Hardware FixRecommendedDevice not working? Your driver may be the problemCheck updates for common hardware issues.Fix DriversOctober DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsPC HealthRecommendedCrashes, freezes, slowdowns? Check your PC nowSpot repairable issues before they interrupt work.Check PC×
Skip to content
The Finance Base
The Money Desk · Blog
Re:

ResumeLooters: What Group-IB Found in the 2023 Job-Site Attacks

Group-IB reported 65 compromised websites in the ResumeLooters campaign and millions of rows in stolen files. Here is what the findings do—and do not—say about personal exposure.
From TheFinanceBase Team3 min to read
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

ResumeLooters was a cybercrime campaign against recruitment and job-search websites, not primarily an attack on job seekers’ personal computers. Group-IB’s 2024 report counted 2,188,444 rows in stolen files and 510,259 user records attributed to job-search websites; neither figure establishes how many unique people were affected. The report identified 65 compromised websites, mostly in APAC, but it does not reveal whether any particular person’s résumé was among the stolen data.

What is ResumeLooters?

ResumeLooters is the name Group-IB gave to a previously unknown cybercrime group that targeted employment agencies and retail companies, with a focus on job-search platforms and résumé theft. Group-IB said it detected the campaign in November 2023 and identified 65 compromised websites between November and December 2023. File creation dates on attacker infrastructure led the researchers to trace the earliest observed attacks to the beginning of 2023. These are findings from Group-IB’s 2024 incident analysis, not a current tally of active attacks. Group-IB’s report

How many resumes did ResumeLooters steal?

Group-IB’s 2024 report counted 2,188,444 rows in stolen files and separately reported 510,259 user records from job-search websites. Those figures describe different units: the first is a total row count across stolen files, while the second is the report’s job-search-site user-data subset. Group-IB did not establish that each row or record represents a different person, so neither number should be presented as a unique-person count. The report also does not establish that every affected website’s full database was taken or that every record was sold.

Group-IB said stolen data was advertised for sale in Telegram channels. Advertising data for sale does not show that every record was purchased or distributed.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What information did ResumeLooters steal?

Group-IB said databases targeted by SQL injection could contain names, phone numbers, email addresses, dates of birth, employment experience, employment history, and other sensitive personal data. The precise fields at risk depended on what each website stored; the report does not say that every compromised site exposed every listed field.

How did SQL injection and XSS affect job sites?

Method Role in the campaign What it could mean
SQL injection Used to retrieve website databases. Could expose stored user information, including contact details and employment history.
Cross-site scripting (XSS) Scripts were injected into legitimate job-search websites to load additional malicious code and display phishing forms. Visitors could encounter phishing behavior through a legitimate site. Group-IB found evidence of execution on some visitors’ devices, but said a script’s presence did not prove it executed on every device.

The two techniques served different purposes: SQL injection targeted stored data, while XSS could affect a site’s content as viewed by visitors. The campaign’s primary target was the websites and their data, rather than job seekers’ computers as the initial entry point.

Rank #2
Sale
The Psychology of Money: Timeless lessons on wealth, greed, and happiness
  • Ideal for Gifting
  • Ideal for a bookworm
  • Compact for travelling

Where were the victims?

Group-IB reported that over 70% of known victims were in APAC. In its 2024 findings, the researchers identified 12 victims in India, 10 in Taiwan, 9 in Thailand, and 7 in Vietnam. They also found compromised companies in Brazil, the United States, Turkey, Russia, Mexico, Italy, and elsewhere. These figures reflect victims identified by the researchers, not a complete census of all affected organizations.

Group-IB observed Chinese-language Telegram accounts and tools, but said these clues did not establish the operators’ nationality, location, or sponsorship. The report does not support attributing the campaign to a government or claiming a definite national origin.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Was my resume stolen in the ResumeLooters attack?

The public Group-IB report does not identify whether a particular person’s résumé or account was included, and it does not provide an individual exposure checker. A person’s presence on a job-search website is not, on its own, proof of exposure. Check for a notice from the specific platform you used and follow its instructions; the report’s aggregate counts cannot confirm individual impact.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How should job seekers handle possible breach messages?

A message claiming to notify you about a breach can itself be a phishing lure. CNIL’s March 13, 2024 guidance after a separate France Travail breach recommends watching for urgent SMS and emails, not sending passwords or banking details by message, avoiding suspicious attachments and login links, going directly to the official service site, monitoring account activity, and using robust passwords. This was guidance for the France Travail case, not advice issued specifically for ResumeLooters. CNIL’s guidance

Quick Recap

SaleBestseller No. 1
SaleBestseller No. 2
The Psychology of Money: Timeless lessons on wealth, greed, and happiness
The Psychology of Money: Timeless lessons on wealth, greed, and happiness
Ideal for Gifting; Ideal for a bookworm; Compact for travelling
$10.99
SaleBestseller No. 5
I Will Teach You to Be Rich: No Guilt. No Excuses. Just a 6-Week Program That Works (Second Edition)
I Will Teach You to Be Rich: No Guilt. No Excuses. Just a 6-Week Program That Works (Second Edition)
It can be a gift option; Comes with secure packaging; Helpful in various ways
$9.15
Best Value
Sale
I Will Teach You to Be Rich: No Guilt. No Excuses. Just a 6-Week Program That Works (Second Edition)
  • It can be a gift option
  • Comes with secure packaging
  • Helpful in various ways

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More post from the Money Desk

  1. The Money DeskBlogTheFinanceBase07 MAR 2625 minWhat Is a 457 Plan?
  2. The Money DeskBlogTheFinanceBase07 MAR 2621 minTime Value of Money: What It Is and How It Works
  3. The Money DeskBlogTheFinanceBase07 MAR 2627 minAre You Living in One of These Top 10 Most Expensive Cities to Retire?
Recommended PC Tool
Recommended PC Tool
PC Slower Than It Used to Be?Free scan - under a minute
Outdated Drivers Are Slowing You DownFree scan - exact matches

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.