TechForge

November 15, 2024

Share this story:

Tags:

Categories::

  • Database exposed sensitive data of 200,000 job seekers.
  • Data leak risks high-value phishing and job-offer scams.

Jeremiah Fowler, a cybersecurity researcher, recently discovered something all too common: open, public-facing files containing personal information. In this instance, the data was details of over 200,000 job-seekers in the tech industry.

Fowler tipped off Website Planet about his discovery, saying that the data seemed to be tied to Alltech Consulting Services, a company recognised for connecting global tech talent with employers in the United States and Canada.

The unprotected database held over 2.3 million records, with a specific folder labelled “Documents” containing details on around 216,000 job seekers. The files listed names, phone numbers, emails, partial-redacted Social Security numbers, passport numbers, visa statuses, and notes on individuals’ previous work experience, skills, and the roles they were seeking.

Fowler managed to trace the database to Alltech Consulting Services, a New Jersey-based company. After his discover, Fowler quickly sent notice to the company and the database was removed in 24 hours. However, he personally didn’t get any message from Alltech, leaving questions about whether the company or a third-party provider were behind the mismanagement of the data. It’s also unclear how long the information was exposed or if anyone else accessed it – answers that would require a forensic investigation.

It wasn’t just job seekers whose details were open; some records also listed employer info, including company names, emails, and phone numbers. Plus, many files mentioned H-1B visas, a type that allows US companies to employ foreign talent in fields like IT and engineering. If cybercriminals had got hold of this detailed data, it could easily be used in targeted attacks.

It’s no secret that tech professionals are valuable targets. Demand for tech talent as soaring – around 377,500 job openings are expected annually through to 2032 – and salaries often top $100,000, so scammers have plenty of incentive. Exposing passport numbers or partial SSNs could be the first puzzle pieces a dedicated criminal would need for full identity theft. With more information on hand, they could launch phishing scams to trick individuals into sharing more sensitive details. Fowler stressed he’s not saying Alltech’s clients are at risk, just that employment scams are a very real issue these days.

Scams involving fake job offers have become a big deal in recent years. According to the FTC, job scams are up 110% in 2023, costing an estimated $737 million in the United States between 2019 and 2023. The schemes cost victims an average of $12,000 each, and regrettably, there is no easy fix.

Fowler advises job seekers to be aware of any recruiter or organisation that asks for upfront fees, credit card details, or sensitive data like Social Security numbers or passport information. The message is to do your homework on the agency and any company offering a position. If something sounds way too good to be true, it probably is.

Interestingly, a large number of people in this database were H-1B visa holders, who might be at additional risk. Since H-1B visas require sponsorship, scammers offering fake jobs with promises of visa help could more easily trick people into giving up personal info or paying fees. Criminals might even impersonate officials or immigration attorneys, making it seem like they’re helping with visa issues, for instance.

This whole incident highlights why data security is so crucial, especially with sensitive personal info left in the open by agencies and emplogers. In the wrong hands, such data could be a goldmine for scammers attempting to abuse high-value targets.

Though the database in question has since been blocked from public access, it is unclear how long it was in the open or whether others accessed it. Fowler suggests companies storing large amounts of data should lock down access controls and run regular security tests to stay ahead of breaches. Updating systems, plugins, and software is another key step to avoid these exposures.

Fowler wasn’t pointing a finger at Alltech or its partners specifically. He shared his discoveries for educational purposes and to urge similar parties to monitor their own security methods.

As an ethical researcher, Fowler does not download any data he finds and instead only takes a few screenshots for verification. Only a forensic investigation could reveal the full details of this exposure, and his role ended at identifying issues and notifying those involved. His goal, and that of others in the security community is simple: to raise awareness about data security and privacy risks that could affect anyone.

Author

  • As a tech journalist, Zul focuses on topics including cloud computing, cybersecurity, and disruptive technology in the enterprise industry. He has expertise in moderating webinars and presenting content on video, in addition to having a background in networking technology.

    View all posts

About the Author

Muhammad Zulhusni

As a tech journalist, Zul focuses on topics including cloud computing, cybersecurity, and disruptive technology in the enterprise industry. He has expertise in moderating webinars and presenting content on video, in addition to having a background in networking technology.

Related

August 24, 2026

August 11, 2026

August 10, 2026

August 5, 2026

Join our Community

Subscribe now to get all our premium content and latest tech news delivered straight to your inbox

Popular

12371 view(s)
11427 view(s)
7693 view(s)
5372 view(s)

Subscribe

All our premium content and latest tech news delivered straight to your inbox

This field is for validation purposes and should be left unchanged.
Name(Required)