A recent staffing agency ransomware attack has exposed sensitive personal data belonging to job seekers and employees at Cornerstone Staffing Solutions. Criminals behind the attack claim they stole hundreds of thousands of documents, including detailed resumes and internal business files. The incident highlights the risks faced by recruitment firms that store large volumes of personal information.

How the attack unfolded

The staffing agency ransomware attack targeted Cornerstone Staffing Solutions, which operates across several U.S. states. Attackers infiltrated internal systems, stole large data sets and then threatened to leak the material unless the agency paid. Soon after the breach, the criminals published samples to prove the theft and attempted to increase pressure on the company.

Their claims include the theft of more than 300 GB of data. The stolen material reportedly contains over 120,000 resumes, around one million internal files and roughly 24 million individual data points tied to job candidates, employees and business operations.

What information was exposed

The leaked resumes held detailed personal information. Many included names, home addresses, phone numbers, employment histories, Social Security numbers and education records.
Attackers also released samples of internal documents that showcased employee lists, payroll details, banking information, invoices and internal communications. The scale and sensitivity of this data make the breach particularly damaging.

The exposed information can enable identity theft, financial fraud, phishing and impersonation attempts. Criminals often use resume data to craft convincing scams, including fake job offers and fraudulent onboarding requests.

Who carried out the attack

The staffing agency ransomware attack was carried out by the Qilin ransomware group. Qilin runs a ransomware-as-a-service model. Affiliates infiltrate organisations, exfiltrate data, encrypt systems and demand payment. If the victim refuses, Qilin publishes stolen material on leak sites to damage the victim’s reputation.

Qilin is known for targeting organisations that handle large pools of personal data, including service providers, healthcare groups and professional firms. The group relies on multi-stage compromise, credential theft and aggressive extortion tactics.

Impact on job seekers and organisations

For job seekers, the staffing agency ransomware attack brings long-term risk. Criminals now have access to highly detailed personal profiles. These profiles can be used to open fraudulent accounts, run targeted scams or impersonate victims in job-related schemes.

For organisations, the attack serves as a warning about the threat level in the staffing and recruitment sector. Agencies store extensive personal information, maintain large digital archives and rely on fast internal processes. These conditions make them high-value targets for criminals.

How affected individuals should respond

Anyone who worked with Cornerstone Staffing Solutions should stay alert for suspicious communication. They should review account activity, freeze credit if necessary and enable strong authentication across key services.
Individuals must also remain cautious of unexpected job offers, document requests or emails that reference previous employment searches. Criminals often use stolen resume data to run long-play social engineering campaigns.

Conclusion

The staffing agency ransomware attack against Cornerstone Staffing Solutions exposed a significant amount of sensitive personal information. With more than 120,000 resumes and millions of internal records leaked, the incident highlights the severe risks facing recruitment firms. Job seekers and organisations must treat this breach seriously, strengthen their security habits and stay aware of potential fraud attempts linked to the stolen data.


0 responses to “Staffing agency ransomware attack exposes over 120,000 resumes”