Skip to content

MyNewTerm Applicant Data on 142,653 Users Offered as a One Time Sale

Breach Report United Kingdom Education Recruitment One Time Sale

MyNewTerm Applicant Data on 142,653 Users Offered as a One Time Sale

A forum actor posting as 888 is selling what they describe as the database of MyNewTerm, a recruitment platform built for the education sector that handles the hiring cycle for schools and trusts from job advert through interview scheduling, references and onboarding. The post claims a breach in August 2026 exposing 142,653 unique users and attributes it to the poster directly. Samples show two layers: vacancy listings with school names, salary ranges and locations, and an applications layer carrying candidate email addresses, the role applied for, application status, start dates and free text recruiter notes. The sale is offered once, in Monero. The claim is unverified.

Unique users142,653
SaleOne time
PaymentMonero
Actor888

Post details

TargetMyNewTerm
CountryUnited Kingdom
SectorEducation recruitment
ListingOne time sale, Monero
Volume142,653 unique users
Stated sourceDirect breach claimed
Observed
Actor888

!What the post claims

  • 142,653 unique users
  • Breach dated August 2026
  • Candidate email addresses
  • Role applied for
  • Application status
  • Offer and hire outcomes
  • Rescinded or withdrawn flags
  • Job reference numbers
  • Job start dates
  • Onboarding owner
  • Free text recruiter notes
  • How each applicant heard of the role
  • Trust and establishment IDs
  • Vacancy listings
  • School names and towns
  • Salary ranges
  • Visa sponsorship flags
  • Post codes and coordinates

Screenshots

Forum post offering the MyNewTerm database for sale, observed 25 August 2026.

Mapped techniques

The post asserts a breach but describes no method. Both entries are inferred from the artefacts.

  • Collection T1213 Data from information repositories Inferred Two joined layers exported together with internal identifiers, version columns and soft delete flags indicate a database export rather than scraping of the public job board.
  • Exfiltration T1567 Exfiltration over web service Inferred Samples are posted inline and the sale is arranged through forum and messenger contact. The route out of the environment is not described.

Potential impact

The two layers are worth very different amounts. Vacancy listings are already public, since school job adverts are published by design, so that half adds little beyond convenience. The applications layer is the problem. It records who applied for which role at which school, what happened to that application, and in many cases a free text note written by the recruiter, including remarks about conversations and personal connections to the school. Job applications are made in confidence and usually by people already employed somewhere else, so the exposure here is not only an email address, it is the fact of having applied, and of having been rejected, withdrawn or had an offer rescinded. The population is also a specific one. These are teaching assistants, cleaners, lunchtime supervisors, invigilators and cover staff, often low paid and often new to a school's systems, which makes them unusually good targets for onboarding themed fraud. An approach quoting a genuine job reference, the correct school and a real start date, asking for identity documents or background check payment, would be very difficult for a recent applicant to distinguish from the real process.

iStatus Unverified

The samples are substantial and internally coherent, running across two related tables with consistent identifiers, plausible reference formats for the sector, and the kind of untidy free text that real recruitment records accumulate and fabricated ones rarely do. The account is also unusually established, holding moderator status with a long history and high standing on the forum, which within that setting is a reputational stake worth something. None of that establishes how the data was obtained, and no method, access route or timeline is described beyond a month. Because part of the set is public job advert data, a sample check on the vacancy layer proves nothing; only the applications layer is diagnostic. Dark Web Informer has not retrieved the data and is not linking it, nor the contact address. MyNewTerm has not publicly addressed the claim. Any school or trust using the platform would have its own notification position to consider, since the applicant records belong to their processes.

Dark Web Informer // Threat Intelligence

Latest