[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f3j9nlwkmi0hte":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"modifiedDate":12,"contentUpdatedAt":13,"source":14,"sourceUrl":15,"sourceUrls":16,"pwnCount":17,"affectedCount":17,"affectedCountStatus":18,"affectedCountLowerBound":19,"affectedCountUnit":20,"hasEnglishDescription":4,"severity":21,"dataClasses":22,"description":26,"seoTitle":15,"seoTitleEn":27,"seoDescription":15,"seoDescriptionEn":28,"logoUrl":29,"isVerified":4,"isSensitive":30,"isSpamList":30,"isMalware":30,"company":31},"68e3266eda11adda488253b8","tehetseg-kapu","TehetségKapu Data Breach","tehetsgkapu","tehetsegkapu.hu","2025-03-26T00:00:00.000Z","2025-05-01T06:55:54.000Z","2026-07-18T23:59:30.354Z","Third party breach","",[],54357,"known",null,"unknown","Medium",[23,24,25],"Email addresses","Names","Usernames","\u003Cp>The TehetségKapu data breach is a security incident recorded in the March 2025 period, affecting approximately 54,000 accounts. Email addresses, names, and usernames were exposed on the talent portal associated with the Hungarian education office. This content has been prepared so that users can understand the scope of the incident, the compromised areas, the level of risk, and the steps they need to take on a single page.\u003C\u002Fp>\u003Cp>Although the data fields are limited, in the context of an education and skills portal, it may allow targeting users with their school, career, or student profiles. The description includes only verifiable data classes; services with the same name, additional claims whose technical details are unclear, or unproven information are not presented as data fields. This approach makes the real risk visible without misleading the user.\u003C\u002Fp>\u003Ch2>Leaking Data Types and Risks\u003C\u002Fh2>\u003Cp>The types of data listed in this incident are as follows: email addresses, names, and usernames. Name and username, along with email address, can be used for fake education portal, application, or account verification messages. When these fields are used together, they can lead to outcomes such as account takeover, social engineering, fraud, physical targeting, or privacy violation.\u003C\u002Fp>\u003Cp>In this record, password, date of birth, official ID, or address fields are not listed; therefore, the sensitivity level has been kept low according to these limited data fields. In records containing passwords, using the same or similar password in other services is one of the most critical risks. In records without passwords, fields such as device, location, phone, address, education, job application, or financial context can make targeted messages more convincing.\u003C\u002Fp>\u003Ch2>Verified Scope and Boundaries\u003C\u002Fh2>\u003Cp>The record covers approximately 54,000 accounts associated with the domain name tehetsegkapu.hu. The incident is in the verified record category. In the scope assessment, the number of accounts, domain name, sector, country, and data classes were checked separately. The data fields shown to the user were kept limited to the fields actually listed in the record.\u003C\u002Fp>\u003Cp>The country has been corrected to Hungary instead of the United States, and the sector has been corrected to an education and talent portal. This boundary is especially important for similar brand names, records covering multiple services, or sensitive sectors. The record has not been merged with another event, has not been expanded in a way that would create duplicate records, and the company context has been clarified as much as possible.\u003C\u002Fp>\u003Ch2>User Groups at Risk\u003C\u002Fh2>\u003Cp>TehetségKapu users, students or teachers registered in the education office portal, and people using the same username on other educational services are at risk. The main risk for these individuals is that the leaked data can be matched with common information used in other accounts. When the same email address, phone number, username, device ID, or password is repeated, attackers may try these details on different services.\u003C\u002Fp>\u003Cp>The educational portal context can be used in fake applications, account verification, competition, or institutional notification messages. Business email and job information stand out for corporate users, while address, date of birth, purchase, location, or membership context stand out for individual users. In areas such as education, telecommunications, finance, travel, politics, job applications, and VPNs, the context itself can also increase targeting risk.\u003C\u002Fp>\u003Ch2>Urgent Measures to Be Taken\u003C\u002Fh2>\u003Cp>Affected users should check their email accounts and examine if there are any suspicious logins on educational portals where they use the same username. If a password or password-like field is listed, users should change it on all accounts where they use the same password, use a unique password, and enable multi-factor authentication where possible. Taking action on only a single platform may not be sufficient.\u003C\u002Fp>\u003Cp>If there are fields such as phone, address, date of birth, device ID, official ID, job application, or reward balance, users should check account recovery information, registered sessions, email forwarding, and suspicious messages. For institutions, processes should be updated against employee alerts, fake invoices, and account verification attempts.\u003C\u002Fp>\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\u003Cp>Unnecessary profile fields should be reduced on educational portals, and different usernames or strong account protection should be preferred on different services. In the long term, a password manager, unique passwords, multi-factor authentication, closing old accounts, deleting unnecessary profile fields, and data minimization form the core security line. Since permanent personal data cannot be recovered, defense relies on strengthening account behavior.\u003C\u002Fp>\u003Cp>On the company and institutional side, post-incident inventory, access permissions, storage of old data, notification processes, and the use of third-party platforms should be reconsidered. On the user side, avoiding the repetition of the same identity information across different services and the habit of verifying suspicious communications through a second channel provide lasting protection.\u003C\u002Fp>\u003Ch2>Record Control and User Action\u003C\u002Fh2>\u003Cp>If the user matches this record, they should check their education account and other school portals they use with the same email address. If a match is found, the user should first read which data fields are listed and then prioritize the steps according to these fields. If there is a password, password change should be prioritized; if there is an official ID, ID monitoring; if there is location or device information, device security; if it concerns education or job applications, institution account checking should be prioritized.\u003C\u002Fp>\u003Cp>Final evaluation: This record has not been marked as sensitive because it contains limited data, but due to the educational context, the risk of targeted messaging has been clearly indicated. The user should compare this record with their account history; they should check the services where they have used the same email, phone, username, or password individually. Unexpected calls, messages, emails, or account recovery notifications should be considered higher risk after the incident.\u003C\u002Fp>","TehetségKapu Data Breach (54.4 Thousand Reported Records)","TehetségKapu Data Breach. 54.4 Thousand reported records were reported. Reported data: Email addresses, Names, Usernames. Review the scope, risks, and…","\u002Fuploads\u002Flogo\u002Ftehetsegkapu_hu.webp",false,{"name":32,"sector":33,"country":34,"website":10,"websiteArchiveUrl":15,"websiteStatus":15,"websiteCheckedAt":19},"TehetségKapu","Education \u002F Talent Portal","Hungary"]