
Researchers identified an unprotected database in late June that granted unauthenticated access to nearly 11 gigabytes of live recruitment data belonging to Talentsconnect, a Hamburg-based human resources technology company. The exposure affected recruitment information tied to 843 companies.
Talentsconnect operates direct-to-talent matching platforms that connect job seekers with employers, positioning the company as an intermediary that distributes job postings from client hiring systems to applicants. The Cybernews research team found the database open on the internet with full read and write access available to anyone, hosted on a MongoDB database maintained by French cloud provider OVH.
The database contained more than 5 million job listings from major DAX and Fortune 500 companies, along with applicant information including names, email addresses, phone numbers, salary expectations and base64-encoded resumes and cover letters.
Researchers also found 335 live credentials stored in plaintext across 56 client integrations, along with 770 Amazon Web Services Secrets Manager references spanning at least 202 distinct paths. The AWS references did not include the actual secret values but pointed to the storage locations of company passwords and keys, information that could help narrow potential targets for further attacks. Companies whose AWS Secrets Manager references appeared in the exposed data included Siemens, Vodafone subsidiary Vantage Towers, Hornbach, ARAG, Computacenter, Peek & Cloppenburg and UniCredit.
Among the plaintext credentials, researchers identified access information for Remondis, a multinational waste management company, that appeared to allow entry to the company’s recruitment portal. The team also found 80 plaintext credentials for FFG Prescreen, a background-check and screening platform used in hiring processes. Additional exposed credentials appeared to grant access to third-party HR platforms including SmartRecruiters, Workday and SAP SuccessFactors.
Researchers said the database was still receiving live production activity one week before its discovery, indicating it was an active system rather than a dormant test environment. They found no evidence that unauthorized parties accessed the data while it remained exposed, though they noted that threat actors regularly search for this type of unsecured database and do not always leave detectable traces.
Talentsconnect closed the database after researchers disclosed the issue to the company, and the data is no longer publicly accessible.
Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543