Monster.com job applicants info exposed on unprotected server
.png)
Personal details from resumes and CVs from job seekers were exposed after a server belonging to a recruitment company that was a customer of Monster.com and others was left unprotected.
Monster.com which learned of the breach in August, did not initially alert potential victims to the exposure, contending that notification responsibly lay with the recruitment company that "owned" the data.
"Customers that purchase access to Monster’s data — candidate résumés and CVs — become the owners of the data and are responsible for maintaining its security," Monster Chief Privacy Officer (CPO) Michael Jones said in a statement cited by TechCrunch. "Because customers are the owners of this data, they are solely responsible for notifications to affected parties in the event of a breach of a customer’s database."
Jones said it contacted the recruitment company it first became aware of the exposed server, which was secured soon thereafter.
"In today’s era of growing privacy regulations, how companies react in the wake of a data breach is critical, said Peter Goldstein, CTO and co-founder of Valimail.
Indeed, "Monster might have paid careful attention to their internal security practices, but still, the data that they are responsible for has been exposed," said Pankaj Parekh, chief product and strategy officer at SecurityFirst. "This is obviously not an acceptable excuse to those whose private information was exposed."
While "Monster shrugs its sloping shoulders," European regulators might not be so blaise about the leak, Lucy Security CEO Colin Bastable said. "Of course, Monster’s Ts and Cs – terms and conditions – may leave them without liability. Let’s see how the EU treats this."
The information exposed included work history, phone numbers, email addresses and home addresses on resumes submitted between 2014 and 2017.
"The exposed resumes give cybercriminals more than enough data to commit phishing attacks and effective impersonation attempts, which can lead to account takeover, identity theft and other scams," said Goldstein. "And the fact that criminals know these individuals are on the job hunt means their social engineering attacks can be highly tailored and therefore all the more convincing to their victims."
He contended that "Monster may not have been required to notify regulators in this specific situation," but an organisation’s "best practices (and in some cases GDPR regulations) dictate that companies notify the customers impacted by a breach."
Users continue to get the short end of the stick and Bastable suggests maybe it’s time for the data-sharing model to change. "Why would anyone trust any business with their data when it is being pimped out like this?" said Bastable. "At least give people a slice of the action when you sell their data."
source scmagazineuk
Industry: Cyber Security

Latest Jobs
-
- IAM developer - Saviynt
- United Kingdom
- Upto £60,000 plus benefits
-
IAM developer/ Consultant is required for a global consultancy who are looking to expand their deployment team within the UK Looking for a IAM developer who has experience with at least one of the following vendors Saviynt, Clearskye, Beyond Trust or Okta You will be part of a deployment team, involved in a number of high profile projects Key duties will be: implement IAM solutions to ensure secure access to applications, systems, and data for authorized users. This may involve integrating technologies and standards such as SAML, OAuth, LDAP, and RBAC. Conduct IAM audits and assessments: to identify vulnerabilities, gaps, and areas for improvement. Provide IAM support and troubleshooting and resolve incidents related to user access, authentication, and authorization.
-
- Lead Cyber Security Incident Response Consultant.
- United Kingdom
- N/A
-
Seeking skilled and passionate UK-based individual for a Lead Cyber Security Incident Response Consultant opportunity 3 core skillsets for the role Hands on technical incident response (triage and planning). Business consultancy (engaging with clients). Commercial awareness. Being able to engage in business growth conversations. Consultancy experience is an essential as it the ability to visit clients and the office. Additional experience will include, but not be limited to: Developing incident response strategies, guides and procedures for effective incident handling Proactive and reactive defense plans based on cyber threat actors' techniques Offering guidance, supervision, and fostering opportunities for team development Significant career development opportunities for the right individuals.
-
- OUTSIDE IR35 Contract- Functional tester- SC clearance Microsoft Windows Server
- London
- Outside IR35 contract
-
Front End Functional tester with SC clearance needed for an Outside IR35 project. Current valid SC clearance is required Experience with functional testing with exchange, sharepoint, SQL and other applications relating across a windows server Migration to 2019. Must be able to get to Central London 3 days a week. Jira, Wiki documentation and automation experience highly desirable.
-
- ForgeRock Consultant- UK
- United Kingdom
- Upto £100,000 plus benefits
-
ForgeRock Consultant/ Architect is require for niche consultancy who are looking to expand their presence within the UK/European Market Looking for a lead IAM architect, ideally with ForgeRock experience but would consider other vendors, But looking for someone who is able to advice and consultant with Clients but have the implementation background so they can get involved in projects as and when needed. Key duties will be: Provider IAM consultancy to clients, with a focus on ForgeRock Product stack ·Responsible for the design and implementation of ForgeRock solutions ·Install and configure ForgeRock stack to meet customer authentication and authorization requirements, ·Design and implement OAuth2 protocol using ForgeRock OpenAM, ·Design and develop OpenAM custom authentication modules, ·Configure ForgeRock stack to protect RESTful API, ·Troubleshoot and support ForgeRock IAM stack. This is a great role to join a niche play as they look to kick of their European expansion