Ladders

NJCCIC Data Breach Notification

Original Release Date: 5/13/2019

Summary

Ladders, a popular employment website, has reportedly exposed more than 13.7 million user records due to a cloud misconfiguration. Some of the information leaked included users’ names, postal and email addresses, phone numbers, and detailed employment histories. The data was stored in an Elasticsearch database hosted by Amazon Web Server (AWS), and was not protected by password authentication. Ladders CEO, Marc Cenedella, confirmed the breach. The database was taken offline within an hour of notification. 

Recommendations

The NJCCIC recommends Ladders users verify their account information and exercise caution when opening Ladders-related emails, as the breached data could be used in social engineering and phishing attempts.

New Jersey Cybersecurity & Communications Integration Cell

2 Schwarzkopf Dr, Ewing Township, NJ 08628

njccic@cyber.nj.gov

OUR COMMITMENT

The NJCCIC is a component organization within the New Jersey Office of Homeland Security and Preparedness. We are the State's one-stop-shop for cyber threat analysis, incident reporting, and information sharing and are committed to making New Jersey more resilient to cyber threats by spreading awareness and promoting the adoption of best practices.

Agency Seals of State of NJ, NJOHSP and NJCCIC

STAY CONNECTED:

View our Privacy Policy here.

View our Site Index here.