On mySimon: Joovy Caboose Ultralight Sunset
BNET Business Network:
BNET
TechRepublic
ZDNet

January 26th, 2009

Monster.com hacked; user ID, e-mail, phone numbers stolen

Posted by Andrew Nusca @ 12:28 pm

Categories: Security

Tags: Andrew Nusca

Monster.com recently posted a PSA on their site notifying users that their database was illegally accessed and certain contact and account data were taken, “including Monster user IDs and passwords, email addresses, names, phone numbers, and some basic demographic data.”

The information accessed does not include resumes.

“Monster does not generally collect – and the accessed information does not include - sensitive data such as social security numbers or personal financial data.”

Monster says they initiated an investigation and took corrective steps, and so far, have not detected misuse of the information.

The company also says users may soon be required to change your password upon logging onto the site, but when I logged in after reading the bulletin, I was not prompted to change my password in any way.

It must also be noted that as a registered user of the site, I was not e-mailed or notified by Monster.com directly about the breach, and only found it doing my normal news-gathering rounds on the web. This is not exactly best business practice for a breach of this nature; it should be noted that Monster has a poor history of waiting before notifying users of its site of security risks.

Of course, with an exposed e-mail address at risk, beware of future “phishing” emails; also, avoid using the same passwords across multiple sites as a precaution for this type of breach.

UPDATE 1/27/09: Looks like the UK got hit for 4.5 million users, and no word on the other 35 countries Monster operates in.

Andrew NuscaAndrew J. Nusca is an associate editor for ZDNet and SmartPlanet. See his full profile and disclosure of his industry affiliations.


Email Andrew NuscaFollow on Twitter

Subscribe to The ToyBox via Email alerts or RSS.

Related Discussions on TechRepublic

Did you know you can take part in these discussions with your ZDNet membership?

  • Talkback
  • Most Recent of 12 Talkback(s)
Re: Monster.com hack
I've gotten jobs, but not one from Monster. I told them last year they were hacked. They said I didn't know what I was talking about. Do you think they told me I was hacked? No! They don't have my soc... (Read the rest)
Posted by: roberts_theodore@... Posted on: 01/29/09 You are currently: a Guest | | Terms of Use
Monster Security  techie_yoshi | 01/26/09
RE: Monster.com hacked; user ID, e-mail, phone numbers stolen  daileyml | 01/27/09
Big freaking deal  Roger Ramjet | 01/27/09
It matters to some  JimSim | 01/27/09
With Caution  west1234 | 01/27/09
Monster.com wrecking their own site  Professor8 | 01/27/09
RE: Monster.com hacked; user ID, e-mail, phone numbers stolen  roberts_theodore@... | 01/27/09
Monster was the bomb back in 2005..  JCitizen | 01/27/09
RE: Monster.com hacked; user ID, e-mail, phone numbers stolen  dinosaur_z | 01/27/09
Re: Monster.com hack  roberts_theodore@... | 01/29/09
some link  rjvargas | 01/28/09
HA! HA!...  JCitizen | 01/28/09

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

advertisement
Click Here

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads

SmartPlanet

Click Here