2025 Info Edge / Naukri — mobile API flaw exposed recruiter emails when viewing profiles
Data compromised
Recruiter email addresses exposed through predictable API responses
Technical writeup
A reported logical flaw in Naukri's mobile application API let unauthenticated callers harvest recruiter email addresses associated with candidate profile views; Info Edge representatives quoted in TechCrunch confirmed remediation steps after independent disclosure in May 2025 and argued no integrity compromise of broader resume databases in their public response.
Root cause
Insecure direct object reference / authorization gap on mobile API endpoints (per researcher and TechCrunch narrative)