Jump to content
  • A UK recruitment firm exposed sensitive applicants data for months


    mood

    • 529 views
    • 3 minutes
     Share


    • 529 views
    • 3 minutes

    A UK recruitment firm exposed sensitive applicants data for months

     

    The company was informed about the exposed data in December 2020 but it only responded and secured the data in March 2021.

     

    FastTrack Reflex Recruitment firm recently joined the ranks of other companies that have been affected by data leaks due to misconfigured AWS S3 buckets. This data breach majorly affected the applicants whose CVs containing personal information were leaked, reports the research team at Website Planet.

     

    Attached to numerous CVs were the personal IDs of applicants, including passports, citizen ID cards, driver’s licenses, and skilled worker IDs. All of these constitute direct and indirect applicant PII. Examples of directly identifiable PII include the following:

    • Full names
    • Email addresses
    • Home addresses
    • Dates of birth
    • Passport numbers
    • Applicant photos
    • Mobile phone numbers
    • Social network URLs for some applicants.

     

    It is worth noting that the configuration of the server is not the responsibility of Amazon but rather the company, FastTrack, that is using it as a public cloud storage resource.

     

    uk-recruitment-firm-exposed-sensitive-ap

    Example of leaked data (Image: Website Planet)

     

    The bucket, according to Website Planet’s blog post, included 21,000 client files (including duplicates), equating to 5GB of data, which were left unprotected for any hacker or cyber criminal with a malicious intent to take advantage of.

    Moreover, tens of thousands of people could be affected by this. As a result of this exposure, FastTrack could receive legislative action from GDPR and the UK’s Data Protection Act 2018. 

     

    The clients could be affected through various criminal acts if cybercriminals found this unprotected database. These include identity theft, fraud, scams, phishing, malware, theft, and account takeover.

     

    The company, on the other hand, will be affected due to their failure to adhere to data privacy laws such as GDPR which could fine it around €20 million, or 4% of the company in question’s annual turnover (whichever is higher).

     

    Additionally, they could possibly face a loss of business due to their existing customers losing trust in their firm and their potential new applicants being driven away. 

     

    The data breach was first discovered on 29th December 2020 by the Website Planet research team and the company was contacted on 15th and 17th January 2021 but they only replied on 17th March, after several attempts of contacting them, and the bucket was secured on 23rd March 2021. 

     

     

    Source: A UK recruitment firm exposed sensitive applicants data for months


    User Feedback

    Recommended Comments

    There are no comments to display.



    Join the conversation

    You can post now and register later. If you have an account, sign in now to post with your account.
    Note: Your post will require moderator approval before it will be visible.

    Guest
    Add a comment...

    ×   Pasted as rich text.   Paste as plain text instead

      Only 75 emoji are allowed.

    ×   Your link has been automatically embedded.   Display as a link instead

    ×   Your previous content has been restored.   Clear editor

    ×   You cannot paste images directly. Upload or insert images from URL.


  • Recently Browsing   0 members

    • No registered users viewing this page.
×
×
  • Create New...