Cybernews researchers discovered an unprotected Talentsconnect database with nearly 11GB of live recruitment data, referencing 843 companies, including references associated with Siemens, Deutsche Bank, Vodafone, BASF, and EY. Talentsconnect is a company that specializes in direct-to-talent (D2T) matching platforms, which connect job seekers and employers.
Here are the key findings:
- The exposed database with over 5 million job listings included applicants’ names, emails, phone numbers, salary expectations, Base64-encoded CVs, or cover letters.
- The database showed 335 plaintext credentials across 56 client integrations. One belonged to the waste management company Remondis, with username and password information potentially providing access to their recruitment portal.
- Researchers found 80 plaintext credentials for FFG Prescreen, a background-check tool used in hiring. These are intended to allow candidates to modify submissions, but malicious actors could exploit them to post fake jobs, alter details, or delete data.
- Exposed data contained AWS Secrets Manager references for such companies as Siemens, Vantage Towers (Vodafone), Hornbach, ARAG, Computacenter, Peek & Cloppenburg, and UniCredit.
“This is a single point of failure sitting behind the hiring pipelines of hundreds of major European employers. Anyone on the internet could have read the entire client roster, harvested candidate personal data, or, because access was read/write, altered or injected data. For example, posting fake job ads under real company names, submitting fraudulent applications with malicious attachments, or deleting listings,” our researchers explained.
Talentsconnect closed the database after researchers disclosed the issue to the company, and the information is no longer publicly accessible. Cybernews researchers found no evidence that unauthorized users accessed the data while it was still leaking.
For more information, here’s the full report:
https://cybernews.com/security/talentsconnect-hr-database-data-leak
Related
This entry was posted on August 12, 2026 at 8:30 am and is filed under Commentary with tags Cybernews. You can follow any responses to this entry through the RSS 2.0 feed.
You can leave a response, or trackback from your own site.
11GB Of Data Exposed Says Cybernews
Cybernews researchers discovered an unprotected Talentsconnect database with nearly 11GB of live recruitment data, referencing 843 companies, including references associated with Siemens, Deutsche Bank, Vodafone, BASF, and EY. Talentsconnect is a company that specializes in direct-to-talent (D2T) matching platforms, which connect job seekers and employers.
Here are the key findings:
“This is a single point of failure sitting behind the hiring pipelines of hundreds of major European employers. Anyone on the internet could have read the entire client roster, harvested candidate personal data, or, because access was read/write, altered or injected data. For example, posting fake job ads under real company names, submitting fraudulent applications with malicious attachments, or deleting listings,” our researchers explained.
Talentsconnect closed the database after researchers disclosed the issue to the company, and the information is no longer publicly accessible. Cybernews researchers found no evidence that unauthorized users accessed the data while it was still leaking.
For more information, here’s the full report:
https://cybernews.com/security/talentsconnect-hr-database-data-leak
Share this:
Like this:
Related
This entry was posted on August 12, 2026 at 8:30 am and is filed under Commentary with tags Cybernews. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.