Monster says millions of users' data may be stolen
NEW YORK/BOSTON (Reuters) - The theft of contact information for job seekers in the database of Monster Worldwide Inc (MNST.O: Quote, Profile, Research) may have been much greater than the 1.3 million individuals reported earlier this month …
Context & Ripple Effects
Monster Worldwide's disclosure is a widening, not a new, incident: nine days earlier, Computerworld reported 1.6 million records taken in an identity attack on Monster.com, after the company had put the initial figure at 1.3 million job seekers. Reuters now reports the true scope may run to millions, meaning the number has been revised upward twice within August.
That cadence is the story's significance — Monster is admitting it cannot yet bound the loss of exactly the asset its business is built on: a curated database of contact details for people actively seeking work.
First-order effects
- Job seekers whose contact information was lifted are exposed to targeted phishing that can reference their real job-search activity, making the attacks harder to spot than generic spam.
- Monster faces notification obligations at an unbounded scale and must explain to corporate customers why a paid, access-controlled database was harvested.
Second-order effects
- Employers and recruiters who pay for access to Monster's resume database have to weigh whether listings there expose their own hiring staff to the same social-engineering playbook used against candidates.
- Rivals in online recruiting can be expected to field security questions from shared enterprise buyers, turning database protection into a competitive talking point rather than a back-office function.
Third-order effects
- If attackers treat job boards as high-yield sources of verified identities, aggregated résumé and contact repositories become standing targets, and sites holding them face pressure to retain less data rather than more.
- Repeated upward revisions of breach scope push disclosure norms toward ongoing updates instead of one-time announcements — a pattern regulators and class-action plaintiffs can later hold against the disclosing company.
The trend: Aggregated personal-data stores like job boards' résumé databases are shifting from passive assets to active liabilities, with breach disclosures increasingly revised upward after the fact.