Back to News
Market Impact: 0.25

Naukri exposed recruiter email addresses, researcher says

Technology & InnovationCybersecurity & Data PrivacyManagement & Governance

Naukri.com, a leading Indian employment website, has resolved a security vulnerability in its mobile app API that exposed recruiter email addresses when they viewed candidate profiles. Security researcher Lohith Gowda discovered the bug, which could have led to targeted phishing attacks and spam, but Naukri's parent company, InfoEdge, stated that no unusual activity affecting user data integrity was detected. The company has implemented enhancements to ensure system resilience following the disclosure.

Analysis

Naukri.com, a prominent Indian employment platform and a subsidiary of InfoEdge, recently rectified a security vulnerability within its mobile application API. This flaw, identified by security researcher Lohith Gowda, inadvertently exposed the email addresses of recruiters when they accessed candidate profiles via Naukri's Android and iOS applications, though the website remained unaffected. The exposure carried potential risks including targeted phishing campaigns, unsolicited emails, and the possibility of these email addresses being incorporated into public breach databases or spam lists, potentially leading to automated bot abuse. TechCrunch independently verified the vulnerability before its remediation. InfoEdge's IT infrastructure head, Alok Vij, confirmed the issue was resolved and stated that system enhancements have been implemented to bolster resilience, further noting that internal teams detected no unusual activity compromising user data integrity. Vij also contextualized that certain recruiter profile elements are intentionally public to facilitate user interaction and transparency regarding profile access, and affirmed the company's commitment to regular security audits. This incident, while resolved, underscores the persistent cybersecurity challenges faced by digital platforms handling sensitive user information, even as Naukri.com maintains its position as India's leading classified recruitment website with operations extending to the Middle East.

AllMind AI Terminal

AI-powered research, real-time alerts, and portfolio analytics for institutional investors.

Request a Demo

Market Sentiment

Overall Sentiment

mixed

Sentiment Score

-0.05

Key Decisions for Investors

  • Investors in InfoEdge should note the company's swift remediation of the identified security flaw, which appears to have mitigated immediate data breach concerns according to the company's statements.
  • The event serves as a reminder of the ongoing operational risks associated with cybersecurity for online platforms; continued vigilance regarding InfoEdge's security protocols and investments in data protection is warranted.
  • Monitor for any potential, albeit currently unstated, reputational impact or changes in user trust, particularly among recruiters, although the company's assertion of no detected data misuse limits immediate financial concerns.
  • Given the low market impact score and the company's proactive response, the incident may not significantly alter InfoEdge's near-term financial outlook, but patterns of such events could become a concern if they recur.