NOS News•today, 5:53 PM
The UWV reports that someone viewed and possibly downloaded 150,000 CVs on werk.nl last Saturday. The UWV website brings employers and job seekers together. The leak has been reported to the Dutch Data Protection Authority and the UWV will also report it. The UWV knows who it is, but the identity of the person has not been disclosed.
“It is very unfortunate that CVs have probably been viewed and possibly downloaded on such a large scale for improper use,” says Judith Duveen, director of Work Company at UWV. “We immediately took appropriate measures and will inform the people involved as best as possible about the consequences of this undesirable mass access and possible download.”
People with benefits and without benefits can use werk.nl to find a job. They can put their CV on the website so that future employers can view and save it. As is often the case with CVs, the documents contain all kinds of personal data, such as names and contact details.
Very rich sources
The intention is that they end up with a potential future employer, but viewing and collecting these CVs on a large scale is of course not the case. “This is against the terms of use,” the benefits agency writes. “That is why UWV considers this as an action for suspected use for improper purposes.”
It is not the first time that someone has plundered the werk.nl database. In 2019, 117,000 CVs were already downloaded. Afterwards, the UWV installed monitoring software to monitor whether this happens more often. Saturday’s case was detected as a result.
It is still unclear who stole the CVs and why. The UWV therefore knows who it is and says that it is in any case not a UWV employee.
“There is a lot of data in CVs: names, addresses, dates of birth, education. So they are very rich sources,” says a spokesperson for the Dutch Data Protection Authority. “If you combine this with other data, you can really build up an extensive profile with a view to scamming, for example through very targeted phishing emails.”
Tags: CVs viewed possibly downloaded
-