Reed
We’re seeing an uptick in breaches sourced from recruitment platforms and HR tech, often surfacing weeks or months after the initial compromise. What really struck us with this particular incident wasn't the volume of records, but the detailed resume and application data exposed. The data had been circulating quietly on a relatively obscure forum frequented by identity thieves, but we noticed an uptick in chatter correlating with recent phishing campaigns targeting specific industries. The setup here felt different because of the completeness of the profiles; it wasn't just email addresses and names, but full career histories, skills assessments, and even salary expectations.
The Recruitment Platform Leak: Reed's Candidate Data Exposed
A significant breach impacting the job recruitment platform Reed.co.uk has resulted in the exposure of sensitive data belonging to job seekers. This incident highlights the ongoing risk associated with third-party platforms handling personal and professional information. The data, discovered on a dark web forum known for trading in stolen identity information, includes a wealth of detail that could be leveraged for targeted social engineering and identity theft.
We first discovered the breach on October 26, 2023, while monitoring a forum known for hosting stolen databases. The initial post advertising the data dump included sample records, allowing us to quickly verify the legitimacy and source of the leak. What caught our attention was the sheer depth of information associated with each individual profile. This level of detail significantly increases the potential for malicious use compared to breaches containing only basic contact information.
This incident matters to enterprises because it underscores the interconnectedness of the threat landscape. Even if a company's internal systems are secure, the security posture of its vendors and partners can create vulnerabilities. The data exposed in the Reed breach could be used to craft highly convincing phishing campaigns targeting employees based on their career history, skills, and job search activity. This breach also demonstrates the continued value of personal data on underground markets, even in the age of sophisticated malware and ransomware attacks.
- Total records exposed: Approximately 2.4 million
- Types of data included: Email addresses, usernames, hashed passwords (bcrypt), full names, phone numbers, job titles, employment history, skills, locations, education details, salary expectations, and application history.
- Sensitive content types: Resumes (in various formats, including .doc and .pdf), cover letters, and potentially assessment results.
- Source structure: Believed to be a partial database dump, likely extracted via SQL injection or similar vulnerability.
- Leak location(s): A dark web forum specializing in the sale of stolen databases.
- Date of first appearance: October 20, 2023
Security news outlets have begun reporting on the breach. For example, Security Affairs reported on October 27, 2023 about the data breach affecting Reed.co.uk, with the stolen data being offered for sale on cybercrime forums. (Source: Security Affairs)
Discussions on Telegram channels dedicated to data breaches confirm the active trading of the Reed data. One Telegram post claimed the files were being sold for between $1000 - $2000, depending on the buyer's reputation and the quantity of data purchased. This price point indicates the perceived value of the data to malicious actors.
The breach aligns with a broader trend of attacks targeting HR and recruitment platforms. Similar incidents have been reported in recent months involving other major job boards and applicant tracking systems. This suggests that attackers are actively focusing on these platforms as a valuable source of personal and professional information.
Breach Breakdown
7,587 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds