Misconfigured, public Elasticsearch cluster owned by Chinese headhunting firm FMC Consulting exposed private data including 20M+ resumes and 5M+ company records
Sergiu Gatlan / BleepingComputer :
Context & Ripple Effects
FMC Consulting's exposed cluster is the latest entry in a pattern researchers have been documenting all year: Chinese HR-sector databases left open on the public internet, following the 590M+ resume leak across Chinese HR-focused companies reported in April and the 202M-resume MongoDB exposure in January.
The tooling is consistent too — the same unsecured Elasticsearch and MongoDB stacks behind the Panama citizen-data cluster found in May — which is why this reads less like one firm's mistake and more like a sector-wide default configuration problem.
First-order effects
- Over 20 million job seekers whose resumes were held by FMC Consulting now have career histories, contact details, and salary expectations sitting in an open database, alongside 5 million company records describing client employers.
Second-order effects
- Every other headhunting firm running Elasticsearch or MongoDB defaults becomes an obvious target for the same scanning researchers are already doing, forcing HR companies to treat database exposure as a board-level risk rather than an IT footnote.
Third-order effects
- If the cadence holds — from the January MongoDB leak through April's HR-sector tally to July's Chinese public security department exposure — regulators and enterprises will increasingly assume Chinese-sourced personal data has been compromised by default, reshaping how cross-border hiring and data-sharing deals get vetted.
The trend: Default-insecure NoSQL deployments are turning China's HR and government data holdings into a rolling series of mass exposures, discovered researcher-by-researcher faster than anyone can remediate them.