Hackers give Glassdoor 172 hours to stop dump of allegedly sensitive data
Job seekers and employers may be at risk.

Image by Cybernews.
- The Gentlemen ransomware gang claims it breached Glassdoor and started a 172-hour leak countdown.
- No data samples are public, so the scale and type of exposed information remain unclear.
- Researchers warn stolen job platform data can help criminals plan phishing and company reconnaissance.
- The gang has ties to Qilin affiliates and uses double extortion against corporate targets.
Key Takeaways by nexos.ai, reviewed by Cybernews staff.
The Gentlemen ransomware gang has given Glassdoor just over a week to respond before it allegedly publishes stolen information.
Glassdoor has allegedly been targeted by the Gentlemen ransomware gang, which is threatening to publish data after a 172-hour countdown expires.
The gang has listed the employment and workplace review platform on its leak site, claiming to have breached the company and exfiltrated data. However, no samples have been released so far, leaving the scale of the alleged data breach unclear.
It is also unknown what type of data may have been affected and whether the claimed haul consists of Glassdoor's internal corporate data, employee information, job seeker information, or some combination of them all.
Glassdoor is an online platform that provides anonymous company reviews, salary data, and job listings shared by current and former employees. The platform has up to 67 million unique monthly visitors, over 2 million companies with reviews, and millions of active job listings.
Aggregated data may expose multiple companies
Targeting companies such as Glassdoor may be highly rewarding for cybercriminals.
Glassdoor and similar employment platforms sit atop a vast pool of information about companies and their workers. The platform aggregates job listings and company information, creating a picture of what businesses are doing across the market.
Its data can provide a broad view of the employment market, potentially revealing patterns across thousands of organizations. If such information were compromised, attackers could use it for reconnaissance to identify companies hiring for particular roles or undergoing workforce changes.
“Glassdoor and other similar platforms keep aggregated data from lots of companies, which could reveal general patterns of job listings and help in reconnaissance,” Cybernews researchers said.
Security-related job listings could be particularly interesting. A sudden search for cybersecurity professionals, incident responders, cloud engineers, or other specialized roles could reveal clues about a company's situation.
Security researchers and OSINT analysts have long used public job postings as a reconnaissance signal. A company that suddenly posts multiple openings for incident responders, forensics analysts, or "security operations" roles, especially with unusual urgency or vague descriptions, can inadvertently reveal that something happened internally.
“If there's any personal information present in the stolen dataset, for example, contact info, it could be used for social engineering campaigns,” researchers said.
For example, criminals could use information about a job seeker and the position they applied for to craft a convincing phishing message that appears to come from a company of interest to them.
If attackers obtained corporate email addresses or information about how particular companies structure employee accounts, they could use it to target workers with highly specific social engineering campaigns.
The alleged data could also be cross-referenced against information from previous breaches.
“Email patterns are another recon point that would allow mass social engineering campaigns targeted towards specific companies, or could be cross-referenced with other leaked data in order to find sensitive information, such as compromised employee credentials,” our researchers added.
We reached out to Glassdoor for a comment. We will update the article once response is received.
Stay updated with our latest stories and follow us on social media
Be the first to discover new stories, ideas, and updates from our team.
Who is the Gentlemen ransomware?
The gang relies on ransomware-as-a-service (RaaS) to profit. They split revenue with affiliates who use their illicit infrastructure.
Gentlemen originated as ArmCorp, a prolific affiliate cluster of the Qilin ransomware program, comprising approximately 20 members.
According to Halcyon security firm, the split between the gangs was triggered by a payment dispute on July 2nd 2025, when the threat actor known as "hastalamuerte" filed a public arbitration complaint on the RAMP underground forum, alleging that Qilin owed roughly $48,000 in unpaid commission.
The first Gentlemen ransomware sample appeared on VirusTotal on July 17th 2025. It is 5 days before the public dispute, with the leak site URL already hardcoded into the binary, indicating the separation was premeditated and already underway.
Thailand is the gang’s most targeted country with 27 victims, followed by the United States, France, and Brazil.
The gang has claimed the NATO contractor Indra, and also targeted the Dutch ice arena Thialf.
According to researchers at ASEC, South Korean cybersecurity firm AhnLab’s threat intelligence and research division, the gang’s technical sophistication suggests a coordinated team with extensive experience in enterprise-focused attacks.
“The group operates a double extortion model that involves breaching corporate networks, exfiltrating data, encrypting the data, and then using the encrypted data to extort victims,” said ASEC researchers, adding that the group was first identified in August 2025.
Job platforms have been bleeding data
Job platforms have been a jackpot for cybercriminals. This April, a hacker claimed to be selling 22 million user records from gig-economy platform Paidwork on an underground forum.
Some platforms seem to shoot themselves in the foot without external attackers breaching their systems. For example, McDonald's hiring chatbot platform was protected by the default password "123456," exposing 64 million job applications.
Cybernews in-house research showed that German HR tech firm Talentsconnect left an unprotected database exposing nearly 11GB of live recruitment data tied to 843 companies, including over 5 million job listings with applicants' names, emails, phone numbers, and CVs.
Even more alarming, researchers found 335 plaintext credentials granting access to major HR platforms like Workday, SAP SuccessFactors, and SmartRecruiters, plus references to AWS secret vaults for companies like Siemens and Vodafone.
Another recruiting platform, TalentHook, left a misconfigured system at this recruiting software maker, exposing nearly 26 million resumes containing job seekers' personal details.
LiveCareer’s resume-building platform leaked over 5 million resumes, putting job seekers at risk of identity theft and scams. HireClick left 5.7 million files containing resumes exposed online, offering scammers job seekers' private data.
And beWanted, a European job platform, leaked 1.1 million resumes with names, IDs, and addresses, despite being notified months earlier.