77 Comments
- brianbb98, on 10/10/2007, -4/+261Someones gonna need to find a new job.
- delgotit99, on 10/10/2007, -2/+141Hopefully whoever stole it is hiring.
- jonrad, on 10/10/2007, -8/+63RTFA
Monster.com wasn't hacked. Some recruiter accounts were compromised and are being used to retrieve information that you've already posted on there. Unless you post your SS when you look for jobs, there's nothing to worry about.
Move on - Salgat, on 10/10/2007, -0/+45I have an account there, but fortunately its all stuff that was meant to be public anyways.
- hexydes, on 10/10/2007, -0/+28lol, I logged in to check my information (I haven't been to Monster in ages). The first screen that popped up was one of those "Want to win $10,000 to pay off your college loan debt?! Enter your social security number and press submit (information will be transmitted securely)."
Thought that was sort of entertaining in an ironic sort of way. - himey, on 10/10/2007, -2/+24If only there were somewhere online where they could post a resume......
- op12, on 10/10/2007, -0/+18I read the article. And there is something to worry about (for some people), as the personal information is gathered to send more convincing emails that look like they're from Monster, and lead you to download a trojan. I bet having personal information in that email makes a lot of people think it's legit:
"Furthermore, Trojan.Gpcoder.E has reportedly been spammed in Monster.com phishing emails. These emails were very realistic, containing personal information of the victims. They requested that the recipient download a Monster Job Seeker Tool, which in fact was a copy of Trojan.Gpcoder.E. This Trojan will encrypt files in the affected computer and leaves a text file requesting money to be paid to the attackers in order to decrypt the files. The code for Gpcoder is rather similar to that of Monstres, which may indicate the same hacker group is behind both Trojans." - kefkastudio, on 10/10/2007, -1/+13Well.. they do have my full name, address, phone, email, a list of competencies and all of my credentials since I was 18.. Now they can send me all sorts of soliciting calls, junk mail and spam that tailors to my interests.
oh ***** - cleverboy, on 10/10/2007, -1/+8jonrad, giving phishers more information to use IS a problem as op noted. It's one thing for a phisher to profile you by looking up your public information and researching a good e-mail to contact you at. It's another for a phisher to have that on 1.6 million people. Imagine every spam message you get referring to you by your first and last name. I've been getting some odd offers from Seattle recently, allegedly from some recruiter. Might be real, might be fake... but a number of these in the past then proceed to ask you for more private information through a trumped up website that looks half-legit.
MONSTER WAS HACKED. Look up the word. Your server does not need a software vulnerability to get hacked through the human vulnerability. If Walmart.com got hacked, people aren't going to say "Oh, its not really 'hacked' because it was a manager's computer who's password was compromised so that the hacker could send himself user data." No... it would just be HACKED. The website wasn't defaced and the server's software did not have a vulnerability exploited. The website was hacked though. Vulnerable users are a tried and true facet of hacking ***** everywhere. - ahussain1986, on 10/10/2007, -0/+6You post ur SS# on ur resume?
- PDave, on 10/10/2007, -1/+7But but but... didn't they have Norton?
- akeema, on 10/10/2007, -0/+4I think this means I might actually get a response back from some of those recruiters that post 1,000 tech jobs a day !
- JonRohan, on 10/10/2007, -0/+3Monster.com, today's the day.
- BradMajors, on 10/10/2007, -0/+3This isn't new. I have determined that spam I received almost a year ago could only have originated from my resume posted on Monster.
- dogstylee, on 10/10/2007, -0/+3I've used Monster before and found several ***** pyramid schemes and home-selling-crap they list as job adverts.
- broeks, on 10/10/2007, -0/+3Dice.com is better for people like us :)
- macfanboi, on 10/10/2007, -0/+3Is this a worm or a shady Recruiter? I don't know the difference.
- mohamedmansour, on 10/10/2007, -0/+3@raftytaffy "Another great reason why microsoft windows and windows server is the best and most secure."
http://toolbar.netcraft.com/site_report?url=http://www.monster.com Returns LINUX not Windows. Stop hating, and stop trolling - cleverboy, on 10/10/2007, -1/+4Jesus. I just supplied Monster with its own email alias. I didn't realize they still had my real one. I guess that's why I've been getting more spam lately. Mystery solved. Dammit.
- allisonaxe, on 10/10/2007, -0/+2hopefully the hackers will see my resume and offer me a job. monster alone hasn't given me any good listings, and i'm not convinced that the people who are in a position to hire me have even gotten it.
considering i gave monster no credit card info, and only my resume, which only consists of personal information that i'd really hope a few more people would see, i'm not that worried. BUT it would be nice if i'd get some actual GOOD job hits..... plus, since i've listed with them (and careerbuilder, to be fair) I've gotten more spam in my inbox than i ever have before (and i've managed to keep this particular email address relatively spam-free for the 6 years that i've had it.) - DarkDragon, on 10/10/2007, -0/+2OS Web Server
Linux Microsoft-IIS/6.0
Either their spoofing OS or Webserver (WINE =P) - JohnnyXmas, on 10/10/2007, -0/+2Yeah, anyone whos ever posted on Monster.com already knows that Monster sells their user information to every ***** Spammer on the planet. Nothing was compromised, so much as it was just "given away for free" this time.
- sgglynn, on 10/10/2007, -0/+2sweet, I had to get my resume out there some how.
- stork123, on 10/10/2007, -1/+3maybe the spammers will hire me
- mbthompson, on 10/10/2007, -0/+2Yep, same boat. Fortunately I didn't give them my primary email account, just the gmail one I use most of the time.
- K3ITHK, on 10/10/2007, -1/+3Anonymous!
- icsbase, on 10/10/2007, -0/+2@mohamedmansour
@raftytaffy "Another great reason why microsoft windows and windows server is the best and most secure."
http://toolbar.netcraft.com/site_report?url=http://www.monster.com Returns LINUX not Windows. Stop hating, and stop trolling
Something does not add up there on Netcraft. OS says Linux but the webserver is Microsoft-IIS/6.0. They use Akamai services which again use Linux so the real os behind Monster.com propably is Windows and that Linux is just another redirect by Akamai. - 2275617, on 10/10/2007, -0/+2This is not "hacking". I mean please, it's just an automated way of gathering information that one could have obtained had they just took their time "cutting" and "pasting". The report said the "hack" required an account holder to log in and search the database. Well any account holder could search the database and simply maintain a copy on their server, isn’t that the same thing? So I don't really see this as a hack.
- finezapa, on 10/10/2007, -1/+2monster.com is flooded with crap. careerbuilder and craigslist ftw!
- brokekneck, on 10/10/2007, -4/+5Monster.com sux anyways. Only jobs they list on that site are setup through temps. monster.com IS just one big ass temp agency.
- mal1964, on 10/10/2007, -3/+4Wow that's a coincides, My site about Monster movies called "Jobs" got hacked also.
- CalmLlama, on 10/10/2007, -0/+1it is the most secure, with over 7 unhacked servers running, windows server is the best product on the market right now!
- wattznext, on 10/10/2007, -0/+1The on you use MOST of the time isn;t your PRIMARY account? Either you don't understand english or you don;t understand email. Or both.
- Incognito, on 10/10/2007, -0/+1***** I was registered on there
Its all old info though - antdude, on 10/10/2007, -0/+1Haha, I checked mine too (haven't logged in since 2002 or so). I also got the same screen! Wow.
- dugem1, on 01/20/2008, -0/+1That's great find
http://www.nasavo.com
http://www.nasavo.com/acne
http://www.nasavo.com/forex
http://car.nasavo.com
http://www.jurugan.com
http://health.jurugan.com
http://www.vrid.net
http://laptop.vrid.net
http://projector.vrid.net
http://tire.vrid.net
http://hyip.ej.am
http://car.ej.am
http://health.bryansoft.com
http://hyipnews.freehostia.com
http://hyipnews.freehostia.com/hyip - Dilz, on 10/10/2007, -1/+2I had been wanting a reason to cancel my account and this is a great one! They have 24 hour customer service via India. (Sunitha was very polite and cooperative...)
From http://help.monster.com:
"If you'd still rather cancel your Monster account, please call 1-800-MONSTER (1-800-666-7837). You may be asked for your email address, first name, last name, street address, city, state, country, zip code, and phone number. Once we verify your information, we will be able to cancel your account."
Feel free to give them a call! :P - JayCruz, on 10/10/2007, -0/+1Monster.com sucks scrotum's!
- FiP0, on 10/10/2007, -0/+1But if you just changed the email monster has, isn't it too late ?
- inactive, on 10/10/2007, -1/+2you wont mind if i send your CV (edited) to your boss then telling him you're looking for a new job in chicken farming and grooming young boys?
- Ryosen, on 10/10/2007, -0/+1Here's a tip. A recruiter will never ask you for your password and will never ask you to download and run a program via email. Common sense.
- Xtopherous, on 10/10/2007, -0/+1Careerbuilder is no better. All my spam is basically due to my former CB and Monster accounts (which I closed a long time ago, but it's too late now, Sydney Car Center has my address and they won't quit!). They both are basically hubs for scammers, temp agencies (head hunters) and the Army. At least with craigslist, they don't have all your personal information to sell off and/or have stolen.
- antdude, on 10/10/2007, -0/+1http://www.informationweek.com/story/showArticle.jhtml?articleID=201800958 for the older story.
- THirD3ye, on 10/10/2007, -0/+1I knows, my feet hurt. When will I ever learn.
- endersshadow, on 10/10/2007, -0/+1Well, I was lucky then, cause I just got a great job via Monster.
As for this, it explains why I'm getting job offers that want me to download and take a test for them...even though I've taken myself off Monster now that I'm employed...dammit. - jepizacar, on 08/22/2008, -0/+1nice resource....
http://topforex.co.cc
http://skincare.freehostia.com
http://acnecare.890m.com
http://acne.ej.am
http://gofinance.890m.com
http://fastcar.890m.com
http://carbeauty.co.cc
http://gadingan.com
http://gadingan.com/indexsc.php
http://gadingan.wordpress.com
http://23ltd.info
http://jeniya.info - inactive, on 10/10/2007, -1/+2"tailors to my interests"
Oh ***** is right. You're going to look stupid with all those alternative lifestyle mags falling out of your mailbox. - PseudoNim, on 10/10/2007, -0/+0Apparently USAjobs.com (the government site) was affected (according to ZDNet). So what is the government doing? In a flash of brilliance, *emailing job seekers that they may get phished.*
Hm... AN URGENT NOTICE FROM THE US GOVERNMENT! YOU MUST IMMEDIATELY UPDATE YOUR INFORMATION. - dansko, on 10/10/2007, -0/+0Maybe they have also stolen Credit card numbers ?>
http://www.born-shoes.org -
Show 51 - 77 of 77 discussions



What is Digg?
Browsing Digg on your phone just got easier with our enhancements to the