Over 26 million resumes exposed in top CV maker data breach – here’s what we know


- Cybernews finds huge databse full of resumes and CVs
- It belongs to TalentHook
- The database apparently remains open to this day
Security researchers have discovered another large unprotected database which was leaking sensitive information to the general public.
Analysts fromCybernews found a misconfigured Azure Blob storage container available to anyone who knew where to look.
The archive contained almost 26 million files, and it was later determined that most of the files were resumes and CVs belonging to US citizens, including people’s full names, email addresses, phone numbers, education details, professional details, and employment history.
TalentHook in trouble
While it might not sound like much, the cache is a treasure trove for cybercriminals. Knowing these people are actively seeking new job opportunities, they can create fully customized, highly relevant phishing emails, successfully tricking people into downloading malware or sharing login credentials.
For example, the North Korean state-sponsored group Lazarus often targets job seekers on LinkedIn and elsewhere, sharing fake job description files which are nothing more than malware.
In some instances, they would have the victim jump through multiple job interview hoops, before asking for “trial work” which includes downloading malicious code.
Cybernews later determined that the archive belonged to TalentHook, a cloud-based applicant tracking system that connects HR departments with individuals seeking work.
Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!
Usually, when the researchers find unprotected databases such as this one, they notify the owners and get it locked down fast. However, in this instance, there was no confirmation that TalentHook actually barred access.
Instead, the Cybernews team shared advice with TalentHook, inviting the team to “change access controls to restrict public access and secure the container”. Therefore, it’s safe to assume that the database remains unlocked and available for all to find. The researchers also did not mention if someone found it already, but this is always a strong possibility.
At press time, there was no evidence of the data already being found and abused in the wild.
You might also like
Cybernews finds huge databse full of resumes and CVs It belongs to TalentHook The database apparently remains open to this day Security researchers have discovered another large unprotected database which was leaking sensitive information to the general public. Analysts fromCybernews found a misconfigured Azure Blob storage container available to anyone…
Recent Posts
- Amazon’s best Kindles are cheaper than ever during Prime Day
- AMD is surpassing Nvidia in one particular market, and I don’t understand why — 11th eGPU based on AMD Radeon RX 7000 series debuts and even has Thunderbolt 5
- Not Just Any Prime Day Deals, 220 Obsessively Tested Picks—even $1,200 off an OLED TV
- Samsung Galaxy Unpacked 2025 as it happened – the new Z Fold 7, Z Flip 7 and Galaxy Watch 8 are here
- Cyberpunk 2077 heads up July’s PS Plus Game Catalog additions
Archives
- July 2025
- June 2025
- May 2025
- April 2025
- March 2025
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023
- May 2023
- April 2023
- March 2023
- February 2023
- January 2023
- December 2022
- November 2022
- October 2022
- September 2022
- August 2022
- July 2022