A threat actor claims to be selling a database from MyNewTerm containing 142,653 unique users tied to the UK education recruitment platform.
The listing appeared on an underground cybercrime forum on Aug. 25 and claims the dataset was obtained from MyNewTerm in August 2026. The seller provided samples showing recruitment-related fields including email addresses, job positions, appointment identifiers, job reference numbers, vacancy sources, start dates and recruitment status information.
MyNewTerm is an applicant tracking system and job board built for the education sector. According to the company, the platform is used by more than 6,000 schools and 500 multi-academy trusts across the UK and supports recruitment from vacancy posting through interviews, references and onboarding.
Samples contain recruitment and candidate data
The sample published with the claim appears to contain records associated with people who applied for or secured jobs through the platform. Fields include email addresses, job titles, appointment IDs, establishment numbers, recruitment source information, job start dates and statuses such as recruited or offered.
The seller also published a second set of records containing vacancy and school information, including employer names, counties, salary ranges, contract terms, job categories, locations, closing dates and trust information.
BreachNews is not reproducing the leaked email addresses, identifiers or other personal information contained in the samples.
The presence of structured records consistent with an education applicant tracking system adds substance to the claim, but it does not independently verify the seller’s assertion that 142,653 unique users were affected or establish how the data was obtained.
MyNewTerm sits inside school recruitment workflows
MyNewTerm describes itself as a dedicated applicant tracking system for schools, colleges and multi-academy trusts, allowing employers to manage candidate applications, interviews, references and onboarding through a single platform.
The company says candidate profiles can store employment history, qualifications, references and other information used when applying for education jobs.
The leaked sample shared publicly in the forum post does not appear to expose that full candidate profile dataset. Instead, the records visible in the claim center on recruitment workflow data and email addresses associated with applications and appointments.
Exposure could reveal sensitive employment history
If authentic, the dataset could create privacy risks beyond ordinary contact information because it may reveal where individuals applied for jobs, which positions they pursued, whether they were offered or recruited, and how they learned about vacancies.
That information could be useful for targeted phishing or impersonation attempts against teachers, support staff, school administrators and other education-sector workers.
The sample also appears to contain recent vacancy records dated into August 2026, suggesting at least part of the material may come from a current or recently updated system rather than an entirely historical archive.
The education sector remains a frequent target for data theft and extortion. Recent BreachNews coverage includes an alleged breach of King of the Curve involving MCAT student profiles and activity data, while ShinyHunters recently published data allegedly stolen from Glendale Community College following an extortion deadline.
Claim remains unconfirmed
The seller describes the dataset as a one-time sale but has not publicly disclosed how MyNewTerm was allegedly compromised.
BreachNews has not independently verified the full database or confirmed the claimed total of 142,653 unique users.
MyNewTerm had not issued any public statement addressing the alleged breach at time of publication. Its website remained operational when checked by BreachNews.











