A threat actor has claimed to be selling a database allegedly belonging to GulfJobs, a recruitment platform serving employers and job seekers across Saudi Arabia and the Gulf region. According to the claim, the database contains approximately 872,000 records.
The alleged dataset is reported to include a wide range of personal and recruitment-related information, including identity details such as names, dates of birth, nationality, and passport information; contact details including email addresses, phone numbers, physical addresses, and LinkedIn profiles; career-related information such as CVs, work experience, skills, certifications, salary expectations, languages, and relocation preferences; as well as authentication logs and other recruitment metadata.
At the time of publication, the authenticity of the dataset and the claimed number of records have not been independently verified.
If the claim proves to be genuine, the exposed information could be exploited to conduct targeted phishing campaigns, identity theft, credential attacks, recruitment fraud, and other forms of cyber-enabled crime. Unlike many other types of personal data, recruitment profiles contain detailed professional and personal information that can help attackers create highly convincing fraudulent communications.
Cybercriminals may use information from a candidate’s CV or online profile to send fake recruitment emails, fraudulent interview invitations, or offers that closely match the victim’s skills and employment history. These tactics increase the likelihood that victims will trust the messages and disclose additional sensitive information.
One of the most common recruitment scams affecting job seekers in the Gulf region involves fake employers requesting payments for visa processing, medical examinations, work permits, document attestation, or other administrative fees before employment. Legitimate employers generally do not require candidates to pay such fees as a condition of recruitment.
As a precaution, individuals using GulfJobs or any online recruitment platform are encouraged to review the security of their accounts. Users should change their passwords immediately if they have reused them on other services, enable multi-factor authentication (MFA) whenever available, remain cautious of unexpected job offers or interview invitations, never share passwords or one-time verification codes, and independently verify any request involving payments or personal documents.
This incident serves as an important reminder that personal and professional information shared on recruitment platforms can become valuable targets for cybercriminals. Protecting online accounts, practicing good password hygiene, and remaining vigilant against recruitment scams are essential steps in reducing cyber risk while searching for new career opportunities.
