Reeqwest Data Breach: 27,665 UAE HR Platform Accounts Exposed in Plaintext (2018)
Gulf Region Recruitment, Fully Exposed: No Hashing, No Protection
Reeqwest offered HR consultancy and staffing services across the Gulf region -- a platform connecting professionals and employers in one of the world's most active recruitment markets. In March 2018, 27,665 user accounts from this Dubai-based platform were exposed, with passwords stored in plaintext. No hashing, no encryption, no barrier. Any attacker with the database had 27,665 working email and password pairs from a professionaly active workforce, ready for immediate use.
Reeqwest (March 2018): Breach Summary
- Records Exposed: 27,665
- Data Types: Email addresses, plaintext passwords
- Breach Type: Database breach
- Country Affected: United Arab Emirates
- Date Leaked: March 19, 2018
Plaintext Passwords in a Professional Recruitment Context
The risk profile of a plaintext breach on a recruitment platform is compunded by the nature of the data that surrounds the credentials. HR platforms accumulate real names, contact numbers, work histories, salary expectations, and professional references. An attacker who gains access to a Reeqwest account isn't just getting an email/password pair -- they're getting a detailed professional dossier. Combined with plaintext credentials that eliminate any cracking step, this creates an immediately actionable package for targeted phishing, business email compromise, and identity-based fraud in a Gulf region workforce context.
The Gulf Region Professional Demographic
Recruitment platforms serving the UAE and broader Gulf Cooperation Council region attract a distinctive user profile: expatriate professionals, multinational executives, finance and construction workers, and government contractors. Many of these users register with corporate email addresses from international employers, creating a credential reuse vector that extends well beyond the breached platform itself. A Gulf recruitment platform breach isn't just a regional incident -- it's a window into the credentials of an internationally distributed professional class, many of whom use the same password acros employer email systems, LinkedIn, and other professional tools.
March 2018: An Early-Year Breach in a Year of Heavy Activity
Reeqwest's breach leaked on March 19, 2018 -- months before the coordinated August 2018 multi-wave release events that would bring dozens more platforms to the surface. The March timing places it among the earlier 2018 breaches now known to have circulted in the same aggregated breach markets as the larger summer waves. Users who registered on Reeqwest and reused their credentials elsewhere faced compounding exposure as each subsequent breach release increased the likelihood of those credentials being actively tested.
Check If Your Credentials Were Exposed
HEROIC's free breach scanner searches across more than 400 billion exposed records -- including recruitment platforms, HR services, and UAE and Gulf region business sites. If you've ever registered on Reeqwest or similar platforms, check now to see if your data is circulating in breach databases.
Breach Breakdown
27,665 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds