SBC Recruitment Data Breach: 33,948 Japanese Employment Records Exposed
Japan's Hiring Industry Has a Data Security Problem
SBC Recruitment operated as a Japanese employment platform connecting job seekers with employers across the country. In November 2017, 33,948 user records -- including the persoanl information and login credentials of job seekers and recruiters alike -- appeared in an underground data dump. What makes this breach particularly concerning is the password hashing format: unknown. When investigators cannot identify the hash type, the safest assumption is that every password in the database should be treated as fully compromised.
SBC Recruitment (November 2017): Breach Summary
- Records Exposed: 33,948
- Data Types: Email addresses, usernames, passwords (Unknown hash)
- Breach Type: Database, Combolist
- Country Affected: Japan
- Date Leaked: November 19, 2017
Unknown Hash Types: Why Ambiguity Is the Worst Outcome
When a breach exposes passwords protected by a known algorithm -- MD5, bcrypt, SHA1 -- security professionals can make concrete assessments about crack resistance. MD5 without salt is effectively plaintext. bcrypt with a high work factor buys significant time. But when the hash type is unknown, no such assessment is possible. The format might be a proprietary scheme with unknown salt handling, an undocumented legacy algorithm, or simply a value that defies automated identification. In all cases, the practical advice is identical: assume the passwords are cracked, assume the credentials are in use, and take immediate remediation action. For SBC's 33,948 affected users, the ambiguity of the hash format provides zero comfort.
Employment Platforms: High-Value Credential Targets
Japanese emploment and recruitment platforms hold an unusually rich data profile compared to consumer sites. Beyond email and password, they typically store full names, phone numbers, work history, and resume data -- a complete profile useful for identity fraud, social engineering, and targeted phishing. Applcants who registered on sbc-web.co.jp likely used professional email addresses -- corporate or academic -- creating a direct bridge between the breach and high-value secondary targets. Recruiters' accounts, if compromised, could be used to conduct fraudulent hiring communications or extract candidate pipeline data from competing firms.
A Late 2017 Disclosure in Japan's Digital Employment Market
Japan's transition to digital recruitment accelerated through the 2010s, with the country's major employment platforms attracting tens of millions of users. SBC Recruitment's November 2017 breach sits in a period when Japanese digital platforms were frequently targeted by actors seeking to accumulate Japanese-language credential databases -- a segment of the underground market that has grown considerably as Japan's technology sector expanded. The 33,948 records from SBC join a broader pool of Japanese employment credentials that have circulated in combolist aggregations since 2017.
Check If Your Credentials Were Exposed
HEROIC's free breach scanner searches across more than 400 billion exposed records to tell you exactly which of your accounts have been compromised. If you used SBC Recruitment's platform -- as a job seeker or a recruiter -- run a check now at HEROIC.com. Unknown hash types offer no protection guarantee, and years of potential cracking time means these passwords should be considered fully exposed.
Breach Breakdown
33,948 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds