Breaking
February 6, 2025

Foh&Boh data leak leaves millions of CVs exposed – KFS, Taco Bell, Nordstrom applicants at risk | usagoldmines.com


  • A hiring company has reportedly left millions of CVs in a publicly accessible AWS bucket
  • Foh&Boh has partnerships with leading food and hospitality services
  • The dataset is now closed, but users may still be at risk

A dataset containing a staggering 5.4 million files has been discovered by researchers online, and is believed to be primarily CVs (resumes) from hiring giant Foh&Boh.

Researchers from CyberNews discovered the publicly accessible AWS bucket containing the exposed records, and after ‘multiple attempts to reach the company’, the dataset was closed.

It’s not clear whether malicious actors have accessed the dataset, but cybercriminals often have automated tools to scan the internet for unprotected instances, and immediately download them, so victims still face very real risks – here’s what we know so far.

Plenty of personal data

The hiring platform, Foh&Boh, aims to ‘find and recruit talent for the hospitality industry’, and partners with independent restaurants, franchises, hospitality groups, and ‘some of the world’s largest hotel chains. The platform boasts partnerships with industry giants like Nobu, Taco Bell, and KFC.

Of course, CVs contain personally identifiable information (PII), and the research team claims this leak includes full names, phone numbers, email addresses, social media links, and employment and education histories, among others.

The data was available online for a fairly significant period of time, with discovery on September 16, 2024, initial disclosure on October 22 2024, and the leak closed on January 8 2025.

This, like all data leaks, leaves those exposed in danger. Primarily, the concern is identity theft, especially since a CV hands over a comprehensive set of personal details over to potential attackers.

“The leak significantly heightens the risk of identity theft, enabling cybercriminals to create synthetic identities or fraudulent accounts, leaving individuals exposed to a range of sophisticated cyberattacks,” the researchers said.

This might sound familiar to some, as just two days ago on the February 4 2025, a large dataset containing over a million CVs stored by Valley News Live was discovered, so it’s a pretty lousy week for jobseekers.

Data breaches have unfortunately become a part of life for anyone on the web. In 2024, one single breach leaked the details of 100 million Americans (although the total is now reported at 190 million – so almost 75% of US adults) – which just shows that no-one is safe.

Also a risk with breached credentials, is social engineering attacks. These commonly come in the form of phishing campaigns, and are designed around the information hackers have obtained, often appearing to know the victim personally or preying on people in difficult financial situations by offering ‘get rich quick’ scams.

“Attackers could craft highly personalized emails referencing specific job details or interests from the resumes, making their phishing attempts ever more convincing” the researchers said. “This targeted approach could deceive candidates more easily, exposing them to further risks.”

How to stay safe

To protect yourself from the risk of identity theft, it’s crucial to keep a close eye on all of your accounts. Monitoring your cards, statements, and transactions for any suspicious activity means that you can quickly identify any issues.

If a service you use has suffered a data breach, make sure you change your password – and probably your passwords to any site that would hold sensitive information. If you’d like some tips on how to choose a secure password, we’ve listed some here.

In short, include capital and lowercase letters, numbers, and special characters – and never reuse a password, especially for sites that carry important information like health or financial data.

If that all seems a little overwhelming, we’ve tested out all the best password managers and the best password generators to simplify the process.

Phishing attacks are most commonly delivered in the form of emails, so be very cautious of any email that urges you to take action, or one which rushes you to click a link or download a file.

Double check any domain names and email addresses, like supp0rt@google instead of support@google, as this is a big indicator that something may not be right.

We’ve made a comprehensive guide on how to spot a phishing email for anyone who wants to make sure they’re wise to scammer’s tricks.

You might also like

​ 

This articles is written by : Nermeen Nabil Khear Abdelmalak

All rights reserved to : USAGOLDMIES . www.usagoldmines.com

You can Enjoy surfing our website categories and read more content in many fields you may like .

Why USAGoldMines ?

USAGoldMines is a comprehensive website offering the latest in financial, crypto, and technical news. With specialized sections for each category, it provides readers with up-to-date market insights, investment trends, and technological advancements, making it a valuable resource for investors and enthusiasts in the fast-paced financial world.

Recent:

Best smart lighting 2025: Smart bulbs, string lights, outdoor, and more | usagoldmines.com

This TCL QLED Is One of the Best Budget-Friendly TVs I've Ever Used Daniel Oropeza | usagoldmines.co...

Five of My Favorite Cheap Storage Solutions Lindsey Ellefson | usagoldmines.com

The Two Biggest Mistakes Beginners Make on the Rowing Machine Beth Skwarecki | usagoldmines.com

Netflix Raises Prices in the UK Juli Clover | usagoldmines.com

Apple Removed Apps Infested With Screen Reading Malware Juli Clover | usagoldmines.com

White House budget proposal could shatter the National Science Foundation Eric Berger | usagoldmines...

Nintendo patent explains Switch 2 Joy-Cons’ “mouse operation” mode Kyle Orland | usagoldmines.com

Changing Your Passwords Isn't the Security Measure You Think It Is Jake Peterson | usagoldmines.com

Google Search App for iOS Now Supports Auto Dark Mode Juli Clover | usagoldmines.com

Leica's new iPhone camera grip could have been great, but has 3 frustrating drawbacks mark.wilson@fu...

This flexible and transparent microLED display eliminates mass transfer and laser welding processes ...

Apple built a super-cute, expressive robot lamp that is giving us major Pixar vibes jacob.krol@futur...

DeepSeek iOS app sends data unencrypted to ByteDance-controlled servers Dan Goodin | usagoldmines.co...

How to Control an Android Phone From Your Computer Justin Pot | usagoldmines.com

Seven of My Favorite Money-Saving Meals Allie Chanthorn Reinmann | usagoldmines.com

Alleged Foldable iPhone Specs Detailed in Questionable Rumor Juli Clover | usagoldmines.com

Apple's New Invites App Hints at iOS 19's Rumored Redesign Joe Rossignol | usagoldmines.com

Screen reading malware found in iOS app stores for first time - and it might steal your cryptocurren...

NYT Connections hints and answers for Friday, February 7 (game #607) | usagoldmines.com

NYT Strands hints and answers for Friday, February 7 (game #341) | usagoldmines.com

Quordle hints and answers for Friday, February 7 (game #1110) | usagoldmines.com

ChatGPT comes to 500,000 new users in OpenAI’s largest AI education deal yet Benj Edwards | usagoldm...

Meta torrented over 81.7TB of pirated books to train AI, authors say Ashley Belanger | usagoldmines....

Best Chromebooks 2025: Best overall, best battery life, and more | usagoldmines.com

This 4K laptop with RTX 4080 and 64GB RAM is a whopping $800 off | usagoldmines.com

How to Nap at Work (and Get Away with It) Jeff Somers | usagoldmines.com

Best Buy Is Giving Away a Free TV When You Buy One of These Massive Samsung LED TVs Daniel Oropeza |...

Microsoft reveals more on just how much it'll cost you to keep using Windows 10 | usagoldmines.com

Protection from COVID reinfections plummeted from 80% to 5% with omicron Beth Mole | usagoldmines.co...

The UK got rid of coal—where’s it going next? Gordon Feller | usagoldmines.com

You Need to Clean Your Humidifier More Than You Think Lindsey Ellefson | usagoldmines.com

Five Easy Ways to Hide Cords and Cables in Your Home Jeff Somers | usagoldmines.com

Disney Plus just lost 700,000 subscribers, but that won’t stop another price hike – far from it hami...

Nvidia out? DeepSeek pairs with banned Chinese tech giant to deliver unbelievably low pricing on AI ...

Google Chrome's Incognito mode is now more private in Windows 11 - and it's all thanks to Microsoft ...

Parrots can imitate meaningless behavior almost as well as humans Elizabeth Rayne | usagoldmines.com

Google’s Gemini rolls out ‘world’s best’ AI model, free of charge | usagoldmines.com

ChatGPT’s new AI search beats Google in this one thing | usagoldmines.com

Is the new AI-powered Alexa almost here? 6 things to know | usagoldmines.com

ASRock says it’s shifting out of China to avoid U.S. tariffs | usagoldmines.com

Warner Bros. Is Uploading Classic Movies to YouTube for Free Jake Peterson | usagoldmines.com

25 of the Best Romantic Comedies Streaming on Netflix Right Now Ross Johnson | usagoldmines.com

Apple Prototypes Tabletop Robot With Lifelike Movements Ahead of Rumored Launch by 2027 Joe Rossigno...

Google Pixel 9a: latest news, rumors, and everything we’ve heard so far | usagoldmines.com

Salesforce rival builds advanced project management into CRM | usagoldmines.com

Laptop makers, I’m begging you for this one simple feature | usagoldmines.com

Super Bowl LIX streaming and viewing options, ranked | usagoldmines.com

I built a maxed-out Raspberry 5 mini PC with an SSD for under $200. You can too | usagoldmines.com

Today’s best laptop deals: Save big on work, school, home use, and gaming | usagoldmines.com

More Windows 11 patch woes, this time with mouse pointers acting up | usagoldmines.com

These tiny security updates make Google Chrome so much better | usagoldmines.com

This uber mini PC packs a Ryzen 9 and 32GB RAM for just $500 | usagoldmines.com

Most HP printer models have these critical security flaws. Update now! | usagoldmines.com

This slim 10K power bank is only $10 today | usagoldmines.com

Corsair’s new pegboard shelf adds workshop chic to your desk | usagoldmines.com

You can now use AI in Teams to improve poor quality video calls | usagoldmines.com

Update now! This 7-Zip exploit bypasses crucial Windows protections | usagoldmines.com

Need a portable laptop monitor? Get this one for just $60 right now | usagoldmines.com

Bill Gates: ‘Intel lost its way’ | usagoldmines.com

Chrome’s Incognito mode no longer saves copied stuff to clipboard history | usagoldmines.com

OnePlus 13’s Free Double Storage Promo Reaches Final Hours, $500 Cheaper Than Galaxy S25 Ultra Kelle...

Google Photos Adds Digital Watermark for Your Fake, AI-Generated Images Kellen | usagoldmines.com

Threads Now Lets You Share Custom Feeds, Just like Bluesky Khamosh Pathak | usagoldmines.com

How to Clean Your Mac's Keyboard Pranay Parab | usagoldmines.com

Former iPhone 7 Owners Begin Receiving Up to $349 Following Lawsuit Joe Rossignol | usagoldmines.com

Let’s Encrypt halts expiration alerts - but it's for a good reason | usagoldmines.com

2025 Genesis Electrified GV70 review: Wait for the next model year Jonathan M. Gitlin | usagoldmines...

Don’t panic, but an asteroid has a 1.9% chance of hitting Earth in 2032 Stephen Clark | usagoldmines...

US lawmakers push to quickly ban DeepSeek on government devices Ashley Belanger | usagoldmines.com

These tiny security updates make Google Chrome so much better | usagoldmines.com

‘Table for Two’ Encourages You to Pause to Enjoy the Romance of Food Allie Chanthorn Reinmann | usag...

Google Just Launched Gemini 2.0 Flash and Pro for Users and Developers David Nield | usagoldmines.co...

This Ring Doorbell Is Down to Its Lowest Price Ever Pradershika Sharma | usagoldmines.com

All the Gardening Tasks You Should Complete in February Amanda Blum | usagoldmines.com

iOS 18.3.1 Update Coming Soon for iPhones Joe Rossignol | usagoldmines.com

Anker Valentine's Day Sale Offering Big Discounts on Charging Accessories Mitchel Broussard | usagol...

I've seen most of 2025’s flagship robot vacuums and let me tell you, things are about to get weird j...

Invincible season 3 changes Oliver Grayson's shocking and violent coming-of-age moment for the bette...

Veeam backup software has a serious security flaw - here's how to stay safe | usagoldmines.com

Apple's Base 128GB iPhone Storage Tier Needs to Go Tim Hardwick | usagoldmines.com

Leica Announces $329 'LUX Grip' Camera Accessory for iPhone Hartley Charlton | usagoldmines.com

New iPhone Feature for Tracking Lost Baggage Expands to More Airlines Joe Rossignol | usagoldmines.c...

Netflix is getting 2 huge thrillers that I can’t wait for, with Robert De Niro, Gillian Anderson and...

Hurry! It's your last chance to save serious money on the Samsung Galaxy S25 Ultra with these pre-or...

Metal Gear Solid Delta: Snake Eater could launch in August, per new leak dash.wood@futurenet.com (Da...

KitchenAid reveals its color of the year for 2025 – and I want to eat it out of a tub with a spoon ...

Cisco patches critical security issues, so update now | usagoldmines.com

Should you buy Nikon’s new Coolpix P1100? Here are 5 things you need to know about the updated 125x ...

Amazon drops unsubtle hints that Alexa AI is landing soon – 3 things to expect from the new voice as...

Humans not needed: AI-powered autonomous drones fused with RFID technology set to revolutionize ware...

Microsoft authentication system spoofed via phishing attack | usagoldmines.com

ChatGPT Search is now free for everyone, no OpenAI account required – is it time to ditch Google? jo...

Spotify will 'double down' on music in 2025, but does that mean Hi-Fi or AI? | usagoldmines.com

New Nvidia GeForce RTX 5060 Ti and RTX 5060 rumor suggests they could end up being great budget buys...

Does Monster Hunter Wilds have crossplay? | usagoldmines.com

Samsung’s Google Messages rival isn’t dead after all – in fact, it’s just been upgraded jamie.richar...

Zyxel says it won’t patch security flaws in its old routers | usagoldmines.com

Apple's M5 chip is rumored to be in mass production - but we're still waiting for M4 MacBook Airs |...

How to combat exfiltration-based extortion attacks | usagoldmines.com

Leave a Reply