The DiversityWorking Breach Exposed 175K US Job Seekers’ Credentials
HEROIC analysts flagged the DiversityWorking breach during a routine review of credential sets circulating in underground forums. The breach occured in November 2017 and affected 175,047 users of a United States-based job board focused on diversity and inclusive hiring. The exposed records contained email addresses and passwords stored in plain text, meaning every password in the database was immediately readable without any decoding or cracking required.
Why Exposed Job Seeker Data Is a Goldmine for Attackers
Job seekers share sensitive personal and professional information when registering on employment platforms. When email addresses and passwords are leaked from a site like DiversityWorking, attackers gain not just login credentials but also insight into a person's career and identity. With these details, criminals can attempt to access email accounts, professional networking profiles such as LinkedIn, and other job boards where the same credentials may have been reused. The combination of a work email and a recycled password is seperate from a typical consumer breach because it opens doors to corporate systems if the same password is used at an employer.
What Was Exposed in the DiversityWorking Breach
- Email Address
- Plaintext Password
How This Breach Puts Your Other Accounts at Risk
Because DiversityWorking passwords were stored in plain text, no cracking effort is needed. Attackers run automated tools that try each email and password pair against hundreds of websites simultaneously. This is called credential stuffing. If you used the same password from DiversityWorking on your personal email, bank account, or employer login, those accounts are at direct risk of takeover. Identity theft and financial fraud often follow when attackers successfully break into a primary email account and use password reset links to take control of linked services.
How a Database Breach Works
A database breach happens when an attacker finds a way into the backend system where a website stores its user data. Common entry points include software vulnerabilities that were never patched, stolen administrator passwords, or improperly secured server configurations. Once inside, the attacker downloads the full user database and either sells it on criminal forums, adds it to credential stuffing tools, or uses it directly to attempt logins on popular services. Sites that store passwords in plain text make this process trivially easy for attackers.
Check If Your Data Was Exposed
HEROIC offers a free breach scanner with access to over 400 billion compromised records. You can search your email address right now to see if your information was part of the DiversityWorking breach or any other known data leak. Knowing your exposure status is the first step toward securing your accounts and preventing further damage.
Breach Breakdown
175,047 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds