DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

Glassdoor email gaffe exposers users’ email addresses

Posted on July 22, 2016 by Dissent

So Glassdoor updated its terms of service, and dutifully notified its users by putting all their email addresses in the TO: field.  Yeah, you read that right.

And no one apparently noticed before hitting SEND.

Leading to a second email later today:

Dear Glassdoor User:

Earlier today we inadvertently exposed your email address to other
recipients during a routine e-mail distribution regarding changes to our
Terms of Use.

We are extremely sorry for this error. We take the privacy of our users
very seriously and we know this is not what you expect of us. It certainly
isn’t how we intend to operate.

If you have any questions, please contact us at emailcare@glassdoor.com.

Sincerely,
The Glassdoor Team

Thanks to Jeanne Price for letting me know about this one. I wonder whether anyone hit reply-all as that would have been quite a storm. 🙂

Update: The number affected may be on the order of 600,000.

Category: Business SectorExposure

Post navigation

← Laser & Dermatologic Surgery Center notifies 31,000 of possible PHI compromise
Wikileaks posts nearly 20,000 hacked DNC emails online →

8 thoughts on “Glassdoor email gaffe exposers users’ email addresses”

  1. Donna says:
    July 25, 2016 at 11:53 am

    So I got won of these apology emails, but what does this breach mean?

    1. Dissent says:
      July 25, 2016 at 1:16 pm

      Not much, actually, except that depending on whether you used a tagged/throwaway email address with them, you might start receiving more spam or phishing attempts.

  2. Javier says:
    July 26, 2016 at 11:54 am

    What a coincidence, that right after I get this message when logging into Glassdoor:

    “We have temporarily disabled your account. We have identified that your password matches one you have used on an unrelated website that has experienced a security breach. Please ​reset your password here.”

    So they screwed with their own security and now try to blame some fictional 3rd party website (how would they know what password I use in that unrelated website? how would they have access to that information? Just tell me which website had that breach, I will decide whether to change my password)

  3. Fulano De Tal says:
    July 28, 2016 at 9:04 pm

    Javier, I got the same message. Seems to me like if they wanted to be helpful they might actually name the “unrelated site” instead of leaving that account wide open.

  4. Anonymous says:
    July 29, 2016 at 9:30 pm

    I also got the email We have temporarily disabled your account. We have identified that your password matches one you have used on an unrelated website that has experienced a security breach. Should I be concerned?

    1. Dissent says:
      July 29, 2016 at 9:46 pm

      Were you notified by the “unrelated web site,” too? If not, yeah, you should be concerned enough to insist Glassdoor tell you who the other site was so you can contact THEM and ask them what data of yours were compromised, etc. And if you used the same login credentials at a third or fourth or fifth site, better change all your passwords.

  5. Jim says:
    August 2, 2016 at 3:14 am

    Can someone forward me the email?

    1. Dissent says:
      August 2, 2016 at 7:50 am

      No, because I remove email addresses from submissions. I posted the notification email in the story itself.

Comments are closed.

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • Mysterious leaker GangExposed outs Conti kingpins in massive ransomware data dump
  • Resource: HoganLovells Asia-Pacific Data, Privacy and Cybersecurity Guide 2025
  • Class action settlement following ransomware attack will cost Fred Hutchinson Cancer Center about $52 million
  • Comstar LLC agrees to corrective action plan and fine to settle HHS OCR charges
  • Australian ransomware victims now must tell the government if they pay up
  • U.S. Sanctions Cloud Provider ‘Funnull’ as Top Source of ‘Pig Butchering’ Scams
  • Victoria’s Secret takes down website after security incident
  • U.S. Government Employee Arrested for Attempting to Provide Classified Information to Foreign Government
  • St. Cloud Provides Update on Ransomware Attack in 2024
  • Bradford Health Systems detected abnormal network activity in December 2023. They first sent out breach notices this week.

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • Resource: HoganLovells Asia-Pacific Data, Privacy and Cybersecurity Guide 2025
  • She Got an Abortion. So A Texas Cop Used 83,000 Cameras to Track Her Down.
  • Why AI May Be Listening In on Your Next Doctor’s Appointment
  • Watch out for activist judges trying to deprive us of our rights to safe reproductive healthcare
  • Nebraska Bans Minor Social Media Accounts Without Parental Consent
  • Trump Taps Palantir to Compile Data on Americans
  • The US Is Storing Migrant Children’s DNA in a Criminal Database

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net

Mastodon: Infosec.Exchange/@PogoWasRight

Signal: +1 516-776-7756

DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.
Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report