CSIDB logo
Incident

InfoJobs

Incident posture

Attack window
Nov 2025
Location
Spain
Status
Unknown
CIA posture
Available to members
Updated
2026-08-17 17:46

Linked entities

Victim
InfoJobs
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Undetermined
Discovered
Undetermined
Disclosed
Jun 2025
Resolved
Pending

Summary

InfoJobs suffered a cyberattack carried out through credential stuffing, resulting in the theft of a significant amount of user data including usernames and passwords that had been reused from other services. The platform notified affected users and implemented reinforced monitoring and security measures across its systems. The stolen data is used by cybercriminals in identity theft attacks, including fraudulent job offers that mimic legitimate companies and create a sense of urgency. Assistance is available through the National Cybersecurity Institute’s free hotline and WhatsApp line.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

On June 1 2025 InfoJobs reported a cyberattack. The attack resulted in theft of a significant amount of data uploaded by candidates to their profiles. The platform did not disclose the total number of affected individuals when questioned by elDiario.es. The intrusion was carried out using credential stuffing, where attackers tested username and password pairs obtained from other security breaches across multiple services, exploiting password reuse. InfoJobs stated that the main responsibility lies with users who reuse passwords, but also noted that platforms should have measures to prevent mass password testing.

The stolen data includes personal information from candidate profiles, which cybercriminals can use for identity theft attacks. Attackers may pose as recognized companies such as InfoJobs or other entities to gain victims' trust by demonstrating access to personal data. A common tactic involves creating a sense of urgency to pressure victims into acting quickly to avoid alleged negative consequences. The article also notes that the Spanish Data Protection Agency (AEPD) had recently fined Carrefour 3.2 million euros for suffering up to six consecutive cyberattacks using the same technique without adequately protecting user data, highlighting a broader regulatory context.

InfoJobs communicated that it is already informing the affected users about the breach. The platform said it has implemented reinforced monitoring and security protocols across all its systems. Additionally, InfoJobs has enabled a special web page providing information for those impacted by the incident.

Sources

Sources available to members: 1 source.

CSIDB