Massive Data Breach: German HR Firm Exposes 11GB of Recruitment Data for Fortune 500 Companies

August 12, 2026
Massive Data Breach: German HR Firm Exposes 11GB of Recruitment Data for Fortune 500 Companies
  • Talentsconnect, a German HR tech company, exposed a public MongoDB database housing nearly 11GB of live recruitment data for 843 companies, including DAX and Fortune 500 firms, until it was shut down after disclosure in July 2026.

  • The breach heightened third-party risk, as compromised credentials and gaps in vendor integrations could enable attackers to post fake job ads, modify listings, or access multiple organizations’ systems through trusted vendors.

  • There were about 770 AWS Secrets Manager references across 202 distinct paths, indicating vaults used by major firms; these references identify where secrets reside and raise risk if exploited.

  • Researchers found 335 live plaintext credentials linked to 56 client integrations, potentially allowing access to third-party HR platforms such as SmartRecruiters, Workday, and SAP SuccessFactors, as well as individual recruitment portals.

  • The exposed data included information on more than 5 million job listings and personal applicant details like names, emails, phone numbers, salary expectations, and base64-encoded CVs or cover letters.

  • The incident highlights the vulnerability of recruitment middleware and the potential blast radius when a single insecure vendor exposes data for hundreds of clients, reflecting a broader pattern of third-party service breaches.

  • Disclosure timeline: the leak was detected on June 24, 2026; first disclosed on July 10, 2026; the database was taken offline by July 16, 2026.

Summary based on 1 source


Get a daily email with more Tech stories

More Stories