[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f2qruwzpkn0r6u":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":7,"domain":9,"breachDate":10,"addedDate":11,"modifiedDate":12,"contentUpdatedAt":13,"source":14,"sourceUrl":15,"sourceUrls":16,"pwnCount":17,"affectedCount":17,"affectedCountStatus":18,"affectedCountLowerBound":19,"affectedCountUnit":20,"hasEnglishDescription":4,"severity":21,"dataClasses":22,"description":27,"seoTitle":28,"seoTitleEn":29,"seoDescription":28,"seoDescriptionEn":30,"logoUrl":31,"isVerified":4,"isSensitive":32,"isSpamList":32,"isMalware":32,"company":33},"68e3266eda11adda48825138","catho","Catho Data Breach","catho.com.br","2020-03-01T00:00:00.000Z","2020-08-18T22:52:39.000Z","2026-07-09T18:02:18.224Z","2026-07-18T23:47:11.661Z","Third party breach","https:\u002F\u002Fsynscan.net\u002Fbreaches\u002Fcatho",[15],1173012,"known",null,"unknown","Critical",[23,24,25,26],"Email addresses","Names","Passwords","Usernames","\u003Cp>The Catho data breach is a significant security incident linked to the unauthorized access to account information of the Brazil-based job posting and recruitment platform around March 2020. It is stated that the publicly disclosed verified dataset contains approximately 11 million records, but the number of affected accounts calculated based on unique email addresses is 1,173,012. This distinction is important; the total number of records should not be directly interpreted as the number of unique individuals, as the same person may appear in multiple rows, there may be duplicate records, or different objects within the platform may be present in the same dataset.\u003C\u002Fp>\n\u003Cp>The primary types of data confirmed in this incident are email addresses, names, usernames, and plaintext passwords. Since Catho is a service focused on job searching and recruitment, the post-attack risk is not limited to account takeover attempts. Name and email information that can be associated with users' professional identities could be used in targeted fraud scenarios prepared with convincing job offers, fake interviews, payment requests, or account verification pretexts. Therefore, the record should be evaluated not only as a technical password leak but also as a social engineering risk that could target individuals' career and job search context.\u003C\u002Fp>\n\u003Ch2>Leaked Data Types and Risks\u003C\u002Fh2>\n\u003Cp>Verified data classes consist of email addresses, names, usernames, and passwords. The most critical field is password information, because plaintext passwords can be tried on other services without any additional cracking process. If a user has used the same or similar password on different accounts, a single leak can create a chain risk across email accounts, social media profiles, job search accounts, financial services, or internal company systems. Email addresses and usernames, on the other hand, give attackers the opportunity to find accounts, perform automated login attempts, and target password reset flows.\u003C\u002Fp>\n\u003Cp>Name information alone may not seem to have a high level of confidentiality; however, when combined with an email address and username, it provides sufficient context to generate personalized messages. Users of job posting platforms, in particular, are naturally more sensitive to topics such as job offers, resume updates, company invitations, or interview scheduling. Therefore, leaked fields can be used for targeted phishing, fake job announcements, application forms containing malicious files, and links disguised as account verifications. The risk is increased by passwords being in plain text because the attacker can also directly see which password the user prefers.\u003C\u002Fp>\n\u003Ch2>Verified Scope and Boundaries\u003C\u002Fh2>\n\u003Cp>The number of affected accounts verified for this record is 1,173,012 unique email addresses. It is also noted that the data set associated with the incident contains approximately 11 million records; however, this large number should not be interpreted as the number of unique users. In publicly confirmed validations, the leaked fields have been listed as name, username, email address, and plaintext password. Since there is no equally verified evidence for fields such as phone number, physical address, identification number, payment card, bank information, or resume content, this record does not include such data classes.\u003C\u002Fp>\n\u003Cp>The incident date has been marked as approximately March 2020. It has been reported that the dataset was later put up for sale along with other violations. This timeline indicates that the leak may not have been immediately noticed by users and that passwords could have been tried by third parties for a long time. Therefore, even if the Catho account was later closed, the risk remains if the same password was used on other accounts. In the scope assessment, the distinction between repeated rows and unique email count should be maintained, and the user should not be conveyed an impact that is larger or unverified.\u003C\u002Fp>\n\u003Ch2>User Groups at Risk\u003C\u002Fh2>\n\u003Cp>The highest risk group consists of individuals who have created an account on Catho and have used the same password on other services. For these users, the likelihood of account takeover is higher compared to other breaches because the attacker directly has a password that can be tried. Users in the job search process may also be more susceptible to fake recruitment messages, as it is not always easy to distinguish between a genuine career opportunity and a malicious link. When name, email, and platform context come together, messages can appear more personal and convincing.\u003C\u002Fp>\n\u003Cp>The second risk group consists of people who use the email address from their Catho account as their work email, school account, or a personal account that has been used for a long time. Such addresses can be linked to social circles, work history, and other online accounts. The leakage of the username can also lead to searching for the same nickname on different platforms. From the perspective of corporate security teams, the risk increases if employees use passwords similar to those on their personal job search accounts for corporate accounts. Therefore, it is necessary to review not only the Catho account but also all accounts associated with the same credentials.\u003C\u002Fp>\n\u003Ch2>Urgent Measures to Be Taken\u003C\u002Fh2>\n\u003Cp>The password used for the Catho account should no longer be considered secure. The user should first set unique and strong passwords on Catho, and then for all accounts where the same or a similar password has been used. If it is not remembered whether the same password has been used in multiple places, email accounts, social media accounts, job search sites, cloud storage services, and financial accounts should be checked first. Using a password manager makes it easier to create different and long passwords for each service.\u003C\u002Fp>\n\u003Cp>Multi-factor authentication should be enabled on the email account, and recent logins and connected applications should be reviewed. Suspicious sessions should be closed, and unknown forwarding rules, recovery emails, and phone numbers should be removed. Attachments and links in messages received in the context of Catho or job searching should be examined carefully. Job offers that require payment, forms requesting personal documents, messages promising quick hiring, and pages asking for passwords under the pretext of account verification should be considered high risk.\u003C\u002Fp>\n\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\n\u003Cp>This incident shows that the accounts used on job search platforms also carry high-value identity information. In the long term, using a different password for each platform should be the basic rule. Users can limit risks by choosing a separate address instead of a public email for recruitment and career accounts. Old job search accounts should be checked regularly, unused accounts should be closed, and information that does not need to be kept on the profile should be removed. In this way, the amount of data that could be exposed in a future incident is reduced.\u003C\u002Fp>\n\u003Cp>From the perspective of companies, it should be clearly explained in employee awareness training that reusing passwords from personal accounts can create corporate risks. Multi-factor authentication, suspicious login monitoring, policies that reduce password reuse, and controls that increase phishing resilience should be implemented on corporate accounts. Even if users cannot be prevented from using the same password pattern on personal and work accounts, early warning and rapid password change processes can reduce damage. Fraud messages in the context of job searching should also be included in the monitoring scenarios of security teams.\u003C\u002Fp>\n\u003Ch2>Record Control and User Action\u003C\u002Fh2>\n\u003Cp>The match seen in this record indicates that the relevant email address is included in the unique email list associated with the Catho data breach. A match does not mean that all of the user's accounts have been compromised; however, it should be assumed that the leaked password may have been tried on other services. The priority is to change accounts that use the same or similar password and to strengthen the security of the email account. Other accounts are not considered secure until the email account is protected, because password reset links usually come to the email.\u003C\u002Fp>\n\u003Cp>Users should check old messages, password records, and accounts they used during the same period associated with Catho. Suspicious login alerts, unexpected password reset emails, or links that appear to be job offers should be taken seriously. Although the verified scope of this incident is limited, its impact could be lasting due to the inclusion of plaintext passwords. The safest approach is to ensure that the leaked password is no longer used anywhere, enable multi-factor authentication, and exercise greater caution with job-search-themed messages.\u003C\u002Fp>","","Catho Data Breach (1.2 Million Reported Records)","Catho Data Breach. 1.2 Million reported records were reported. Reported data: Email addresses, Names, Passwords. Review the scope, risks, and protective steps.","\u002Fuploads\u002Flogo\u002Fcatho_com_br.webp",false,{"name":34,"sector":35,"country":36,"website":9,"websiteArchiveUrl":28,"websiteStatus":28,"websiteCheckedAt":19},"Catho","Online recruitment platform","Brazil"]