-
A forum actor using the handle 888 claims to have breached MyNewTerm and obtained data linked to 142,653 users.
-
Reported samples include applicant emails, job records, school details, salaries, vacancy data, and application status information.
-
MyNewTerm has not confirmed the claim. The full dataset, user count, and source remain unverified.

A threat actor claims to have breached MyNewTerm, a UK recruitment platform for schools and education groups. The actor uses the handle 888. Reports say the actor posted the database on an underground forum on August 25.
The listing says the data came from an August 2026 breach. HackNotice also recorded the claim and named 888 as the alleged attacker.
HackNotice lists fields from the alleged database. They include trust IDs, job positions, appointment IDs, vacancy references, start dates, onboarding data, email addresses, and status fields.
Other reports say 888 offered the data as a one-time sale for Monero. There is no public evidence that shows how the actor gained access to MyNewTerm.
Samples Show Recruitment and Applicant Records
The reported samples appear to contain more than basic contact details. They include email addresses, job positions, appointment IDs, job reference numbers, vacancy data, start dates, and recruitment status.
Other reported fields include school and trust IDs, job titles, locations, salary ranges, contract types, and subject or department data. The samples also appear to show different stages of an application. These include offers, recruitment, withdrawals, and other status changes.
That matters because recruitment data can reveal much more than an email address. A leaked record could show where a person applied. It could show the job they wanted. It could also show how far their application went.
This is not the only recent case involving alleged stolen recruitment data. A hacker has also claimed the sale of 422,000 records from Saudi recruitment platform Mihnati, highlighting the growing value of employment and applicant information on underground markets.
The data could link an applicant to a school, trust, role, salary range, or vacancy. Some vacancy details may already appear on public job pages. But linking those details to applicant records could give attackers a much clearer picture.
MyNewTerm Handles Sensitive Hiring Data
MyNewTerm describes itself as a UK education job board and applicant tracking system. The company says more than 6,000 schools and 500 multi-academy trusts use its platform across the UK. The service supports many types of education jobs. These include teaching, school leadership, support, admin, technical, catering, and trustee roles.
MyNewTerm says candidate profiles can store employment history, qualifications, references, and other details needed for job applications. Its registration page also shows that users can enter names, addresses, phone numbers, job preferences, and visa sponsorship needs.
The platform lets candidates apply to employers and track their applications through one account. That gives the service access to a wide range of hiring data.
The Alleged Data Could Aid Targeted Scams
If the database proves genuine, the exposure could create risks beyond spam. Someone with applicant emails and job details could send convincing phishing messages. An attacker could mention a real school or job. They could also mention an application status. That could make a fake message look like a real hiring update.
Recruitment data could also help attackers impersonate schools, trusts, recruiters, or applicants. The risk grows when attackers combine email addresses with real job details. They could use those details to create messages that look like normal recruitment emails. There is no evidence yet that attackers have used the alleged data in follow-on attacks.
MyNewTerm Lists Several Security Controls
Based on MyNewTerm’s security overview, the platform encrypts data when it’s in transit using TLS 1.2 or above. Additionally, it states that it uses AES-256 encryption for its databases and file systems.
Moreover, the company claims that it restricts access to its production systems. It uses role-based access control and multi-factor authentication as well. MyNewTerm has also stated that it does vulnerability scanning and security patching regularly. It also says it monitors threats and maintains an incident response plan.
A UK government Digital Marketplace listing also describes real-time security monitoring and procedures for handling possible compromises. Those controls do not confirm or disprove the breach claim.
Strong security controls can reduce risk. But they cannot prove that an attack did not happen. The key question remains whether someone accessed MyNewTerm systems without permission.
No Public Confirmation of the Breach
As of September 14, there’s been no public confirmation from MyNewTerm of a breach matching the forum claim. The company continues to operate its website and recruitment service.
The current evidence comes mainly from the underground listing, reported samples, breach-monitoring services, and posts from researchers tracking the claim.
That evidence makes the allegation worth watching. It does not prove that the full database contains 142,653 people. It also does not show that every record came directly from MyNewTerm. Some data could have come from another source.
For now, the alleged MyNewTerm data breach remains merely claims until independent researchers or MyNewTerm itself confirm it and reveal the full scope.