


26 million CVs were exposed when a recruiting software firm left a misconfigured Azure container open – cybersecurity experts warn it's an easy mistake that's becoming far too common
Jul 24, 2025 am 01:53 AMSecurity researchers have discovered a misconfigured recruitment database that is leaking nearly 26 million files, with security experts warning that this kind of incident is becoming increasingly frequent.
According to a report from Cybernews, TalentHook—an online applicant tracking platform connecting HR departments with job seekers—had left an Azure Blob storage container improperly configured and publicly accessible.
As a result, the resumes of millions of U.S. citizens were exposed, including full names, email addresses, phone numbers, educational backgrounds, professional qualifications, and employment histories.
“The level of personal detail contained in these exposed resumes makes them ideal for highly targeted phishing attacks,” the Cybernews team explained.
"Email addresses and phone numbers can be exploited in phishing emails, SMS scams, or fake job offers designed to trick individuals into disclosing sensitive data such as ID scans or bank information."
Researchers warn that this data could prove valuable to cybercriminals targeting job hunters. In recent months, groups like the North Korean state-backed Lazarus group have specifically focused on jobseekers.
Earlier research this year revealed how the group has been using platforms like LinkedIn or impersonating recruiters via email and WhatsApp to lure victims.
Strengthen storage configuration practices
Tim Mackey, head of software supply chain risk at Black Duck, said this incident highlights the serious risks associated with overlooked misconfigurations and urged businesses to improve their configuration management processes.
"Misconfigured systems, VMs, containers, microservices, and databases are not new issues," he noted.
"For instance, the sample data from this breach shows masked identifiers like email addresses and mobile numbers, suggesting those fields weren't encrypted or that an insecure API may have also contributed to the leak."
Dray Agha, senior manager of security operations at Huntress, supported Mackey’s view, emphasizing that incidents like this are growing more routine.
"Misconfigured cloud storage—like the exposed Azure container in this case—remains a shockingly common and avoidable problem, especially among organizations handling sensitive personal data," said Agha.
"Organizations must carry out regular configuration audits, apply least-privilege access policies, and maintain continuous monitoring to prevent large-scale exposure of personal information."
The Cybernews team stated they have reached out to TalentHook and advised the company to adjust access settings to restrict public access and secure the container, while also updating permissions to ensure only authorized users or services can access the data.
Be sure to follow php.cn on Google News for all our latest updates, expert analysis, and reviews.
The above is the detailed content of 26 million CVs were exposed when a recruiting software firm left a misconfigured Azure container open – cybersecurity experts warn it's an easy mistake that's becoming far too common. For more information, please follow other related articles on the PHP Chinese website!

Hot AI Tools

Undress AI Tool
Undress images for free

Undresser.AI Undress
AI-powered app for creating realistic nude photos

AI Clothes Remover
Online AI tool for removing clothes from photos.

Clothoff.io
AI clothes remover

Video Face Swap
Swap faces in any video effortlessly with our completely free AI face swap tool!

Hot Article

Hot Tools

Notepad++7.3.1
Easy-to-use and free code editor

SublimeText3 Chinese version
Chinese version, very easy to use

Zend Studio 13.0.1
Powerful PHP integrated development environment

Dreamweaver CS6
Visual web development tools

SublimeText3 Mac version
God-level code editing software (SublimeText3)

Hot Topics

In what seems like yet another setback for a domain where we believed humans would always surpass machines, researchers now propose that AI comprehends emotions better than we do.Researchers have discovered that artificial intelligence demonstrates a

Artificial intelligence (AI) began as a quest to simulate the human brain.Is it now in the process of transforming the human brain's role in daily life?The Industrial Revolution reduced reliance on manual labor. As someone who researches the applicat

Like it or not, artificial intelligence has become part of daily life. Many devices — including electric razors and toothbrushes — have become AI-powered," using machine learning algorithms to track how a person uses the device, how the devi

A new artificial intelligence (AI) model has demonstrated the ability to predict major weather events more quickly and with greater precision than several of the most widely used global forecasting systems.This model, named Aurora, has been trained u

The more precisely we attempt to make AI models function, the greater their carbon emissions become — with certain prompts generating up to 50 times more carbon dioxide than others, according to a recent study.Reasoning models like Anthropic's Claude

Artificial intelligence (AI) models can threaten and blackmail humans when there’s a conflict between the model's objectives and user decisions, according to a new study.Published on 20 June, the research conducted by the AI firm Anthropic gave its l

The major concern with big tech experimenting with artificial intelligence (AI) isn't that it might dominate humanity. The real issue lies in the persistent inaccuracies of large language models (LLMs) such as Open AI's ChatGPT, Google's Gemini, and

The more advanced artificial intelligence (AI) becomes, the more it tends to "hallucinate" and provide false or inaccurate information.According to research by OpenAI, its most recent and powerful reasoning models—o3 and o4-mini—exhibited h
