Job seeker 'horrified' after recruitment website PageUp data breach threatens New Zealand applicants
Monday, 18 June 2018
New Zealanders who applied for jobs with Jetstar and Kathmandu have been warned they may have had their data accessed by hackers.
Third party e-recruitment platform PageUp, which has 2.6 million users in 190 countries, confirmed their client data had been accessed by 'unauthorised persons' in a malware attack on May 23.
On Monday night, retail company Kathmandu and Australian airline Jetstar emailed job applicants to advise their privacy may have been breached.
Sydney-based PageUp said they believed job applicants names, email and physical addresses, phone numbers, biographical details such as date of birth, gender, country of residence, and employment details may have been compromised.
**READ MORE:
* Over half of Kiwis more worried about privacy online than two years ago
* Thousands of 'vulnerable' customers' private data shared by Vector app
* Mercury 'extremely sorry' for privacy breach of shareholder information
* NZ privacy commissioner has pulled up Facebook for breach of privacy laws**
No employment contracts, applicant resumes, tax file numbers, credit card information or bank account information were affected, they said on their website.
There was no evidence of an ongoing threat and the jobs website could continue to be used, PageUp said.
A Christchurch man who applied for a job with Kathmandu on May 20 said he was 'horrified' to learn of the breach.
'Personal info that can be used to hijack my identity, hack into my accounts, change passwords on other sites, doctor my credentials has been stolen and shared amongst virtually anyone,' he said.
The man, who did not want to be named, said he was asked to complete an online application on their 'secure' website, which looked as though it was Kathmandu's site - the colours, themes and logos all matched.
He said he was not happy with Kathmandu's 'bulk response' almost a month after the breach occurred.
'The full damage is yet to be known and Kathmandu is nothing short of grossly incompetent. I have no interest in working for these amateurs after this,' he said.
Neither company had been advised of any specific breach of data provided by Jetstar or Kathmandu job candidates, the emails said.
'Whilst we are still waiting for a response from PageUp to confirm, in relation to Kathmandu job applicants, the specific data and specific individuals impacted, (amongst other information requests) we are contacting all individuals who could have been affected through applying for a job at Kathmandu,' Kathmandu's email said.
However, both Kathmandu and Jetstar urged people who had applied for jobs to change their passwords and check there had been no unusual activity concerning their personal information.
'We wanted to let you know what has happened so that you may take additional steps you deem appropriate to protect your privacy,' Jetstar said.
Kathmandu used PageUp between 2015 and May 2018.
Jetstar said PageUp 'formerly' provided IT services used in their recruitment process.
Across the ditch, major Australian universities, AusPost, Coles, Telstra, Commonwealth Bank, Lindt, Aldi, NAB, Medibank and the Reserve Bank of Australia were all affected, the Sydney Morning Herald reported.
The breach was being investigated by the Australian government's Cyber Security Centre.