[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f2xiz8crt21qh3":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":7,"domain":9,"breachDate":10,"addedDate":11,"modifiedDate":11,"contentUpdatedAt":12,"source":13,"sourceUrl":14,"sourceUrls":15,"pwnCount":16,"affectedCount":16,"affectedCountStatus":17,"affectedCountLowerBound":18,"affectedCountUnit":19,"hasEnglishDescription":4,"severity":20,"dataClasses":21,"description":26,"seoTitle":14,"seoTitleEn":27,"seoDescription":14,"seoDescriptionEn":28,"logoUrl":29,"isVerified":4,"isSensitive":4,"isSpamList":30,"isMalware":30,"company":31},"68e3266eda11adda488253a3","switch","Switch Data Breach","switchit.hu","2024-10-01T00:00:00.000Z","2024-10-05T20:18:44.000Z","2026-07-18T23:58:50.626Z","Third party breach","",[],5397,"known",null,"unknown","Low",[22,23,24,25],"Email addresses","Job applications","Names","Social media profiles","\u003Cp>The Switch data breach is a security incident recorded in October 2024 that affected approximately 5,400 accounts. In the incident related to the IT recruitment service based in Hungary, candidate applications and social profile fields were exposed. This content has been prepared so that users can understand the scope of the incident, the leaked fields, the risk level, and the steps they need to take, all on a single page.\u003C\u002Fp>\u003Cp>Job application data is considered sensitive because it can be linked to a person's career plan, the industry they work in, their social profile, and private evaluation notes. Only verifiable data classes are included in the description; different services with the same name, additional claims whose technical details are not clear, or information with unproven scope are not presented as data fields. This approach makes the real risk visible without misleading the user.\u003C\u002Fp>\u003Ch2>Leaking Data Types and Risks\u003C\u002Fh2>\u003Cp>The types of data listed in this event are: email addresses, job applications, names, and social media profiles. When candidate applications and social profile information are found together, targeted messages related to a person's current job status can be prepared. When these fields are used together, they may result in account takeover, social engineering, fraud, physical targeting, or privacy violations.\u003C\u002Fp>\u003Cp>In this record, the password field is not listed; the risk is more concentrated in the areas of career privacy, candidate profile, and recruitment fraud. In records that contain passwords, using the same or similar password on other services is one of the most critical risks. In records that do not contain passwords, fields such as device, location, phone, address, education, job application, or financial context can make targeted messages more convincing.\u003C\u002Fp>\u003Ch2>Verified Scope and Boundaries\u003C\u002Fh2>\u003Cp>The record covers approximately 5,400 candidate or customer records associated with the domain switchit.hu. The incident is classified as a confirmed record. In the scope assessment, the number of accounts, domain, sector, country, and data classes were checked separately. The data fields shown to the user were limited to the fields actually listed in the record.\u003C\u002Fp>\u003Cp>The sector has been corrected from technology to IT recruitment and headhunting. This distinction is especially important for similar brand names, records covering multiple services, or sensitive sectors. The record has not been combined with another incident, expanded in a way that would create duplicate records, and the company context has been clarified as much as possible.\u003C\u002Fp>\u003Ch2>User Groups at Risk\u003C\u002Fh2>\u003Cp>Candidates applying for jobs through Switch, IT professionals, and people whose social profiles are linked to the application are at risk. The main risk for these individuals is the matching of leaked fields with common information used in other accounts. When the same email address, phone number, username, device ID, or password is repeated, attackers may try this information on different services.\u003C\u002Fp>\u003Cp>In the hiring context, it can be misused in fake job offers, salary negotiations, document requests, or interview link messages. For corporate users, job emails and task information stand out, while for individual users, address, date of birth, purchase, location, or membership context stands out. In fields such as education, telecommunications, finance, travel, politics, job applications, and VPNs, the context itself can also increase targeting risk.\u003C\u002Fp>\u003Ch2>Urgent Measures to Be Taken\u003C\u002Fh2>\u003Cp>Affected users should check their application accounts and work emails, and verify any unexpected job offers or document upload requests. If a password or password-like field is listed, users should change it on all accounts where they use the same password, use a unique password, and enable multi-factor authentication where possible. Operating on just a single platform may not be sufficient.\u003C\u002Fp>\u003Cp>If there are fields such as phone, address, date of birth, device ID, official ID, job application, or reward balance, users should check account recovery information, registered sessions, email forwarding, and suspicious messages. For institutions, processes should be updated against employee alerts, fake invoices, and account verification attempts.\u003C\u002Fp>\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\u003Cp>Candidates should share their personal social profiles minimally in job applications and use separate passwords and careful document sharing on recruitment platforms. In the long term, a password manager, unique passwords, multi-factor authentication, closing old accounts, deleting unnecessary profile fields, and data minimization form the core security line. Since permanent personal data cannot be recovered, defense relies on strengthening account behavior.\u003C\u002Fp>\u003Cp>On the company and institutional side, post-incident inventory, access permissions, storage of old data, notification processes, and the use of third-party platforms should be reconsidered. On the user side, avoiding the repetition of the same identity information across different services and the habit of verifying suspicious communications through a second channel provide lasting protection.\u003C\u002Fp>\u003Ch2>Record Control and User Action\u003C\u002Fh2>\u003Cp>The user should check the social profiles and application history shared in job applications if they match this record. If a match is observed, the user should first read which data fields are listed, and then prioritize the steps according to these fields. If there is a password, password change should be prioritized; if there is official identification, identity monitoring; if there is location or device information, device security; if there is education or job application, institutional account verification should be prioritized.\u003C\u002Fp>\u003Cp>Final assessment: Although this record does not contain a password, it is a sensitive career data incident due to the context of job applications and social profiles. The user should compare this record with their account history; they should individually check the services where they used the same email, phone number, username, or password. Unexpected calls, messages, emails, or account recovery notifications should be considered higher risk after the incident.\u003C\u002Fp>","Switch Data Breach (5.4 Thousand Reported Records)","Switch Data Breach. 5.4 Thousand reported records were reported. Reported data: Email addresses, Job applications, Names. Review the scope, risks, and…","\u002Fuploads\u002Flogo\u002Fswitchit_hu.webp",false,{"name":32,"sector":33,"country":34,"website":9,"websiteArchiveUrl":14,"websiteStatus":14,"websiteCheckedAt":18},"Switch","IT Recruitment \u002F Headhunting","Hungary"]