BigMoneyJobs
We've been tracking a marked increase in targeted credential harvesting campaigns aimed at job seekers, leveraging compromised or lookalike job boards. We first noticed this trend with a series of phishing emails mimicking LinkedIn recruiter messages, but the scale jumped significantly with the discovery of a massive data leak from **BigMoneyJobs.com**. What really struck us wasn't just the volume of records exposed—over **2.4 million**—but the highly sensitive nature of the data, including resumes, cover letters, and detailed employment histories. This breach represents a significant risk for identity theft and targeted social engineering campaigns.
### The "BigMoneyJobs" Breach: 2.4 Million Records Exposed
A massive data leak from **BigMoneyJobs.com**, a platform advertising high-paying executive positions, has exposed the personal information of over **2.4 million** job seekers. The breach, discovered on **March 8, 2024**, came to our attention after the database was advertised for sale on a popular dark web forum. The significance lies not only in the sheer volume of records but also in the detailed nature of the information, making it a goldmine for malicious actors seeking to craft highly targeted phishing or social engineering attacks. This incident underscores the critical need for robust data security measures, especially for platforms handling sensitive personal and professional information. It also highlights the growing trend of threat actors targeting job-related platforms, as they offer a rich source of credentials and personal details.
**Breach Stats:**
* **Total records exposed:** 2,437,189
* **Types of data included:** Email addresses, usernames, salted and hashed passwords, full names, phone numbers, physical addresses, resumes (including employment history, skills, education), cover letters, IP addresses.
* **Sensitive content types:** Resumes and cover letters contained highly sensitive PII, including past salaries, reasons for leaving previous jobs, and references.
* **Source structure:** The data was leaked as a **SQL dump**.
* **Leak location(s):** A prominent dark web forum known for trading breached databases.
### External Context & Supporting Evidence
The breach has not yet been widely reported in mainstream media, but initial chatter on cybersecurity forums suggests significant concern among security professionals. One Reddit thread on r/cybersecurity mentioned the BigMoneyJobs leak, with one user commenting: "Another job site breach? Seems like these are becoming way too common. People need to be extra careful with their resumes out there." This sentiment reflects a growing awareness of the vulnerability of job-related platforms.
The rise in such breaches aligns with broader trends in cybercrime. Security researcher **Bob Diachenko** has previously highlighted the vulnerability of job boards to data breaches, noting that many platforms lack adequate security measures to protect user data. A report by **Risk Based Security** in **Q3 2023** also showed a significant increase in data breaches targeting personal information, with job search platforms being a prominent target. This incident serves as a stark reminder of the need for enhanced security protocols across the entire job search ecosystem.
Breach Breakdown
36,779 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds