Switch Data Breach (2024): What Was Exposed & What To Do
SourceBreach data provided in part by Have I Been Pwned, used under CC BY 4.0.
Switch Data Breach (2024) was disclosed on 01 October 2024, exposing the email addresses, names, job applications and social media profiles of about 5,000 individuals. Anyone who has applied for a job or otherwise shared personal details with Switch is advised to verify whether their information was compromised and to take appropriate protective steps.
In October 2024, people who had applied for IT roles through the Hungarian headhunting service Switch learned that personal details from their job applications had been left exposed online. For the roughly five thousand individuals whose records were involved, the practical stakes are straightforward: names, email addresses and application materials that were meant for recruiters became publicly reachable, creating openings for unwanted contact, phishing or misuse of professional information.
The incident, reported on 1 October 2024, involved an inadvertent exposure rather than a sophisticated intrusion. Understanding what is known—and what remains limited—helps those affected decide what steps to take next.
Breaking down the breach
According to the reported details, Switch, a Hungarian IT headhunting service, inadvertently exposed thousands of customer records via a public GitHub repository in October 2024. The exposure affected approximately 5,000 people. The data that became accessible included job applications containing names, email addresses and, in some cases, commentary on the applicant. Social media profiles were also among the data types named as exposed.
Public reporting does not provide further technical specifics such as how long the repository remained public, the exact number of files involved, or the precise moment the exposure was discovered and closed. No additional methods of compromise beyond the public GitHub repository are described. The incident is therefore characterised as an inadvertent exposure of customer records rather than a confirmed external attack.
How a breach like this happens
Incidents of this type typically arise when sensitive files or databases are placed in a code-hosting service such as GitHub and the repository’s visibility setting is left public instead of private. Developers or staff sometimes upload data for temporary collaboration, testing or backup purposes and overlook the access controls. Once public, the repository can be indexed by search engines or discovered by automated scanners that look for exposed credentials and personal information.
In general, no advanced hacking technique is required; the data simply becomes reachable to anyone who finds the link. Organisations that handle recruitment data often store application packages, candidate notes and contact details in formats that are convenient for internal use but risky if the storage location is not properly restricted. The absence of any attributed threat group in this case is consistent with an accidental misconfiguration rather than a targeted campaign.
About Switch
Switch operates as an IT headhunting service based in Hungary. Firms of this kind specialise in matching technology professionals with employers, collecting and reviewing job applications, curricula vitae, contact details and sometimes evaluative notes about candidates. Because recruitment work depends on accurate personal and professional information, these organisations routinely hold names, email addresses, career histories and related profile data.
A breach at a headhunting service is consequential precisely because the data is both personal and career-related. Applicants entrust the firm with information they expect to remain confidential between themselves and potential employers. When that trust is broken, the consequences extend beyond the organisation to the individuals whose professional identities and contact details have been exposed.
What data was at risk
The facts name the following data types as exposed: email addresses, job applications, names and social media profiles. The reported summary further states that the exposed records contained job applications with names, email addresses and, in some cases, commentary on the applicant.
Exact contents beyond these categories are not further itemised in public reporting. Organisations that perform IT recruitment typically also hold additional materials such as full CVs, telephone numbers or employment histories, yet those elements are not confirmed as present in this exposure. Readers should therefore treat only the named categories as verified and regard any other possible fields as unconfirmed.
Why it matters
For the people whose records were exposed, the immediate risks are concrete. Email addresses and names can be used to craft targeted phishing messages that appear to come from recruiters or employers. Job-application details and any accompanying commentary may reveal career aspirations, salary expectations or personal assessments that an individual would prefer to keep private. Social-media profile information can help an adversary build a fuller picture of the person for social-engineering purposes.
For Switch itself, the exposure raises questions of trust among candidates and client companies that rely on the firm’s discretion. Even when an incident is inadvertent, the practical result is the same: personal data that should have remained under controlled access became publicly available. The scale—approximately five thousand people—means a non-trivial number of individuals now face the need to monitor for misuse of their professional contact details.
What to do if you're exposed
If you applied for roles through Switch or otherwise supplied personal information to the service, treat the named data types as potentially compromised. Change passwords on any accounts that share the same email address, enable multi-factor authentication where available, and remain alert for unsolicited messages that reference job applications or recruitment. Consider reviewing the privacy settings on any social-media profiles that may have been linked.
You can also run a free exposure scan of your email address to check whether your information has already surfaced in known breach data sets. Doing so provides an additional, independent way to assess whether further protective steps are warranted.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Speedio Data Breach (2024)Young Living Essential Oils Data Breach (2024)Senior Dating Data Breach (2024)FlipaClip Data Breach (2024)Latest breaches
Read GalaxyWarden’s full analysis of the Switch Data Breach (2024) →
Verified breach. Breach data provided in part by Have I Been Pwned, used under CC BY 4.0.
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.