
It has been confirmed that personal information of corporate members was leaked from the hiring management solution Nine Hire. The leaked information includes the names and account email addresses of corporate member users. The company stated that passwords, login authentication information, phone numbers for identity verification, payment details, and personal information of applicants managed by Nine Hire were not leaked.
According to a personal information leak notice sent by Nine Hire to its members on the 18th, the company confirmed on the 15th that unauthorized external access occurred to the server storing member information, resulting in a data breach. Nine Hire stated, "We sincerely apologize for causing concern to our valued members who have trusted and used our service."
Nine Hire is a hiring management solution used in corporate recruitment processes for managing applicants, operating recruitment procedures, and scheduling interviews. As a service utilized by hiring managers and corporate HR teams, this incident could escalate beyond a simple email leak into a broader SaaS security issue for recruitment platforms.
However, the company drew a clear line by stating that applicant personal information was not leaked. Nine Hire specified that non-leaked data includes passwords, login authentication information, phone numbers for identity verification, payment details, and applicant personal information managed by Nine Hire. The company explained that whether individual members were affected would be communicated only to them after logging in.
After confirming the incident, Nine Hire blocked the access path used in the attack and stopped the misuse of member inquiry functions. Related servers were also isolated. The company reported the leak to the Korea Internet & Security Agency (KISA) and the Personal Information Protection Commission (PIPC). It further stated that it is checking for additional leaks and strengthening access control and systems for detecting and monitoring abnormal activities.
Nine Hire urged members to be cautious of impersonation emails, as leaked email addresses could be exploited in phishing attempts or account takeover attacks. A company representative said, "Nine Hire never requests passwords, authentication codes, or payment information via email." Members were advised not to respond to suspicious emails but to report them to the company's inquiry channel. The company also recommended changing passwords if the same password is used across multiple services.
For those who have suffered damage or suspect an issue, reports can be submitted through Nine Hire's in-service chat support or customer support email. The company stated that it will review the reported content to assess its connection to the incident and provide individual notifications regarding findings and support measures.
This incident once again highlights vulnerabilities in enterprise SaaS security. Hiring management solutions often handle sensitive data beyond corporate contact information, including applicant resumes, phone numbers, interview evaluations, and recruitment stage details. Although Nine Hire confirmed no leak of applicant personal information, the need for stricter access control and management of inquiry functions on recruitment platforms is expected to come into focus.
As personal information leaks continue to recur, the responsibility for security management in enterprise business solutions is growing. Particularly with B2B SaaS services where multiple corporate accounts converge on a single platform, a single breach can expose individual corporate contacts' email addresses to phishing attacks, potentially leading to further account takeover attempts. Even if the scope of leakage is limited, preventive measures against subsequent damage are necessary.
Nine Hire stated, "We will provide updates on any newly confirmed facts and responsibly implement measures to verify damages and prevent recurrence."