The JobStreet Breach Happened 14 Years Ago. The Data Just Went Public.
JobStreet is one of Southeast Asia's largest online job search platforms, operating across Malaysia, Singapore, the Philippines, and other countries. The site suffered a database breach in March 2012 that exposed 1,787,973 user accounts. The stolen records included full names, email addresses, usernames, phone numbers, birthdates, and password data. The breach stayed hidden for years until October 2017, when the data surfaced for sale on lowyat.net, a Malaysian online forum, five years after it was originally stolen.
Why JobStreet Breach Is Dangerous
Job search platforms collect some of the most sensitive personal information people share online. This breach exposed full names, birthdates, phone numbers, and email addresses alongside password data stored in Base64 encoding, which is not a proper hashing algorithm and provides essentially no protection. Decoded passwords from a Base64 database are as readable as plaintext. That combination of rich PII and unprotected credentials makes this breach particulary damaging, even by the standards of large data leaks.
What Was Exposed in the JobStreet Leak
- Email Address
- Username
- Phone Number
- Birthdate
- First Name
- Last Name
- Password Hash
Why This JobStreet Data Puts You at Risk
This breach goes beyond credential theft. Full name, phone number, and birthdate are enough to attempt identity verification bypass at financial institutions and telecom providers. Attackers can use the phone number for SIM swapping attacks to intercept two-factor authentication codes sent to your phone. If you used the same email and password on other accounts, those are at additonal risk. The combination of all these data types in one dump gives attackers the tools for layered, persistent attacks on multiple aspects of your digital identity.
How Database Breaches Work
In a database breach, an attacker gains unauthorized access to a site's backend and extracts user records. The breach occured at JobStreet in March 2012 but wasn't publicly known until October 2017, when the data was sold on a Malaysian online forum. That five-year window means the data may have been used in seperate private attacks before it ever became public. Once released, the data spread across breach aggregation sites and dark web markets where it remains available today.
Check If Your Data Was Exposed
HEROIC's free breach search checks your email against 400 billion+ compromised records, including data from the JobStreet dump. Search now to find out if your personal information was part of this breach, and take action on any accounts that share the same login details.
Breach Breakdown
1,787,973 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds