[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f14qfkj34f68ke":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"publishedAt":12,"modifiedDate":13,"contentUpdatedAt":12,"source":14,"sourceUrl":15,"sourceUrls":16,"pwnCount":21,"affectedCount":21,"affectedCountStatus":22,"affectedCountLowerBound":21,"affectedCountUnit":23,"hasEnglishDescription":4,"contentLocale":24,"availableLocales":25,"translations":27,"severity":30,"dataClasses":31,"description":44,"seoTitle":8,"seoDescription":45,"logoUrl":46,"isVerified":47,"isSensitive":4,"isSpamList":47,"isMalware":47,"company":48},"a47202bf3963d2965d217249","HeadHunter","HeadHunter (hh.ru) 2018 Associated Resume Dataset","headhunter-hh-ru-2018","hh.ru","2018-01-01T00:00:00.000Z","2026-08-31T16:40:38.738Z","2026-09-17T19:37:16.459Z","Sealed third-party CSV archive with public breach-directory and first-party service context","https:\u002F\u002Fbreachera.com\u002F",[15,17,18,19,20],"https:\u002F\u002Fleakedsource.com\u002Fbreaches?search=HeadHunter","https:\u002F\u002Fwww.vedomosti.ru\u002Ftechnology\u002Farticles\u002F2018\u002F05\u002F04\u002F768503-headhunter-sude","https:\u002F\u002Ffeedback.hh.ru\u002Fknowledge-base\u002Farticle\u002F1333","https:\u002F\u002Fdata-wells.niamonx.io\u002FBreach\u002FHeadHunter",564552,"lower_bound","email_identifiers","en",[24,26],"tr",{"en":28,"tr":29},{"slug":9},{"slug":9},"High",[32,33,34,35,36,37,38,39,40,41,42,43],"Email addresses","Names","Phone numbers","Geographic locations","Dates of birth","Genders","Job titles","Employers","Education information","Salaries","Skype usernames","Resume information","\u003Cp>This entry documents a resume dataset associated with HeadHunter and \u003Ccode>hh.ru\u003C\u002Fcode> and labelled as 2018. It is not presented as a verified security intrusion. No public source reviewed here supplies a precise incident day, a complete attack method, or an operator notice that uniquely identifies this archive, so the record uses \u003Ccode>isVerified=false\u003C\u002Fcode>. January 1, 2018 is only the technical representation of a year-precision date; it does not claim that an incident occurred in January. The page preserves both the measurable connection between the sealed source and public metadata and the limits of that connection.\u003C\u002Fp>\n\u003Cp>BreachEra lists HeadHunter, the \u003Ccode>hh.ru\u003C\u002Fcode> domain, the year 2018, a scope of 827,198 records, and resume-related data classes including email addresses in one exact row. The reviewed CSV contains exactly 827,198 logical data records, while its filename carries both 2018 and a 827,199 physical-line scope. The LeakedSource directory displays 564,875 records for the same name and domain, while NiamonX and 9GHz describe about 827 thousand records. public breach source has no exact HeadHunter entry. These conflicting scopes are not promoted into a unique affected-person count, so \u003Ccode>pwnCount\u003C\u002Fcode> remains null.\u003C\u002Fp>\n\u003Cp>A Vedomosti article dated May 4, 2018 describes HeadHunter litigation concerning extraction from its resume database and third-party access to that data. The article provides context for unauthorized extraction of HeadHunter resume information in 2018, but it does not prove that this exact archive was the copy involved in the dispute or that it came from a particular security vulnerability. HeadHunter’s own help center separately explains that resume contact information includes a name, phone number, email address, and other communication channels, and that detailed contact access is a paid service. Together these sources support the entity, service, domain, and field semantics without overstating incident verification.\u003C\u002Fp>\n\u003Cp>The reviewed \u003Ccode>HeadHunter_BF.7z\u003C\u002Fcode> archive is 59,693,254 bytes and is sealed by SHA-256 \u003Ccode>e91452…ca2a\u003C\u002Fcode>. A complete \u003Ccode>7z\u003C\u002Fcode> integrity test passes. The archive contains one 501,590,148-byte CSV data member and a 441-byte generic release metadata member. The CSV has SHA-256 \u003Ccode>b4c951…3150\u003C\u002Fcode>, uses UTF-8 with a byte-order mark, a comma delimiter, and an explicit 41-column header. The generic metadata member contains no row-level email field and no at-sign, and it is closed as \u003Ccode>NO_EMAIL_FIELD\u003C\u002Fcode>.\u003C\u002Fp>\n\u003Cp>The explicit \u003Ccode>Email\u003C\u002Fcode> header is zero-based field index 6 and is the only field authorized for import. Phone, secondary phone, Skype, name, country, address, region, city, gender, date of birth, education, employment history, salary, profession, work preferences, free text, and URL fields are excluded. All 41 fields were nevertheless profiled for email-shaped whole-cell values. There are 279 such shapes outside the selected column, mostly in Skype and name fields. None is used to widen coverage or move the result toward a catalog count because those columns do not carry email-field authority.\u003C\u002Fp>\n\u003Cp>Of 827,198 data records, 591,700 have a non-empty value in the email column. The current \u003Ccode>canonical-ascii-email-v1\u003C\u002Fcode> rule accepts 590,343 occurrences, rejects 1,357 non-empty values, and excludes 235,498 blank cells. Lowercasing, trimming surrounding whitespace, and global deduplication produce 564,552 unique canonical email addresses. The final private file is 11,595,144 bytes with SHA-256 \u003Ccode>d560fc…a916\u003C\u002Fcode>, identical in two separately materialized outputs. This is not a person count: one person can use multiple addresses and an address can be shared.\u003C\u002Fp>\n\u003Cp>Three implementations support the result. A compiled extractor using Go’s standard CSV reader, a separately compiled validator using a custom byte-level RFC 4180 state machine, and Python’s strict CSV reader agree on 827,198 records, field 6 selection, 590,343 accepted occurrences, 1,357 rejected non-empty values, 235,498 blanks, and 564,552 unique canonical addresses. The compiled tools also agree on the 12,102,121-byte occurrence stream and every aggregate in the 41-field profile. Mapping-admission v3 passes with \u003Ccode>COMPLETE\u003C\u002Fcode> source coverage, no deferred member, and an explicit exclusion of all 279 off-field shapes.\u003C\u002Fp>\n\u003Cp>A live Mongo ownership comparison finds 410,683 canonical addresses already present in other incident records and 153,869 addresses absent from the global email index. The overlaps are spread across 703 breach identifiers; the largest belong to large credential compilations and broad Russian datasets. No single existing breach represents the HeadHunter set, and no prior job is bound to the HeadHunter name, domain, slug, source key, archive digest, or canonical digest. The dataset is therefore not treated as already imported under another identity, while ordinary cross-breach overlap is not mistaken for proof that a person used HeadHunter.\u003C\u002Fp>\n\u003Cp>LeakData is prepared to process only the verified email associations. It does not import names, phone numbers, addresses, birth dates, employment history, salary, education, or free-text resume content from this source. Complete archive review does not claim that the archive is a complete copy of the historical event. A match does not prove that an account was active in 2018, that every source field is current, or that the address owner supplied the record. Users should be alert to targeted recruitment phishing, messages quoting old resume details, and account-recovery fraud, and should use unique passwords and multi-factor authentication wherever available.\u003C\u002Fp>","Review the 564,552 addresses verified only from the explicit Email column in the 2018 resume dataset associated with HeadHunter and hh.ru.","\u002Fuploads\u002Flogo\u002Fhh_ru.webp",false,{"name":7,"sector":49,"country":50,"website":51,"websiteArchiveUrl":52,"websiteStatus":52,"websiteCheckedAt":53},"Recruitment","Russia","https:\u002F\u002Fhh.ru","",null]