Job applications leaked: what it means and what to do

Risk level: medium. Can you change it: no. Found in 6 breaches in this directory.

What this data is

Applications you sent through job sites or employer portals: CVs, cover letters, work history, education, referees, salary expectations and sometimes right to work documents, ID scans or background check consent forms.

The risk on its own

A CV is a detailed biography: full name, address, phone, email, employers, dates, qualifications and often your referees' contact details. On its own it does not open accounts. It does give a fraudster most of what they need to impersonate you convincingly, and it exposes your referees too.

The risk combined with other data

If the application included ID documents, a date of birth or a tax number, treat the breach as an identity document leak. It also reveals that you were job hunting, which can cause trouble with a current employer. Scammers use the data to send fake interview invitations and job offers that ask for more personal and bank details.

How criminals use it

  • A fake recruiter contacts you about the exact role you applied for and asks for bank details and ID for onboarding.
  • Your work history and qualifications are used by someone else to apply for jobs or visas.
  • Your referees receive phishing that mentions your application by name.
  • Your current employer finds out you were applying elsewhere.

What to do now

  1. Check whether the application included ID, a date of birth or tax numbers, and if so follow the steps for leaked government IDs and consider a credit freeze.
  2. Verify any job offer by contacting the company through its official website, and never pay for training, equipment or background checks.
  3. Warn your referees that scammers may contact them.
  4. Close accounts on job sites you no longer use and delete stored CVs.
  5. Leave your full address and date of birth off future CVs. A suburb and an email address are enough.

Frequently asked questions

What should I take off my CV to stay safer?

Your full street address, date of birth, photo and any ID numbers. Employers only need those after an offer, through a verified process.

How do I spot a fake recruiter?

Warning signs include offers without an interview, messages from free email addresses, requests for payment and pressure to move to a messaging app.

Should I tell my referees?

Yes. Their names and contact details were in your application, so a short warning helps them spot scams.

Breaches that exposed this data

  • IIMJobs: 2018-12-31, 4.2M accounts, Dates of birth, Email addresses, Geographic locations, IP addresses, Job applications, Job titles
  • Ajarn: 2018-12-13, 266K accounts, Dates of birth, Education levels, Email addresses, Genders, Geographic locations, Job applications
  • europa.jobs: 2019-08-11, 226K accounts, Dates of birth, Email addresses, Geographic locations, Job applications, Names, Passwords
  • Wendy's: 2018-03-31, 52K accounts, Education levels, Email addresses, IP addresses, Job applications, Names, Passwords
  • Protemps: 2021-10-04, 50K accounts, Email addresses, Genders, Job applications, Marital statuses, Names, Nationalities
  • Switch: 2024-10-01, 5.4K accounts, Email addresses, Job applications, Names, Social media profiles

Tools that help

Related guides

Breach data sourced from Have I Been Pwned, used under CC BY 4.0. Additional breach metadata provided by XposedOrNot. DataExposed is an independent service and is not affiliated with or endorsed by either.