ADVERTISEMENT

Major employment platform leaks 1.1M job seekers’ details

beWanted, one of the largest employment platforms in Europe, exposed a trove of sensitive details, revealing job seekers’ personal information.

beWanted data leak

Image by Cybernews.

Vilius Petkauskas
Vilius Petkauskas Deputy Editor
May 1, 2025 Updated: May 15, 2025 2 min read
Ernestas Naprys Paulina Okunyte Gintaras Radauskas Jurgita Lapienyte
Be the first to know and get our latest stories on Google News
Add us as your Preferred Source on Google.

What data beWanted leaked?

  • Full names and surnames
  • Phone numbers
  • Email addresses
  • Home addresses
  • Dates of birth
  • National ID numbers
  • Nationalities
  • Places of birth
  • Social media links
  • Employment history
  • Educational background
ADVERTISEMENT
“This exposure creates multiple attack vectors, enabling cybercriminals to engage in identity theft, where personal information can be used to create synthetic identities or fraudulent accounts.”
  • Restrict Public Access. Remove any public permissions on the bucket. Enable Public Access Prevention to ensure the bucket is not accessible by unauthorized users.
  • Implement Access Controls. Assign permissions only to authorized users and services based on their specific needs. Follow the Principle of Least Privilege to minimize access.
  • Monitor Access Activity. Enable Cloud Audit Logs to track all access to the bucket. Configure alerts through Cloud Monitoring to detect and respond to suspicious activity.
  • Enable Data Encryption. Activate server-side encryption to protect data at rest. Utilize Google Cloud Key Management Service (KMS) for secure key management.
  • Enforce Secure Data Transmission. Require the use of SSL/TLS for all data transfers to and from the bucket. Block any non-secure (HTTP) connections.
  • Adopt Security Best Practices: Conduct regular security audits and reviews of permissions and configurations. Use Google Cloud Security Command Center for automated security assessments.

  • Leak discovered: November 12th, 2024
  • Initial disclosure: November 28th, 2024
  • CERT contacted: February 3rd, 2025
  • Leak closed: May 8th, 2025
ADVERTISEMENT