
A misconfigured Amazon S3 storage bucket belonging to HireClick, a U.S.-based recruitment platform serving small and mid-sized businesses, has led to one of the most significant leaks of job applicant data to date. The unsecured bucket, which contained over 5.7 million files, was publicly accessible and exposed sensitive personal information of millions of job seekers across the United States.
Cybernews researchers discovered the breach, tracing it back to HireClick’s cloud infrastructure. The exposed files, largely comprised of resumes, included full names, email addresses, phone numbers, physical addresses, and other personal details often found in employment applications. The open configuration of the bucket meant that anyone with internet access could retrieve the data without authentication or special tools.
Despite multiple contact attempts by researchers, HireClick has yet to respond or issue a public statement, raising concerns over the company’s incident response and regulatory compliance. As of this report, affected individuals have not been notified of the breach, potentially leaving them vulnerable to identity theft, impersonation scams, and targeted online harassment for an extended period.
Resumes are a rich source of information for threat actors. In addition to basic contact details, they frequently include employment histories, educational backgrounds, and references. Cybersecurity experts warn that this data can be used in social engineering attacks, such as phishing or smishing campaigns that mimic legitimate recruitment communications. Attackers may pose as employers or HR personnel, tricking victims into providing further sensitive documents like government IDs or financial information.
The potential for abuse extends beyond financial fraud. The availability of detailed personal profiles could also lead to doxxing—where individuals are targeted and harassed using their own exposed data. For many job seekers, especially those in vulnerable communities, the psychological and reputational risks are substantial.
This incident follows a troubling pattern of similar breaches across the global recruitment sector. In recent years, Cybernews has reported on misconfigured data exposures involving platforms such as Foh&Boh, which services brands like KFC and Hyatt; Valley News Live, a North Dakota-based job listing provider; European job platform beWanted; and Singapore-based Snaphunt. Each case underscores a systemic failure to secure sensitive applicant data and implement adequate privacy safeguards.
Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543