German healthcare recruiter Pflegia exposed job seeker files in open AWS bucket

Organization
Pflegia
Exploit
Misconfiguration
Industry
Recruitment

Pflegia, a German recruitment platform that places nurses and other healthcare workers with hospitals, nursing homes, outpatient services and intensive care units, left an Amazon Web Services storage bucket open to the internet.

The exposure was found by researchers at Cybernews, who reported that the instance held more than 360,000 files. Most were resumes uploaded by people applying for jobs through the platform.

The files contained full names, dates of birth, occupational histories, home addresses, telephone numbers and email addresses. Researchers noted the combination is well suited to targeted phishing, since an attacker holding an applicant's employment history can convincingly pose as a recruiter with a tailored job offer, as well as to identity theft.

The bucket was closed to public access shortly after the researchers disclosed it. Accounts of the company's response varied. The researchers reported that Pflegia did not reply to their notification, while the company was later described as cooperating with the relevant German authorities.

Neither the company nor the researchers published a figure for the number of individuals whose records were in the bucket, and there was no indication that anyone other than the researchers had accessed it. The leak was reported publicly on June 8 and 9, 2023.

Sources