Limited DisclosureThis breach is handled differently. Because being connected to it can itself be sensitive, we do not confirm anyone’s presence publicly.
Breach Risk Index i
44/100
Lower riskHigher risk
Moderate: notable exposure with meaningful misuse potential.
Data Sensitivity i
Restricted
Being associated with this breach can itself be harmful. Disclosure is limited and presence is not confirmed to unverified parties.
50KRecords
2021Year
The Breach Risk Index (BRI) is a proprietary 0–100 score rating how dangerous a breach is right now, based on how recently the data has been circulating on the dark web and how valuable it is to attackers.
In October 2021, the Singaporean recruitment website Protemps suffered a data breach that exposed almost 50,000 unique email addresses. The impacted data includes names, email and physical addresses, phone numbers, passport numbers and passwords stored as unsalted MD5 hashes, among troves of other jobseeker data.
Full threat analysis, exploitation vectors, and principal guidance below.
10 additional sections · verified field analysis · defensive doctrine
Querying breach corpus…
Cross-referencing exposed field types…
Resolving threat-actor attribution…
Compiling principal risk advisory…
50K records analyzed
About Protemps
Protemps is a singaporean recruitment website.
Why They Hold Your Data
Protemps is a singaporean recruitment website. Services like this typically hold email addresses, names, gender, job application data, nationality, passport numbers, passwords, phone numbers, physical addresses, relationship status, religion, salutation through account registration and normal operations.
Recent Developments
The Protemps dataset circulated publicly; treat as part of the standing exposure landscape.
Data Points Exposed
12 verified field types
Email Address
Full Name
Gender
Job Application Data
Nationality Or Citizenship
Passport Number Critical
Password High
Phone Number
Physical address High
Relationship Status
Religion
Salutation
Breach Impact
The exposure of credentials alongside personal data heightened account-takeover and reuse risk for Protemps users and drew scrutiny of its data protection.
Exploitation & Downstream Threats
• Credential stuffing against reused passwords across other platforms | • SIM swap attacks where phone numbers are present | • Targeted phishing campaigns using exposed email addresses | • Doxxing risk from physical address exposure
Principal Risk Advisory
What this means for a principal
A consumer-service breach: contact and account data supports phishing, account takeover and profile enrichment. For a high-profile principal this is targeting-grade, not merely identity-theft-grade: the combination lets an adversary locate, impersonate, or pressure the principal with little additional work.
What You Should Do
Freeze credit at all three bureaus and monitor for new-account and tax-refund fraud.
Treat the home address as exposed: review mail and package handling and physical-security routines, and brief household staff to verify unusual requests.
Reset any reused passwords and enable MFA on email first, then financial accounts.
Guard against SIM-swap and vishing: add a carrier port-out PIN and verify any 'support' calls independently.
Do not use unofficial 'am I affected' lookups; several are themselves harvesting operations.
How ObscureIQ Can Help
Corpus confirmation: determine whether and where the principal (plus household and staff) appear in this dataset and which specific fields are exposed for them.
Exposure mapping and footprint neutralization: cross-reference against broker-available data and suppress still-removable elements, prioritizing address and phone, since this record re-seeds broker networks.
ThreatWatch tuned to this incident's identifiers and misuse pattern (impersonation and targeting patterns, not generic credential monitoring).
Protect Yourself
High-Risk? Get an Exposure Audit
Executives, public figures, and high-visibility operators can receive tailored exposure intelligence and hardening guidance.