UK government jobs website exploited by hackers

Hackers have been able to exploit security flaws in a new government jobs website to steal personal information about job applicants

Hackers have been able to exploit security flaws in a new government jobs website to steal personal information about job applicants.

The Universal Jobmatch website has been described as a "scammer's paradise" in a Channel 4 News investigation, which uncovered security flaws that enabled access to data including passport scans.

The new site was launched on 19 November to replace the Jobcentre Plus website, which was shown to be vulnerable to hackers in 2011.

According to reports, a fake job ad placed by a group of hackers seeking to draw attention to the site’s security flaws was able to harvest the personal details of more than 70 jobseekers, the report said.

Such information could be used for identity fraud or illegal access to email, bank accounts and other online accounts of job applicants.

No security checks are carried out on advertisers, which means anyone is able to register as an employer and publish job vacancies without any vetting taking place.

The website’s security vulnerabilities have been reported to the UK’s privacy watchdog, the Information Commissioner’s Office, which is tasked with enforcing the country’s data protection laws.

In a statement, the Department of Work and Pensions, said: "The site clearly advises jobseekers not to give out personal details such as bank accounts or National Insurance numbers until a job offer has been made. Anybody seeking to acquire personal data by publishing fake job adverts should be aware this is potentially an attempt to commit fraud and that is a criminal offence.

"The security of a claimant's data is of the utmost importance to us and we have a number of checks in place when employers register to use the site. Sadly, there will always be a small number of cases where people seek to get around these checks. If someone is being asked for personal information or details beyond their CV we would recommend they alert Jobcentre Plus immediately."

Read more on Privacy and data protection