Go4ConstructionJobs Breach: 175,108 UK Construction Job Seeker Accounts Exposed (2018)
175,108 Construction Job Seekers, Zero Password Protection
Job seekers trust recruitment platforms with more than just an email and password. They submit CVs, employment histories, professional qualifications, and sometimes personal identification. When Go4ConstructionJobs, a UK construction recruitment platform, suffered a data breach in August 2018, the 175,108 affected users didn't just lose their login credentials -- they lost them in plaintext, with no hashing, no encryption, no barrier whatsoever between their passwords and whoever was collecting this data.
Go4ConstructionJobs (August 2018): Breach Summary
- Records Exposed: 175,108
- Data Types: Email addresses, plaintext passwords
- Breach Type: Database breach
- Country Affected: United Kingdom
- Date Leaked: August 21, 2018
Plaintext on a Recruitment Platform: A Compounded Risk
Plaintext password storage means there's no cracking step required. An attacker with the Go4ConstructionJobs database had 175,108 working email/password pairs, immediately ready for use in credential stuffing attacks across any other platform those users might have registered on. But the risk doesn't stop at credentials. Recruitment platforms accumulate rich professional profiles: real names, phone numbers, home locations, employment histories, trade certifications, and references. Even without payment data, the combination of verified identity information and plaintext login credentials makes a recruitment breach significnatly more valuable than a typical consumer account leak.
Construction Industry Targeting: A Pattern Worth Noting
Construction and trades recruitment platforms attract a specific demographic: workers and contractors who may be less digitally sophisticated than tech industry professionals, and who frequently use the same email and password across multiple platforms -- job boards, equipment hire sites, supplier portals, and contractor management tools. A plaintext breach from a construction job board isn't just a consumer privacy incident. It's a credential harvest from a workforce that, in many cases, also has access to commercial properties, project managment systems, and physical site acces tools.
Largest in the August 21 Wave
At 175,108 records, Go4ConstructionJobs was among the largest breaches in the August 21, 2018 opening wave -- a day that also saw Highland Host (UK), DownloadPlex (USA), Hamumu (USA), Handheld Culture (Hong Kong), Educationext (Canada), and Detalles Falabella (Spain) all surface simultaneously. The sheer volume of the Go4ConstructionJobs records, combined with plaintext storage, made it one of the most immediatley actionable breaches in the entire August 2018 cluster.
Check If Your Credentials Were Exposed
HEROIC's free breach scanner searches across more than 400 billion exposed records -- including UK recruitment platforms, job boards, and construction industry services. If you've ever registered on Go4ConstructionJobs or similar sites, check now to see if your data is circulating in breach databases.
Breach Breakdown
175,108 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds