DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

Glassdoor email gaffe exposers users’ email addresses

Posted on July 22, 2016 by Dissent

So Glassdoor updated its terms of service, and dutifully notified its users by putting all their email addresses in the TO: field.  Yeah, you read that right.

And no one apparently noticed before hitting SEND.

Leading to a second email later today:

Dear Glassdoor User:

Earlier today we inadvertently exposed your email address to other
recipients during a routine e-mail distribution regarding changes to our
Terms of Use.

We are extremely sorry for this error. We take the privacy of our users
very seriously and we know this is not what you expect of us. It certainly
isn’t how we intend to operate.

If you have any questions, please contact us at [email protected].

Sincerely,
The Glassdoor Team

Thanks to Jeanne Price for letting me know about this one. I wonder whether anyone hit reply-all as that would have been quite a storm. 🙂

Update: The number affected may be on the order of 600,000.

No related posts.

Category: Business SectorExposure

Post navigation

← Laser & Dermatologic Surgery Center notifies 31,000 of possible PHI compromise
Wikileaks posts nearly 20,000 hacked DNC emails online →

8 thoughts on “Glassdoor email gaffe exposers users’ email addresses”

  1. Donna says:
    July 25, 2016 at 11:53 am

    So I got won of these apology emails, but what does this breach mean?

    1. Dissent says:
      July 25, 2016 at 1:16 pm

      Not much, actually, except that depending on whether you used a tagged/throwaway email address with them, you might start receiving more spam or phishing attempts.

  2. Javier says:
    July 26, 2016 at 11:54 am

    What a coincidence, that right after I get this message when logging into Glassdoor:

    “We have temporarily disabled your account. We have identified that your password matches one you have used on an unrelated website that has experienced a security breach. Please ​reset your password here.”

    So they screwed with their own security and now try to blame some fictional 3rd party website (how would they know what password I use in that unrelated website? how would they have access to that information? Just tell me which website had that breach, I will decide whether to change my password)

  3. Fulano De Tal says:
    July 28, 2016 at 9:04 pm

    Javier, I got the same message. Seems to me like if they wanted to be helpful they might actually name the “unrelated site” instead of leaving that account wide open.

  4. Anonymous says:
    July 29, 2016 at 9:30 pm

    I also got the email We have temporarily disabled your account. We have identified that your password matches one you have used on an unrelated website that has experienced a security breach. Should I be concerned?

    1. Dissent says:
      July 29, 2016 at 9:46 pm

      Were you notified by the “unrelated web site,” too? If not, yeah, you should be concerned enough to insist Glassdoor tell you who the other site was so you can contact THEM and ask them what data of yours were compromised, etc. And if you used the same login credentials at a third or fourth or fifth site, better change all your passwords.

  5. Jim says:
    August 2, 2016 at 3:14 am

    Can someone forward me the email?

    1. Dissent says:
      August 2, 2016 at 7:50 am

      No, because I remove email addresses from submissions. I posted the notification email in the story itself.

Comments are closed.

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • Hunters International to provide free decryptors for all victims as they shut down (1)
  • SEC and SolarWinds Seek Settlement in Securities Fraud Case
  • Cyberattacks Disrupt Iran’s Bread Distribution, Payments Remain Frozen
  • Hacker with ‘political agenda’ stole data from Columbia, university says
  • Keymous+ Hacker Group Claims Responsibility for Over 700 Global DDoS Attacks
  • Data breach reveals Catwatchful ‘stalkerware’ is spying on thousands of phones
  • DOJ investigates ex-ransomware negotiator over extortion kickbacks
  • Hackers Using PDFs to Impersonate Microsoft, DocuSign, and More in Callback Phishing Campaigns
  • One in Five Law Firms Hit by Cyberattacks Over Past 12 Months
  • U.S. Sanctions Russian Bulletproof Hosting Provider for Supporting Cybercriminals Behind Ransomware

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • Record-Breaking $1.55M CCPA Settlement Against Health Information Website Publisher
  • Ninth Circuit Reviews Website Tracking Class Actions and the Reach of California’s Privacy Law
  • US healthcare offshoring: Navigating patient data privacy laws and regulations
  • Data breach reveals Catwatchful ‘stalkerware’ is spying on thousands of phones
  • Google Trackers: What You Can Actually Escape And What You Can’t
  • Oregon Amends Its Comprehensive Privacy Statute
  • Wisconsin Supreme Court’s Liberal Majority Strikes Down 176-Year-Old Abortion Ban

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net

Mastodon: Infosec.Exchange/@PogoWasRight

Signal: +1 516-776-7756

DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.