Naukri.com exposedthe email addresses of employers who used its platform to search and hire candidates online.
See also: 3AM ransomware: Spoofed IT calls, email bombing to breach networks

The issue was discovered by security researcher Lohith Gowda and involved an API used by Naukri in its Android and iOS apps. The API exposed the email addresses of employers who visited candidate profiles on Naukri’s platform. The flaw did not appear to affect the website . The researcher added that the exposed email addresses could be added to databases or spam lists, while the bulk collection of email addresses could lead to abuse by automated bots or scams.
TechCrunch confirmed the data leak after the researcher shared details of the bug. The researcher confirmed that the issue was fixed earlier this week, which Naukri also confirmed on Friday.
See also: Microsoft bans the word "Palestine" in internal emails
Naukri.com, founded in March 1997, is India's leading job posting website, facilitating connections between employers, recruiters and job seekers. In addition to India, the platform also operates in the Middle East under the name Naukrigulf.com.

The Naukri case highlights the importance of cybersecurity on job search platforms, where sensitive personal data, such as emails and professional profiles, is shared. Such errors can lead not only to privacy breaches, but also to potential malicious actions, such as phishing attacks or abuse by automated bots.
See also: Phishing emails distribute Horabot malware in Latin America
The company's immediate response and collaboration with security researchers is a positive example of responsible cybersecurity management. At the same time, it highlights the need for continuous monitoring and upgrading of technological infrastructure, especially on internationally active platforms such as Naukri.com and Naukrigulf.com.
Source: techcrunch
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
