Recruitment firms are trusted with some of the most sensitive information a person can share: their home address, employment history, identity documents, payroll details and, in some cases, their National Insurance number.
That makes a recruitment database far more valuable to criminals than it may appear.
The August 2025 Manpower ransomware incident brought this risk into sharp focus. Reports put the number of affected individuals at approximately 140,000 to 144,000, including candidates, workers and clients. The exposed information reportedly included names, addresses, email addresses, phone numbers, employment histories and, for some people, government-issued identification numbers.
The incident is a cautionary tale for recruitment and staffing firms, but the lesson extends to any growing business holding sensitive personal data.
The question is not whether your business is “big enough” to be targeted. It is whether the information you hold is valuable enough to be exploited.
An important clarification about the incident
The Manpower breach has been described in some secondary reports as affecting a UK franchise, with a detection and disclosure sequence of 10–12 August 2025.
However, the primary breach notification and reporting from The Register and SecurityWeek identify the affected operation as an independently owned Manpower franchise in Lansing, Michigan.
Those reports state that:
- Unauthorised access took place between 29 December 2024 and 12 January 2025.
- An IT outage disrupted systems on 20 January 2025.
- RansomHub claimed to have stolen around 500GB of data.
- Notifications and public disclosure took place in August 2025.
- Approximately 144,000 people were affected.
ManpowerGroup said its corporate systems were not affected because the franchise used a separate IT platform.
This distinction matters when discussing the facts. But it does not reduce the importance of the warning for UK businesses. Recruitment firms in Britain hold similar categories of data and face the same ransomware, credential theft and data protection risks.
What information was exposed?
The full contents of every affected record were not publicly confirmed. However, reporting and screenshots published by the attackers indicated a broad collection of personal and business information, including:
- Names and addresses
- Email addresses and phone numbers
- CV and employment history information
- HR and workforce records
- Client and customer lists
- Contracts and business correspondence
- Passports, identity cards and driving licences
- Government-issued identification numbers
- Financial and corporate documents
For some records, the exposed information reportedly included Social Security numbers. In a UK recruitment environment, the equivalent high-risk identifier would generally be a National Insurance number.
That is where the danger becomes considerably more serious.
Why National Insurance numbers are more dangerous than email addresses
A leaked email address is a problem. It can result in phishing, spam, impersonation attempts and password-reset attacks.
But an email address can be changed.
A CV can be updated. A phone number can be replaced. A password can be reset.
A National Insurance number is different. It is a persistent identifier connected to an individual’s employment, tax and benefits records. It does not expire simply because it has been exposed.

A National Insurance number may not be enough to commit fraud on its own, but combined with a person’s name, date of birth, address, employment history or identity documents, it can help criminals impersonate that person.
Potential risks include:
- Fraudulent employment or payroll activity
- Attempts to interfere with tax records
- Benefits fraud
- Identity theft
- Social engineering against employers or public bodies
- More convincing phishing and recruitment scams
- Fraudulent applications for financial products or accounts
The danger is not only the immediate exposure. It is the long tail of possible misuse.
An email address may lead to a bad week of unwanted messages. A National Insurance number, combined with other personal information, can create a risk that follows someone for years.
This is why recruitment firms need to classify data by sensitivity rather than treating every record in a database as having the same value.
Why recruitment firms are attractive targets
Recruitment agencies sit in an unusual position. They often hold:
-
Large volumes of personal data
A single agency may have tens or hundreds of thousands of candidate records accumulated over many years. -
High-value identity information
Candidates may submit passports, driving licences, National Insurance numbers, bank details and right-to-work documents. -
Detailed profiles for social engineering
CVs reveal job titles, employers, responsibilities and career history. This information can help attackers craft convincing emails. -
Distributed access
Staff, recruiters, contractors, payroll teams, clients and remote workers may all need access to systems. -
Pressure to keep systems available
If a recruitment platform or payroll system goes offline, candidates may not be paid and placements may be delayed.
This combination makes staffing firms attractive to ransomware groups. It also means that a smaller agency can hold data that is more immediately useful than the information held by a much larger company.
Many growing firms also have fewer internal security resources than banks, insurers or large financial institutions. That gap between the value of the data and the maturity of the security controls creates an opportunity for attackers.
How ransomware attacks develop
Ransomware is rarely just a case of malware appearing from nowhere.
A typical intrusion may begin with:
- A stolen password
- A successful phishing email
- Exposed remote access
- An unpatched server or application
- A compromised supplier account
- Weak administrator credentials
Once inside, attackers may spend time exploring the environment. They look for additional accounts, identify valuable systems, increase their privileges and move laterally across the network.
If access is not detected, the attacker may copy sensitive data before encrypting systems. This is known as double extortion: the business faces both operational disruption and the threat of public data release.
That is why an antivirus product alone is not enough. Businesses need layered protection and the ability to identify unusual behaviour quickly.
The controls every data-heavy business should prioritise
1. Endpoint security for business
Every laptop, desktop and server connected to your network needs protection that can identify suspicious behaviour, not just known viruses.
Modern endpoint security should help detect unusual PowerShell activity, credential theft, ransomware behaviour, unauthorised encryption and attempts to disable security tools.
It should also be centrally managed so alerts are not left sitting unread on individual devices.
2. Multi-factor authentication
MFA should be mandatory for email, remote access, cloud applications, administrator accounts and systems containing candidate or client information.
A stolen password should not be enough to enter your environment.
Prioritise privileged accounts first, then extend MFA across all users and external access points.
3. Patch management
Unpatched operating systems, firewalls, remote access tools and business applications are common entry points.
Patching needs to be systematic. That means knowing what devices and applications you have, understanding which vulnerabilities are critical and confirming that updates have been successfully applied.
4. Network segmentation
A recruiter’s laptop should not be able to communicate freely with every database, server and backup system.
Segmentation limits the damage if one account or device is compromised. Candidate databases, payroll systems, administration networks and backups should be separated wherever practical.
5. Least-privilege access
People should have access to the information they need for their role, and no more.
A junior recruiter may not need access to National Insurance numbers. A finance user may not need access to every CV. Administrator permissions should be limited, monitored and reviewed regularly.
6. Monitored remote access
Remote Desktop Protocol, VPNs, cloud portals and other remote access services must be protected with MFA, strong policies, logging and continuous monitoring.
If remote access is not needed, disable it. If it is required, ensure it is not exposed unnecessarily to the public internet.
7. Immutable and tested backups
Backups are essential, but a backup that can be deleted or encrypted by the same attacker is not a reliable recovery plan.
Maintain protected, offline or immutable backup copies. Test restoration regularly, including the recovery of critical recruitment, payroll and client systems.
The goal is not simply to have a backup. The goal is to know how quickly your business can recover.

Why 24/7 monitoring matters
An attacker does not work nine-to-five. They may begin an intrusion overnight, at the weekend or during a bank holiday.
A small internal IT team may not see the warning signs until systems stop working. By then, the attacker may already have escalated privileges or copied data.
A managed security services provider can monitor endpoints, identities, networks and cloud services around the clock. More importantly, a good provider combines automated detection with human investigation and a documented incident response process.
This is where managed IT services and managed security need to work together. Patching, access control, device management, backups and security monitoring should not operate as disconnected tasks.
Whether you are looking for cybersecurity for small business, IT support in Cardiff or broader cyber security in Cardiff, the important question is the same: who is watching your environment when your team is not?
Key insights for recruitment firms and SMEs
- Your business may be small, but your data may be extremely valuable.
- National Insurance numbers and identity documents require stronger protection than ordinary contact details.
- A separate franchise, branch or supplier platform can still create significant security and reputational risk.
- Ransomware often involves data theft as well as encryption.
- MFA, patching and endpoint security must be combined with monitoring and response.
- Backups need to be protected from attackers and tested through realistic recovery exercises.
- Data minimisation matters: do not retain sensitive information indefinitely without a clear business and legal reason.
The ICO’s personal data breach guidance explains that organisations must assess the likely risk to individuals and report a notifiable breach without undue delay, where feasible within 72 hours. High-risk incidents may also require communication with affected individuals.
A practical security checklist
If your business stores sensitive personal data, review these points this month:
- Identify where candidate, employee and customer data is stored.
- Classify National Insurance numbers, identity documents and bank details as high-risk data.
- Remove unnecessary or outdated records.
- Enforce MFA on every critical system and remote access service.
- Deploy centrally managed endpoint security on all business devices.
- Check that operating systems, applications and network devices are patched.
- Review administrator permissions and apply least privilege.
- Segment sensitive databases and servers from ordinary office devices.
- Monitor remote access and investigate unusual login behaviour.
- Maintain immutable or offline backups.
- Test restoration of critical systems and data.
- Create and rehearse an incident response plan.
- Confirm who is responsible for contacting the ICO, insurers, legal advisers and affected individuals.
- Review the security of technology suppliers, franchises and outsourced providers.

Protect the data people trust you to hold
The Manpower incident is a reminder that sensitive data does not need to belong to a bank to be worth stealing. Recruitment firms, payroll providers, accountants, healthcare businesses and many other SMEs hold information that can seriously affect people if it is exposed.
Security is therefore more than a technical expense. It is part of your duty to candidates, employees, customers and clients.
You do not need to build an internal security department to improve your protection. Picnic IT provides enterprise-focused managed security, all-you-can-eat managed IT support and 24/7 protection covering email, endpoints, applications and servers.
If you are unsure whether your current controls would withstand a ransomware attack, contact Picnic IT for a straightforward conversation about your risks and next steps.
The most valuable time to strengthen your defences is before an attacker tests them.