[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fdzo5mg66ju5d":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"modifiedDate":13,"contentUpdatedAt":13,"source":14,"sourceUrl":15,"sourceUrls":16,"pwnCount":18,"affectedCount":18,"affectedCountStatus":19,"affectedCountLowerBound":20,"affectedCountUnit":21,"hasEnglishDescription":4,"severity":22,"dataClasses":23,"description":28,"seoTitle":29,"seoTitleEn":30,"seoDescription":29,"seoDescriptionEn":31,"logoUrl":32,"isVerified":4,"isSensitive":4,"isSpamList":33,"isMalware":33,"company":34},"68e3266eda11adda4882524b","Jobandtalent","Jobandtalent 2018 Data Breach","jobandtalent","jobandtalent.com","2018-02-01T00:00:00.000Z","2021-01-17T22:31:00.000Z","2026-07-29T19:06:43.843Z","Verified breach record","https:\u002F\u002Fwww.zdnet.com\u002Farticle\u002Fhacker-puts-up-for-sale-third-round-of-hacked-databases-on-the-dark-web\u002F",[15,17],"https:\u002F\u002Fwww.jobandtalent.com\u002F",10981207,"known",null,"email_identifiers","Critical",[24,25,26,27],"Email addresses","IP addresses","Names","Passwords","\u003Cp>\u003Cstrong>The Jobandtalent 2018 data breach\u003C\u002Fstrong> concerns account data from the recruitment platform. A verified external breach record dates the event to approximately February 2018 and reports 10,981,207 unique email addresses. The production email-only job processed 10,878,501 lines and created 10,876,576 unique email associations. These are different measures and are not added together.\u003C\u002Fp>\n\n\u003Ch2>How was the event verified?\u003C\u002Fh2>\n\u003Cp>A ZDNet report dated February 17, 2019 documented an actor offering databases attributed to eight companies for sale on a dark-web marketplace. Its listing table gave Jobandtalent a scope of about 11 million rows, a February 2018 date, and fields described as an ID, email, SHA-1 password hash, password salt, first name, surname, and current IP address. The report said that none of the eight companies had previously disclosed a breach and that requests for comment had been sent.\u003C\u002Fp>\n\u003Cp>The external corpus subsequently added to a verified breach index supports the exact unique-email count and four structured data classes. That verification does not mean the company confirmed the attack narrative, actor, or initial access method. The exact event day and method of network access have not been disclosed.\u003C\u002Fp>\n\n\u003Ch2>Which data types are in scope?\u003C\u002Fh2>\n\u003Cp>The verified structured classes are email addresses, IP addresses, names, and passwords. The passwords were reported as salted SHA-1 hashes; plaintext password exposure has not been established. The ID described in the sale listing is not added as a separate structured class because it was not confirmed in the verified class list.\u003C\u002Fp>\n\u003Cp>Phone numbers, résumés, job applications, employment histories, government identity documents, payment cards, and bank accounts are outside the verified scope. An email match does not prove that a name, IP address, and password hash occurred together for the same person or that the person was a job seeker, employee, or current user.\u003C\u002Fp>\n\n\u003Ch2>What does the count difference mean?\u003C\u002Fh2>\n\u003Cp>The 10,981,207 value is the number of unique email addresses in the external corpus. The local job processed 10,878,501 email lines; 10,876,576 email associations remained after normalization and deduplication. The unique local scope is 104,631 below the external measure. Because corpus version and deduplication details are not reconciled across the sources, the values are displayed separately.\u003C\u002Fp>\n\u003Cp>The local file contains email addresses only. Names, IP addresses, and password hashes reported by external sources are not locally stored production fields. This boundary prevents a local match from producing conclusions about those other fields.\u003C\u002Fp>\n\n\u003Ch2>What steps can people consider?\u003C\u002Fh2>\n\u003Cp>If a password used in 2018 was reused on another service, it can be replaced there with a unique password and multifactor authentication can be enabled where available. Unexpected job-offer, shift, payroll, or account-verification messages should be confirmed through Jobandtalent's known address or a separate official channel without following a link in the message.\u003C\u002Fp>","","Jobandtalent 2018 Data Breach (11 Million Email Identifiers)","The 2018 Jobandtalent breach contains 10,981,207 verified unique emails. Review salted SHA-1 password hashes and the smaller local email subset.","\u002Fuploads\u002Flogo\u002Fjobandtalent_com.webp",false,{"name":7,"sector":35,"country":36,"website":10,"websiteArchiveUrl":29,"websiteStatus":37,"websiteCheckedAt":38},"Recruitment","Spain","active","2026-07-29T18:57:55.000Z"]