• About WordPress
    • WordPress.org
    • Documentation
    • Learn WordPress
    • Support
    • Feedback
Skip to content
May 26, 2026
  • Linkedin
  • Twitter
  • Facebook
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Watchtower
  • Cyber Criminals
  • Data Leak
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Vulnerability Report
Light/Dark Button
  • Home
  • News
  • Data Leak
  • HR software PageUp has been compromised by malicious software
  • Data Leak

HR software PageUp has been compromised by malicious software

Ddos June 7, 2018 3 minutes read

According to ZDNet, PageUp, an Australian-based human resource (HR) software company, has confirmed that its IT infrastructure was found to have abnormal activity last month, which may lead to leakage of customer data.

According to the information displayed on the PageUp company’s official website, the company’s main business is to provide customers with HR software-as-a-service, allowing customers to recruit from anywhere in the world through a unified talent management platform. Employees are trained, trained and managed. The platform currently has more than 2 million active users and covers more than 190 countries worldwide.

The company has branches in many countries and regions around the world, including New York, United Kingdom, London, Singapore, Philippines, Manila, Hong Kong, China, Sydney, Australia, and Melbourne. Its large clients include the chocolate brand Lindt, Australia’s largest logistics company LinFox, the Reserve Bank of Australia (RBA), Zurich Insurance and Victoria University.

On May 23, after discovering that the system was infected with malware, the company immediately conducted an in-depth investigation. After a five-day investigation, the company said that its concerns have been confirmed, and some indicators in the survey results indicate that some customer data are likely to have been leaked.

The company said in a statement: “If any personal data has been affected it could include information such as name and contact details. It could also include identification and authentication data e.g. usernames and passwords which are encrypted (hashed and salted). There is no evidence that there is still an active threat, and the jobs website can continue to be used. All client user and candidate passwords in our database are hashed using bcrypt and salted; however, out of an abundance of caution, we suggest users change their password.”

Karen Cariss, the company’s chief executive officer, and co-founder emphasized that both the signed employment contract and the resume are stored on different infrastructures and there is no evidence that the infrastructure on which the files were stored was destroyed. He also said that PageUp has been working with international law enforcement agencies, government agencies and independent security experts to fully investigate the matter. Therefore, it is not yet possible to provide more details on what information is affected.

“Since becoming aware of unauthorised access we have been urgently analysing the impact and consequences of this incident and have engaged independent digital forensic expertise, who have been attempting to identify what, if any personal data may have been accessed. That said, we can share that the source of the incident was a malware infection. The malware has been eradicated from our systems and we have confirmed that our anti-malware signatures can now detect the malware. We see no further signs of malicious or unauthorised activity and are confident in this assessment.“

Telstra, an Australian telecommunications service provider, also issued a statement regarding the PageUp incident, stating that in most cases the personal information that may be affected is the applicant’s name, telephone number, application history, and email address. For those who apply for success, the data in the PageUp system may include a date of birth, employment details, employee number (if present or former), pre-employment check results, and arbitration details.

PageUp also stated that it had contacted the Australian Cyber Security Center (ACSC), the Australian Computer Emergency Response Team (CERT), the Australian Information Commissioner’s Office (OAIC) and the National Cyber Security Center (NCSC) on the matter and suggested The user changes his own password.

Rate this post

Support Our Threat Intelligence

If you find our CVE report and cybersecurity news helpful, consider supporting our work.

Buy Me a Coffee Logo Buy Me a Coffee PayPal
Crypto QR Code
USDT (TRC20):
TN8BdV8cp4T1Cd28gK9qTAnZknzzuwyUtm
USDT (ERC20):
0x3725e1a7d3bc5765499fa6aaafe307fabcd75bce

Share this article:

Facebook Post LinkedIn Telegram

Related posts:

  1. Email address and some 3.3 million passwords of Dutch people leak
  2. US Comcast website leaks Xfinity customer data
  3. AndroCon: New Study Shows How Your Phone Can Track Your Every Move, Even Indoors
  4. Elon Musk’s xAI Sues Ex-Engineer Over Stolen Grok AI Secrets
  5. LinkedIn to Use Your Data for AI Training. Here’s How to Opt Out
Tags: HR software PageUp

Search

Translation

CVE WATCHTOWER
🚨

Receive alerts for vulnerabilities being exploited in the wild.

⚡

Get notified instantly when a Proof of Concept (PoC) exploit is published.

🔍

Access critical info on vulnerabilities even when marked as "RESERVED".

🧠

Insights powered by decades of expertise and global intelligence sources.

🎯

Customize alerts with up to 10 keywords for your specific tech stack.

📊

Export the raw CVE database for SIEM integration and reporting.

Upgrade Package

🔴 Live Critical Threats

  • CVE-2026-42773CVSS 9.3
    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')...
  • CVE-2026-42774CVSS 9.3
    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')...
  • CVE-2026-9478CVSS 9.8
    A weakness has been identified in Totolink A8000RU 7.1cu.643_b20200521. Impacted is the...
  • CVE-2026-9477CVSS 9.8
    A security flaw has been discovered in Totolink A8000RU 7.1cu.643_b20200521. This issue...
  • CVE-2026-9476CVSS 9.8
    A vulnerability was identified in Totolink A8000RU 7.1cu.643_b20200521. This vulnerability affects the...
  • CVE-2026-9475CVSS 9.8
    A vulnerability was determined in Totolink A8000RU 7.1cu.643_b20200521. This affects the function...
  • CVE-2026-9458CVSS 9.8
    A vulnerability was identified in Totolink A8000RU 7.1cu.643_b20200521. The impacted element is...
  • CVE-2026-9457CVSS 9.8
    A vulnerability was determined in Totolink A8000RU 7.1cu.643_b20200521. The affected element is...
  • CVE-2026-9456CVSS 9.8
    A vulnerability was found in Totolink A8000RU 7.1cu.643_b20200521. Impacted is the function...
  • CVE-2026-9455CVSS 9.8
    A vulnerability has been found in Totolink A8000RU 7.1cu.643_b20200521. This issue affects...
Powered by CVE WATCHTOWER

Recent Zero-Day Vulnerabilities

  • Exploited in the Wild: Critical OWA Spoofing Flaw (CVE-2026-42897) Hits On-Premises Exchange Servers
  • Exploited in the Wild: Maximum CVSS 10 SD-WAN Flaw (CVE-2026-20182) Grants Admin Control
  • Exploited in the Wild: Critical 9.8 CVSS RCE Hits Canon GUARDIANWALL MailSuite
  • Exploit Code Released: Public PoC Dumps for Windows BitLocker Bypass and SYSTEM Elevation Zero-Days
  • Exploited in the Wild: “Dirty Frag” Linux Vulnerability Grants Instant Root Access
  • Under Active Attack: Ivanti EPMM Zero-Day Exploited in the Wild via Harvested Admin Credentials
Our Websites
  • Penetration Testing Tools
  • The Daily Information Technology
  • Daily CyberSecurity

    • About SecurityOnline.info
    • Advertise with us
    • Announcement
    • Contact
    • Contributor Register
    • Login
    • About SecurityOnline.info
    • Advertise on SecurityOnline.info
    • Contact Us

    When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

    • Disclaimer
    • Privacy Policy
    • DMCA NOTICE
    • Linkedin
    • Twitter
    • Facebook
    • Youtube
    Copyright Daily CyberSecurity © All rights reserved.