Talentsconnect data leak: 5M+ job listings, including Fortune 500 companies, exposed
The exposed data includes references to Siemens, Deutsche Bank, Vodafone, BASF, and EY.

Image by Cybernews.
- An unprotected database exposed nearly 11GB of live recruitment data from German HR tech company Talentsconnect, affecting 843 companies.
- Researchers found 335 live credentials in plaintext, granting access to platforms like SmartRecruiters, Workday, and SAP SuccessFactors.
- The leak exposed job applicants' names, emails, phone numbers, salary expectations, and CVs from over 5 million job listings.
- Exposed AWS Secrets Manager references pointed toward vaults for Siemens, Vodafone, Hornbach, ARAG, and other major companies.
Key Takeaways by nexos.ai, reviewed by Cybernews staff.
A completely unprotected database, with recruiting information from nearly 900 companies, including major brands, was left exposed. More worryingly, exposed data included live credentials for companies’ HR platforms, severely increasing what attackers could do with it.
In late June, our research team identified a public database without authentication that granted anyone full read and write access to several gigabytes of data. According to the team, the exposed data belonged to Talentsconnect, a German HR tech company.
The Hamburg-based company specializes in direct-to-talent (D2T) matching platforms, which connect job seekers and employers. In essence, Talentsconnect sits in the middle of the hiring process. For example, a company posts a job offer on its hiring system, and Talentsconnect solutions would take the ads and send them to places where users can apply.
Meanwhile, the Cybernews research team discovered that the exposed database allowed access to nearly 11GB of live recruitment data, belonging to 843 companies. Additionally, researchers found hundreds of credentials from tens of companies, presumably revealing their access to the platform.
Talentsconnect closed the database after researchers disclosed the issue to the company, and the information is no longer publicly accessible. We have reached out to the company for a statement and will update this article once we receive a reply.
Our researchers found no evidence that unauthorized users accessed the data while it was still leaking. However, threat actors monitor the web for exactly these types of exposed databases and don’t always leave an easily identifiable trail of evidence.
According to the researchers, the database was still receiving live production events one week before discovery, meaning it was most likely not a dormant test system.
“This is a single point of failure sitting behind the hiring pipelines of hundreds of major European employers. Anyone on the internet could have read the entire client roster, harvested candidate personal data, or, because access was read/write, altered or injected data. For example, posting fake job ads under real company names, submitting fraudulent applications with malicious attachments, or deleting listings,” our researchers explained.
Inside the Talentsconnect data leak
The exposed data was sitting on a MongoDB database hosted by the French cloud services provider OVH. Businesses often utilize MongoDB to organize large volumes of constantly updating, real-time data. Users sometimes misconfigure the database, inadvertently leaving the data stored there unprotected.
According to our researchers, the database contained over 5 million job listings from major DAX and Fortune 500 companies. The database also included information on job applicants, exposing their:
- Names
- Emails
- Phone numbers
- Salary expectations
- Base64-encoded CVs/cover letters
However, much more dangerous were the findings revealing 335 live credentials stored in plaintext across 56 client integrations.
For example, one of the credentials belonged to Remondis, a large multinational waste management company. According to the team, the Talentsconnect database contained username and password information, likely allowing it to connect to Remondis' recruitment portal. At least in theory, threat actors could post fake job ads on the company’s recruitment site.
“What makes matters worse is that the exposed third-party credentials extend the blast radius well beyond Talentsconnect itself, potentially into the applicant-tracking systems (ATS) environments of its clients,” researchers explained.
The team identified 80 plaintext credentials for FFG Prescreen, a background-check and screening tool used in hiring. Credentials are meant to enable candidates, for example, to modify information they submitted. However, malicious actors could potentially use the same access to post fake job ads, modify details, or delete data entirely.
Other exposed credentials seemingly granted access to the SmartRecruiters, Workday, and SAP SuccessFactors platforms, which are used by thousands of HR divisions worldwide. Access keys and passwords for all of them were found in the exposed database, meaning the leak wasn't confined to Talentsconnect's own system, potentially opening the door to other major platforms as well.
Moreover, the team saw at least 770 Amazon Web Services (AWS) Secrets Manager references with at least 202 distinct paths.
AWS Secrets Manager is Amazon's secure vault service that companies use to store their real passwords and keys safely. The exposed data wasn't the actual secret values from that vault, but addresses pointing to where those secrets can be found.
Malicious actors would value this type of data as it narrows down where to target if, for example, cybercrooks want to get their hands on a Fortune 500 company's AWS Secrets Manager secure vault.
Check if your data has been leaked
For example, the exposed data contained AWS Secrets Manager references for such companies as Siemens, Vantage Towers (Vodafone), Hornbach, ARAG, Computacenter, Peek & Cloppenburg, and UniCredit.
“For the general public, the data leak means the personal data of job applicants was left unprotected. Meanwhile, for the industry, it highlights the systemic third-party risk of recruitment middleware: one insecure vendor exposes the data and vendor relationships of 843 organizations at once,” the team explained.
Third-party attacks wreak havoc
Third-party attacks can often be as harmful, if not more, than a direct hit on the company.
For example, last year, attackers managed to force Jaguar Land Rover (JLR) to halt its production lines, costing the British manufacturer millions. Reportedly, the attacker leveraged third-party services to acquire legit logins.
More recently, a data breach at CEVA Logistics, a global supply chain company, exposed the details of organizations such as Dutch football club Ajax, the global financial institution ING, and the optician chain Ace & Tate.
Other notable third-party attacks that cost companies millions were the MOVEit attack, after the Cl0p ransomware cartel exploited a zero-day bug to access files on a popular file storage platform, and a wave of ShinyHunters’ Salesforce attacks.
Disclosure timeline
- Leak discovered: June 24th, 2026
- Initial disclosure: July 10, 2026
- Leak observed closed: July 16th, 2026