IntelBroker and Sanggiero claimed a data breach at staffing firm Robert Half
- Organization
- Robert Half International
- Exploit
- Hacking
- Industry
- Staffing and Recruitment
In February 2024, two threat actors using the handles IntelBroker and Sanggiero claimed on the BreachForums cybercrime marketplace that they had compromised the staffing and recruitment company Robert Half International. The pair said they obtained the data on February 8, 2024.
The listing advertised more than 64 GB of material, described as confidential company documents, roughly 1,700 source code repositories, employee records, customer information and configuration data for third-party services including OpenAI and Twilio. The sellers published screenshots that appeared to show Git repositories and Amazon Web Services settings, along with client spreadsheets containing company names, contact identifiers, staff names, job titles and phone numbers.
The data was offered for $20,000 in Monero, a privacy-focused cryptocurrency. The sellers wrote that the material was current and implied they still had access to Robert Half systems.
Robert Half did not publicly confirm or deny the claim, and the number of individuals whose information may have been involved was never established. Reporters who approached the company did not receive a substantive response.
The claim followed a separate incident disclosed in June 2022, when Robert Half reported to the Maine Attorney General that attackers had targeted more than 1,000 customer accounts, exposing names, Social Security numbers and tax documents.