Monster.com job seeker data exposed in third-party leak

Unprotected server contained CVs from between 2014 and 2017

A web server storing the CVs of job seekers, including those from recruitment site Monster, has been discovered online.

While exact numbers are not known, the CVs include job applicants from 2014 to 2017, with those effected potentially running into the tens of thousands. The CVs contain private information such as addresses, phones numbers, email address and work history.

According to a report by TechCrunch, a statement by Monster's chief privacy officer Michael Jones said the server was owned by an unnamed recruitment customer, which it no longer works with.

Jones said that his firm's security team "was made aware of a possible exposure and notified the recruitment company of the issue". The company added that the server was secured in August.

"Customers that purchase access to Monster's data - candidate rsums and CVs - become the owners of the data and are responsible for maintaining its security," the statement added. "Because customers are the owners of this data, they are solely responsible for notifications to affected parties in the event of a breach of a customer's database."

The majority of the CVs appeared to belong to users in the US, but trove could also include users in the EU, suggesting that regulatory action from European data protection authorities operating under GDPR could be on the horizon.

While data is not directly accessible, private information could be found in caches of search engines.

Erich Kron, security awareness advocate for KnowBe4, told IT Pro that this is a lesson in how data can spread without people being aware of it.

"In this case, when we put our job history, resume and/or CV on these types of sites, we should assume that organisations are going to collect them as they review and use them for job considerations. Where things get murky is what happens with the information after it is used, and ensuring it was used in a proper manner in the first place. Currently, in the US, people are often completely unaware when data is processed by a third party. This is something that GDPR is designed to address," he said.

"While the potential leak should not have taken place at all, the third party did respond in a timely manner and fixed the problem," added Kron. "Unfortunately, many organisations have not considered how to deal with events like this and therefore lack the policies and procedures to deal with them quickly and efficiently."

Back in 2009, Monster's UK site was hit by a direct hack on its systems that led to the theft of data belonging to 4.5 million users, considered at the time to have been the largest data breach in UK history.

Featured Resources

How to be an MSP: Seven steps to success

Building your business from the ground up

Download now

The smart buyer’s guide to flash

Find out whether flash storage is right for your business

Download now

How MSPs build outperforming sales teams

The definitive guide to sales

Download now

The business guide to ransomware

Everything you need to know to keep your company afloat

Download now

Most Popular

KPMG offers staff 'four-day fortnight' in hybrid work plans
flexible working

KPMG offers staff 'four-day fortnight' in hybrid work plans

6 May 2021
Dell XPS 17 (2021) review: A big laptop for big jobs
Laptops

Dell XPS 17 (2021) review: A big laptop for big jobs

10 May 2021
16 ways to speed up your laptop
Laptops

16 ways to speed up your laptop

29 Apr 2021