Monster.com job seeker data exposed in third-party leak

Unprotected server contained CVs from between 2014 and 2017

A web server storing the CVs of job seekers, including those from recruitment site Monster, has been discovered online.

While exact numbers are not known, the CVs include job applicants from 2014 to 2017, with those effected potentially running into the tens of thousands. The CVs contain private information such as addresses, phones numbers, email address and work history.

According to a report by TechCrunch, a statement by Monster's chief privacy officer Michael Jones said the server was owned by an unnamed recruitment customer, which it no longer works with.

Jones said that his firm's security team "was made aware of a possible exposure and notified the recruitment company of the issue". The company added that the server was secured in August.

"Customers that purchase access to Monster's data - candidate rsums and CVs - become the owners of the data and are responsible for maintaining its security," the statement added. "Because customers are the owners of this data, they are solely responsible for notifications to affected parties in the event of a breach of a customer's database."

The majority of the CVs appeared to belong to users in the US, but trove could also include users in the EU, suggesting that regulatory action from European data protection authorities operating under GDPR could be on the horizon.

While data is not directly accessible, private information could be found in caches of search engines.

Erich Kron, security awareness advocate for KnowBe4, told IT Pro that this is a lesson in how data can spread without people being aware of it.

"In this case, when we put our job history, resume and/or CV on these types of sites, we should assume that organisations are going to collect them as they review and use them for job considerations. Where things get murky is what happens with the information after it is used, and ensuring it was used in a proper manner in the first place. Currently, in the US, people are often completely unaware when data is processed by a third party. This is something that GDPR is designed to address," he said.

"While the potential leak should not have taken place at all, the third party did respond in a timely manner and fixed the problem," added Kron. "Unfortunately, many organisations have not considered how to deal with events like this and therefore lack the policies and procedures to deal with them quickly and efficiently."

Back in 2009, Monster's UK site was hit by a direct hack on its systems that led to the theft of data belonging to 4.5 million users, considered at the time to have been the largest data breach in UK history.

Featured Resources

Security analytics for your multi-cloud deployments

IBM Security QRadar SIEM solution brief

Download now

Five reasons to move to the cloud

Join the enterprises moving their workloads to the cloud

Download now

Architecting hybrid IT and edge for digital advantage

Why business leaders should consider a hybrid IT strategy

Download now

Six reasons to accelerate remote asset monitoring with AI

How to optimise resources, increase productivity, and grow profit margins with AI

Download now

Most Popular

How to build a CMS with React and Google Sheets
content management system (CMS)

How to build a CMS with React and Google Sheets

24 Feb 2021
Oxford University COVID lab falls victim to hackers
hacking

Oxford University COVID lab falls victim to hackers

26 Feb 2021
Npower shuts down app after hackers steal user data
hacking

Npower shuts down app after hackers steal user data

25 Feb 2021