Password Manager.
- Microsoft Azure Portal outage traced to a possible DDoS attack claimed by Anonymous Sudan.
- Zacks Investment Research breach exposes personal data for 8.8 million customers.
- LockBit ransomware gang extorts an estimated $91 million from U.S. organizations since 2020.
- MOVEit file transfer breach hits multiple U.S. government agencies, including the Department of Energy.
Published: June 2023. Updated: August 2026 (formatting and analysis refreshed; news content is an accurate historical record and has not been altered). Reviewed by Encryption Consulting’s Threat Intelligence team.
About this series: Data Privacy Weekly is Encryption Consulting’s curated roundup of notable data privacy and cybersecurity news. Each edition is compiled by our editorial team from named third party outlets, published weekly. Read the next edition (week of July 1, 2023).
01. Google Chrome’s Enhanced Password Manager Safeguards Your Credentials
Google Chrome’s built-in Password Manager is receiving new security features to protect user credentials. These enhancements include a dedicated desktop shortcut for easy access, biometric authentication on desktop platforms, the ability to save custom notes with logins, importing passwords from other managers, and an expanded Password Checkup tool on the Chrome iOS app.
Despite the potential risks associated with storing passwords in a browser, these updates aim to enhance the security of Google Password Manager and provide added protection for users’ accounts.
Enterprise implication: Browser based password managers are convenient, but they remain a single point of failure if an employee’s device is compromised; treat them as a baseline, not a replacement for a managed enterprise password or secrets manager.
Recommended action: Encourage employees to turn on biometric authentication in Chrome’s Password Manager, and route business critical credentials through your organization’s own password or secrets manager instead.


02. Microsoft Azure Portal: Traffic Spike or DDoS Attack?
Microsoft Azure experienced connectivity issues on its Azure Portal, which the company initially attributed to a “traffic spike.” However, a cybercrime group, Anonymous Sudan, claimed responsibility for the outage, suggesting it was a distributed denial of service (DDoS) attack, meaning an attempt to flood a service with junk traffic until it becomes unavailable. The incident affected multiple Microsoft services, including Entra Admin center and Intune.
Microsoft employed load balancing and auto-recovery operations to mitigate the issue and continued monitoring platform health. Prior to this, OneDrive was also targeted by a DDoS attack with the same threat actor claiming responsibility.
Enterprise implication: A DDoS attack against a major cloud provider’s admin console can disrupt any organization relying on that console for identity or device management, even when the attacker’s real target is the platform itself, not you.
Recommended action: Confirm your incident response plan includes a fallback path for managing Azure and Entra resources if the admin portal becomes temporarily unavailable.
03. Major Data Breach at Zacks Investment Research Exposes 8.8 Million Customers
Zacks Investment Research has reportedly suffered an undisclosed data breach affecting 8.8 million customers, with the compromised database now circulating on a hacking forum. This breach follows a previously disclosed incident where unauthorized individuals accessed the personal information of approximately 820,000 customers. The additional breach, discovered by the data breach notification service Have I Been Pwned, contains email addresses, usernames, passwords, addresses, phone numbers, and other data but does not include financial information.
Zacks plans to notify affected users but has not provided a timeline. The leaked database increases the risk of phishing and credential-stuffing attacks, necessitating users to change their Zacks passwords and any reused passwords on other sites.
Enterprise implication: Large credential exposures like this one feed credential stuffing attacks against unrelated services whenever a password is reused. See Encryption Consulting’s guide to secure password storage for how credential databases like this one are supposed to be protected.
Recommended action: Rotate your Zacks password immediately if you have an account, along with any other account where you reused it.


04. LockBit Ransomware Gang Extorts $91 Million from U.S. Organizations
U.S. and international cybersecurity authorities issued a joint advisory revealing that the LockBit ransomware gang has extorted approximately $91 million from U.S. organizations through 1,700 attacks since 2020. This Ransomware-as-a-Service (RaaS) operation, meaning affiliates rent LockBit’s ransomware tools in exchange for a cut of each payout, was the leading global threat in 2022, with the highest number of victims on their data leak site.
LockBit targeted various sectors, including finance, education, healthcare, and government, and the advisory provides a list of tools and tactics used by LockBit affiliates. Mitigation measures are also recommended to defend against LockBit activity. The FBI urges organizations to review the advisory and report any cybercrime incidents.
Enterprise implication: LockBit’s affiliate model means organizations of any size or sector can become a target; finance, education, healthcare, and government were all named specifically in this advisory.
Recommended action: Compare the joint CISA/FBI advisory’s indicators of compromise against your own environment, and confirm your offline backups are tested and isolated from your primary network.
05. U.S. Government Agencies Targeted in Global Cyberattack on File-Transfer Service
Multiple U.S. government agencies, including the Department of Energy, were targeted in a global cyberattack on the file-transfer service MOVEit, a managed file transfer platform used by many enterprises and government agencies to move large or sensitive files between systems. The attack, attributed to a Russian-speaking criminal group, has not led to data leaks or extortion demands so far. The software operator, Progress, has released security patches, and law enforcement agencies are involved.
Recent cyberattacks, including the SolarWinds incident, have been linked to Russian government-backed groups or individual actors. In a separate development, Microsoft revealed a state-sponsored Chinese hacking group spying on critical infrastructure organizations. Collaborative efforts are underway to identify the extent of the breaches.
Enterprise implication: MOVEit is used indirectly through vendors and contractors by many organizations, so exposure can exist even if you never used it directly. See Encryption Consulting’s overview of third party and supply chain risk for how vendor side exposure like this can reach your organization.
Recommended action: Ask your vendors and contractors whether they use MOVEit, and if so, confirm they have applied Progress’s security patches.

This Week at a Glance
| Story | Category | Real World Impact |
|---|---|---|
| Google Chrome Password Manager updates | Product security update | Stronger built in credential protection for Chrome users, though browser stored passwords remain a single point of failure |
| Microsoft Azure Portal outage | Suspected DDoS attack | Temporary disruption to Entra Admin center and Intune access, mitigated through load balancing |
| Zacks Investment Research breach | Data breach | Personal data for 8.8 million customers exposed, raising credential stuffing risk |
| LockBit ransomware advisory | Ransomware / RaaS | Roughly $91 million extorted from U.S. organizations across 1,700 attacks since 2020 |
| MOVEit file transfer cyberattack | Vendor / supply chain breach | Multiple U.S. government agencies affected, including the Department of Energy |
Limitations
- This is a curated selection of newsworthy stories from the week of June 18, 2023, not an exhaustive record of every data privacy or security event that occurred that week.
- Facts and figures are sourced from the named third party outlets linked in each item and in the References section below; Encryption Consulting has not independently re-verified the underlying claims in those reports.
- This page reflects a historical record as of its original publish date; later developments in any of these stories, such as updated breach totals or legal outcomes, may not be captured here.
Frequently Asked Questions
What happened in the Zacks Investment Research data breach? In June 2023, a database from Zacks Investment Research exposing personal data for 8.8 million customers, including email addresses, usernames, passwords, addresses, and phone numbers, was found circulating on a hacking forum and identified through Have I Been Pwned. It followed an earlier breach affecting about 820,000 customers.
Was the Microsoft Azure Portal outage confirmed as a DDoS attack? Microsoft initially described the June 2023 Azure Portal disruption as a traffic spike. The group Anonymous Sudan claimed responsibility for a distributed denial of service attack, but Microsoft’s public statements focused on mitigation through load balancing rather than formally confirming the cause.
How much money has the LockBit ransomware gang extorted from U.S. organizations? According to a joint CISA and FBI advisory, LockBit extorted approximately $91 million from U.S. organizations through roughly 1,700 attacks between 2020 and 2023, making it one of the most active ransomware as a service, or RaaS, operations of that period, with victims spanning finance, education, healthcare, and government.
What was the MOVEit cyberattack and who was affected? MOVEit is a managed file transfer platform used to move large or sensitive files between systems. A June 2023 attack on it, attributed to a Russian speaking criminal group, affected multiple U.S. government agencies, including the Department of Energy. Progress Software, MOVEit’s operator, released security patches in response.
More from Data Privacy Weekly
This is the earliest edition of Data Privacy Weekly in Encryption Consulting’s current archive. Continue to the next edition, covering the week of July 1, 2023, for more curated data privacy and cybersecurity news.
References
- Google, “Chrome’s Password Manager gets new features,” blog.google
- TechRadar, “Microsoft Azure outage caused by huge spike that could have been a DDoS attack,” techradar.com
- CPO Magazine, “Zacks Investment Research Firm Data Breach Expands to Nearly Nine Million Impacted,” cpomagazine.com
- BleepingComputer, “CISA: LockBit ransomware extorted $91 million in 1,700 US attacks,” bleepingcomputer.com
- Forbes, “US Government Agencies, Including Energy Department, Targeted In Latest Global Cyberattack,” forbes.com
