'ResumeLooters' Attackers Steal Millions of Career Records
ID: adbef05e-983b-59cf-8798-027c0f6755c3
STIX ID: report--adbef05e-983b-59cf-8798-027c0f6755c3
Feed Name: Dark Reading
Date Published: 2024-02-06
Date Updated: 2026-04-21
Author: Elizabeth Montalbano, Contributing Writer
Researchers from Group-IB uncovered the "ResumeLooters" campaign that, between November and December, used SQL injection (primarily via sqlmap) and XSS to steal databases containing 2,079,027 unique emails and other resume personal data from at least 65 job-recruitment and retail sites across APAC and other regions; attackers used publicly available pentesting tools, left logs on a malicious server (139.180.137.107), and put stolen data up for sale on Chinese-speaking Telegram channels.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
