A threat actor is claiming to have breached Z.ro Global’s internal recruitment platform and obtained the company’s entire candidate evaluation pipeline, allegedly exposing 55,866 candidate records alongside CVs, interview recordings, AI-generated assessments, and proprietary hiring logic.
The dataset was listed for sale on August 13, 2026. According to the threat actor, the material covers recruitment activity processed through the platform from its inception through August 8 and was obtained through a vulnerability that allegedly allowed access without authentication.
Z.ro Global had not issued any public statement regarding the alleged incident at time of publication.
Candidate records reportedly include full CV data
The threat actor claims the database contains 55,866 candidate records with extensive personally identifiable and employment-related information.
According to the listing, the allegedly exposed information includes:
- Full names
- Personal email addresses
- Phone numbers
- Detailed employment histories
- Full CV text extracted from uploaded documents
- Internal candidate evaluation scores
- AI-generated competency assessments
- Candidate progression and decision timelines
- Audio recordings from candidate interviews
The inclusion of CV content makes the alleged exposure broader than a conventional recruitment database. Resumes can contain years of employment history, education details, professional qualifications, contact information, and other information candidates provided specifically for hiring purposes.
AI scoring system allegedly exposed
Beyond candidate information, the threat actor claims the stolen material contains internal components of Z.ro Global’s AI-assisted recruitment system, which the listing describes as being powered by LangGraph.
The allegedly exposed material reportedly includes prompts used during candidate evaluation, scoring weights, decision thresholds, confidence values, and fallback logic used by the platform when determining whether applicants should advance through the hiring process.
The seller also claims the database preserves internal hiring states showing how individual candidates were scored across different evaluation dimensions and includes AI-generated assessments used during the recruitment workflow.
If authentic, the exposure would provide unusually detailed visibility into both the information collected about applicants and the internal logic used to evaluate them. It could also reveal proprietary recruitment technology and potentially allow affected candidates to determine how automated systems characterized their applications.
Interview recordings increase sensitivity of the leak
The claimed presence of full interview audio significantly increases the sensitivity of the alleged breach. Unlike ordinary account information, voice recordings cannot simply be changed following a security incident.
Audio associated with identifiable candidates could potentially be abused for impersonation, targeted social engineering, or AI-generated voice cloning if the recordings are authentic and sufficiently clear.
The threat actor claims 25 sample candidate records were provided with the sale listing, including some audio material. BreachNews has not independently verified the sample or confirmed that the records originated from Z.ro Global.
Access allegedly required no authentication
The seller claims the recruitment data was exfiltrated through a vulnerability that exposed the platform without requiring authentication. No detailed technical evidence was provided publicly to independently establish the access method, and BreachNews is not publishing information that could facilitate access to any affected system.
The actor additionally claims to have validated a random set of 500 candidate records against publicly available professional profiles and reported a 100% match rate. That verification was performed by the seller and should not be treated as independent confirmation of the dataset’s authenticity.
Recruitment data creates targeted social engineering risk
If the dataset is genuine, candidates could face risks extending beyond ordinary spam or credential theft. Detailed employment histories, recruitment status, interview information, and internal evaluations could give attackers highly specific material for targeted phishing and impersonation attempts.
Someone with access to the data could potentially craft messages referencing real job applications, previous employers, interview stages, or other details known only to candidates and recruiters. That level of context can make fraudulent recruitment communications substantially more convincing.
The alleged exposure of internal AI prompts and candidate scoring logic adds another dimension to the incident because the claimed dataset would contain both sensitive applicant information and proprietary information about how hiring decisions were made.
BreachNews has not independently confirmed the claimed 55,866-record breach, the authenticity of the interview recordings, or the alleged unauthenticated access. The threat actor is offering the purported dataset for sale rather than publishing the complete archive publicly.











