CRPx0 Ransomware Hits Hyundai Turkey: Why Recruitment Data Is a Bigger Target Than You Think
A late-July 2026 attack on Hyundai Motor Türkiye's recruitment systems shows why HR and hiring data deserves the same protection as financial records.
What happened
On 31 July 2026, the ransomware group CRPx0 claimed an attack on Hyundai Motor Türkiye, publishing roughly 1.5GB of stolen data on its leak site. Unlike a typical customer-data breach, what CRPx0 took was HR and recruitment material: candidate assessment results, proctored exam data, and executive assessment reports. The group listed Tox and Session messenger IDs for ransom negotiation — a deliberate choice to avoid centralised infrastructure that could be seized.
This isn't Hyundai's first brush with ransomware. Its European division was hit by Black Basta in 2024, and Hyundai AutoEver America disclosed a breach affecting millions of customer records in 2025. Three incidents in three years at the same corporate group suggests the problem isn't one bad afternoon — it's a pattern.
Why this matters if you're not a car manufacturer
Recruitment and HR platforms are consistently under-scrutinised compared to finance or customer databases, even though they hold exactly the kind of sensitive personal data — assessments, background checks, salary expectations — that's valuable to attackers and painful to have leaked. If your business uses a third-party applicant tracking system, an HR SaaS tool, or even a shared drive for CVs and interview notes, it's worth asking the same questions you'd ask about your customer database: who has access, is it backed up separately, and would you know if someone exported it all at once?
What to actually do
- Audit who has access to your recruitment/HR tools — ex-employees and old integrations are the usual culprits.
- Don't assume a "small" HR dataset isn't worth protecting — assessment and interview data is personal data under GDPR regardless of size.
- If you use a third-party HR platform, ask about their own security posture — you're trusting them with your candidates' data.
Repeat incidents at the same organisation are a reminder that a one-off audit isn't enough — continuous monitoring catches drift that a single point-in-time check misses.
Sources: GBHackers, CyberPress
$ ./get-your-score
Get a free Security Score for your site
Automated TLS, headers, DNS, and exposure checks — results in under a minute.
Request a free scan