Talentsconnect Data Leak Exposes 5M+ Job Listings From Major Companies

Talentsconnect Data Leak Exposes 5M+ Job Listings From Major Companies

A Talentsconnect data leak left recruitment records and company credentials publicly accessible. Here’s what job seekers should know about the leaked information and how to reduce phishing and account risks.

What Happened in the Talentsconnect Data Leak?

According to Cybernews, Talentsconnect — a German HR technology company — had an unprotected database containing nearly 11GB of recruitment data.

Researchers discovered the database on June 24, 2026. It required no login, meaning anyone online could read or change its contents.

The data came from 843 companies that used Talentsconnect services to manage and distribute job listings. Cybernews notified Talentsconnect on July 10, and researchers confirmed the database was no longer publicly accessible by July 16.

There is currently no evidence that criminals accessed the information while it was available. However, unauthorized access can be difficult to detect.

Data leaks like this can create risks long after the information is secured. Personal details may be used in phishing emails, fake recruiter messages, or other scams that appear more convincing.

Your information may also have appeared in other leaks without you realizing it. If you are unsure whether your data has been leaked somewhere online, automatic monitoring can help you spot problems earlier.

Futureproof monitors your data for leaks 24/7 and helps you reduce scam risks with simple, clear steps.

Who Was Affected and What Data Was Leaked?

The database contained more than 5 million job listings, including listings connected to major European and Fortune 500 companies.

It also contained personal information belonging to job applicants, including:

  • names
  • email addresses
  • phone numbers
  • salary expectations
  • CVs and cover letters

Some CVs and cover letters were Base64-encoded. This changes how information looks but does not securely encrypt or protect it.

Cybernews did not report how many individual job applicants had information in the database. The 5 million figure refers to job listings, not people.

Researchers also found 335 active login credentials stored as readable text across 56 company integrations.

Some credentials were connected to recruiting platforms such as SmartRecruiters, Workday, SAP SuccessFactors, and FFG Prescreen.

Researchers also found hundreds of references pointing toward AWS Secrets Manager locations used by several companies. These were locations of stored secrets, rather than the passwords themselves.

For job seekers, information like your email, phone number, CV, and employment interests can help criminals create more convincing messages.

For example, a fake recruiter could mention a company or position you recognize, making a phishing email harder to spot.

How the Talentsconnect Database Was Left Unprotected

The information was stored in a MongoDB database hosted by cloud provider OVH.

MongoDB is software companies use to organize and manage large amounts of information.

According to Cybernews, the database had no authentication, meaning a password or other login was not required to access it.

Researchers could also read and change information in the database.

Talentsconnect has not publicly explained exactly why those security protections were missing.

However, the incident involved an improperly protected database rather than a confirmed break-in by hackers. That makes this a data leak, not a confirmed data breach.

Check if your data is safe from scammers

Futureproof scans your data for leaks and shows exactly how to close security gaps — before scammers find them first.

Check my safety

Why Job Seekers Should Pay Attention

Recruitment information gives scammers useful context.

If someone knows your name, email, work history, and the types of jobs you seek, they can create convincing recruiter messages.

The company credentials found in the database created another concern. In some cases, they could potentially allow someone to interfere with legitimate recruitment systems.

Researchers said this could include changing listings or creating fake job advertisements under real company names.

That means recognizing the employer’s name may no longer be enough to decide whether a job message is trustworthy.

The case also shows how information can spread beyond the company where you originally provided it. One recruitment provider handled data connected to 843 organizations.