[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f1poeysasplcum":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":7,"domain":9,"breachDate":10,"addedDate":11,"publishedAt":12,"modifiedDate":13,"contentUpdatedAt":13,"source":14,"sourceUrl":15,"sourceUrls":16,"pwnCount":19,"affectedCount":19,"affectedCountStatus":20,"affectedCountLowerBound":12,"affectedCountUnit":21,"hasEnglishDescription":4,"contentLocale":22,"availableLocales":23,"translations":25,"severity":28,"dataClasses":29,"description":33,"seoTitle":34,"seoDescription":35,"logoUrl":36,"isVerified":4,"isSensitive":4,"isSpamList":37,"isMalware":37,"company":38},"6a455d0a137840ea9fce5f47","lako-do-posla","Lako do posla 2022 Data Breach","lakodoposla.com","2022-09-07T00:00:00.000Z","2026-07-01T18:31:36.998Z",null,"2026-07-29T23:49:03.763Z","Database leak","https:\u002F\u002Fmikicaivosevic.medium.com\u002Flako-do-posla-lako-do-podataka-ea6bc3ad52fd",[15,17,18],"https:\u002F\u002Fwww.securitysee.com\u002F2022\u002F09\u002F23\u002Flako-do-posla-lako-do-podataka\u002F","https:\u002F\u002Fwww.lakodoposla.com\u002F",554899,"known","email_identifiers","en",[22,24],"tr",{"en":26,"tr":27},{"slug":7},{"slug":7},"High",[30,31,32],"Email addresses","Names","Passwords","\u003Cp>\u003Cstrong>The Lako do posla 2022 data breach\u003C\u002Fstrong> concerns a job-search database reported online in an independent technical assessment published in September 2022. The researcher described approximately 500,000 active and inactive users, while production holds 554,899 unique email associations. These are different measures produced by different methods. The legacy unsourced value of 549,788 is not used as a verified count of people or accounts.\u003C\u002Fp>\n\n\u003Ch2>What do the external sources establish?\u003C\u002Fh2>\n\u003Cp>A researcher article dated September 7, 2022 says the lakodoposla.com database had appeared online a few days earlier and contained names, surnames, email addresses, passwords, and other fields for approximately 500,000 active and inactive users. The author reported that about 15,000 passwords were in plaintext and that the latest database entry was dated July 28. A local security article dated September 23 repeats the same scope and password finding with attribution to the researcher.\u003C\u002Fp>\n\n\u003Cp>The researcher used an August 10 forum post and historical network observations to assess local file inclusion and externally reachable MySQL access as a likely attack chain. Because the author explicitly described that part as an inference, the method is not presented as confirmed fact. No company notice, regulator record, or verified external breach-index entry was found; the event identity is supported by the independent technical report and local email corpus.\u003C\u002Fp>\n\n\u003Ch2>Why are the counts different?\u003C\u002Fh2>\n\u003Cp>The external source describes approximately 500,000 active and inactive users; that rounded figure is not a unique-email analysis. The completed production job took the union of source fields with explicit email-address meaning and login-username fields proven through aggregate validation to contain email addresses. Notification preferences, email flags, and email identifier or filter fields were excluded.\u003C\u002Fp>\n\n\u003Cp>The local job accepted 554,899 lines under the \u003Ccode>canonical-ascii-email-v1\u003C\u002Fcode> validator and wrote the same number of unique email associations. Its canonical input manifest records file integrity and line scope. The approximate external user scope and local unique-email count are not added together, and an email is not assumed to represent one person, one account, or an active user.\u003C\u002Fp>\n\n\u003Ch2>Which data types remain within the evidence boundary?\u003C\u002Fh2>\n\u003Cp>The two public articles explicitly support names, email addresses, and passwords for this event. Legacy classes for dates of birth, genders, job information, nationalities, phone numbers, physical addresses, usernames, and website activity were removed because no currently accessible full schema or independent source re-established them during this review. The researcher's reference to “other” data is not specific enough to add individual classes.\u003C\u002Fp>\n\n\u003Cp>Production collections contain no password, name, phone, username, IP, identity, or sensitive-data associations for this event; only the email index is populated. The researcher's finding of approximately 15,000 plaintext passwords is therefore external-source context and does not imply that local password search is available. The current lakodoposla.com site confirms the job-listing platform identity but publishes no incident statement.\u003C\u002Fp>\n\n\u003Ch2>What does this mean for users?\u003C\u002Fh2>\n\u003Cp>People who had an account with the service in 2022 and may have reused its password elsewhere should replace the reused password on those other services with a unique one. This advice follows the researcher's plaintext-password finding; it does not claim every user's password was stored in plaintext. Unexpected messages framed as job applications, résumé updates, or account checks should be verified through a known channel opened directly from the active lakodoposla.com domain rather than through an incoming link.\u003C\u002Fp>","Lako do posla 2022 Data Breach (554.9 Thousand Email Identifiers)","The Lako do posla 2022 incident was reported at about 500,000 users; the local index contains only 554,899 unique email associations.","\u002Fuploads\u002Flogo\u002Flakodoposla.webp",false,{"name":39,"sector":40,"country":41,"website":42,"websiteArchiveUrl":43,"websiteStatus":44,"websiteCheckedAt":45},"Lako do posla","Employment","Serbia","www.lakodoposla.com","","active","2026-07-29T23:31:48.000Z"]