Job Site Ladders Exposes 13.7 Million User Records in Security Lapse
A popular recruitment platform for high-paying jobs leaves a massive database unprotected, exposing sensitive user details and employment histories. The company secures the data shortly after receiving a media inquiry.
Job recruitment site Ladders exposes more than 13.7 million user records after leaving an Amazon-hosted Elasticsearch database without a password. Security researcher Sanyam Jain discovers the unprotected database and reports it to TechCrunch, prompting Ladders to pull the data offline within an hour of being contacted.
The exposed records contain highly sensitive information, including names, email addresses, phone numbers, and detailed employment histories. Many user profiles also reveal current compensation, work authorizations like H1-B visas, and U.S. security clearances tied to specific jobs in telecoms or the military.
Ladders chief executive Marc Cenedella confirms the exposure but insists their AWS-managed system remains secure and accessible only by employees. TechCrunch verifies the leaked data by contacting affected users, with at least one individual confirming they plan to stop using the service entirely as a result of this incident.