Michael Cooney
Senior Editor

Morgan Stanley abused CareerBuilder.com personal information to make sales calls, state says

Opinion
Oct 1, 20073 mins

Massachusetts is charging financial advisors from Morgan Stanley in Boston with improperly accessing CareerBuilder .com to download resumes and collect personal information of job seekers in an effort to solicit business on behalf of Morgan Stanley.  The state also says Morgan Stanly advisors broke state and national Do Not Call registries by making   “several hundred calls.”Court papers state at least one advisor downloaded over 1,000 resumes contain personal and financial information. 

The use of such information for sales purposed is a breach of contract between Careerbuilder.com and Morgan Stanley, as the financial firm was to only use such information for recruitment purposes only, the state says. The state is seeking a cease and desist order for Morgan Stanley  as well as  fines and compensatory damages to people it contacted according to court papers filed by the Mass. Securities Division, the securities enforcement arm of  Massachusetts Secretary of State William F. Galvin.

Job  recruitment websites in general are under the gun for not securing information contained on their sites. Monster.com disclosed on Aug. 23 that it had discovered a data breach caused by hackers who posed as employers, then illegally downloaded the names, addresses, phone numbers and e-mail addresses of 1.6 million job-seekers. The hackers then sent e-mail to the users in an attempt to collect their passwords to financial sites or to install viruses on their PCs. Monster has posted a Web page listing antifraud advice, and asked its users to forward any suspicious e-mail to the company. Earlier this year attackers launched targeted phishing scams from CareerBuilder.com.   Careerbuilder.com and Monster.com are the two biggest job sites, each hosting tens of millions of résumés and more than 1 million job listings.In an article in the  

StarTribune.com, Both sites said in e-mail responses to questions about their safety practices, that they have layers of protections for résumé posters, which are regularly updated, including advice to job seekers about how to post safely. Most job sites offer anonymous postings that let users mask contact information on the résumé.

An article in the Boston Globe today stated companies that buy access to CareerBuilder.com to find employees must provide their own phone numbers, domain names, and tax identification information to guard against fraudulent use of the data. But Liz Ryan, a career adviser in Boulder, Colo., said it is easy to purchase a password by posing as a small business. Password- borrowing also is common. “Logistically, it’s wide open,” she said.

And as they have grown, the sites have become attractive targets for thieves and scam artists. Symantec  the data-security company that first noticed Monster.com’s vulnerability, wrote on its site that the records compromised are “a spammer’s dream.” Some Monster.com users received so-called “phishing” e-mails that contained victims’ personal information and asked that they download a file to assist in their job search. Instead, the file was a “Trojan horse” that encrypted documents in the victims’ computer and left a text file asking for money to decrypt the information, according to the Boston Globe article.