Work & cloud tools

Glassdoor account hacked? Here’s what to do

Move fast and in the right order: reclaim the account through Glassdoor’s official flow, kick the attacker out of every session, then close the door they came through — usually a password that leaked in a breach and was reused.

ByNikita Lushpanov· Chief Product Officer ·LinkedIn

A ransomware crew says it has Glassdoor data. That is still the whole of it

A group calling itself The Gentlemen put Glassdoor on its extortion site at the end of August 2026 and started a 172-hour clock, which ran out on 6 September. The listing named no data categories, gave no record count and came with no sample file, and nothing has been published since the deadline passed. Trackers who follow this group say as much in their write-ups: an extortion page is a sales pitch, and material bought elsewhere or recycled from an older incident gets posted under a well-known name often enough to be worth saying out loud. Glassdoor has not confirmed anything and has not written to users, so there is no file to check yourself against. What is worth doing costs nothing and is useful either way: change the password if you used it anywhere else, and switch on two-factor.

The Gentlemen’s own leak-site listing, logged by breach trackers on 29 and 30 August 2026, and reporting by Cybernews on 1 September 2026. Glassdoor has published no statement of its own, and no data has appeared.

Quick answer

If your Glassdoor account was hacked: start recovery at the official page (help.glassdoor.com/s/article/Account-Settings-and-Security?language=en_US), change the password to a unique one, sign out all other sessions, and re-check the recovery email and phone on the account. Then find out how the attacker got in — check whether your password appears in known breach data — and turn on two-factor authentication so it can’t happen again.

Recover your Glassdoor account, step by step

These steps follow Glassdoor’s official process. Official links only: account recovery · password reset · two-factor setup.

1

Change the Glassdoor password, and change it anywhere you reused it. Password reuse is the route that gets used whether or not this particular claim is real, and it is the only step here that closes a door instead of watching one.

2

Turn on two-factor authentication in account settings. Glassdoor supports codes by text message or from an authenticator app, and the app is the better of the two because it survives a phone number being taken over.

3

Remember that the same login opens Indeed, and check that account too: the applications you have sent, the CV files stored there and the email address on the profile.

4

Read what your profile actually shows. Your name, current employer, job title and any salary you submitted are all editable, and if the real-name change caught you out in 2024 this is the moment to look rather than assume.

5

Delete CV files you no longer need from the account. A stored CV is a home address, a phone number, an employment history and often a second email address in one document, and it is the single most useful thing in a job-site account for anyone building a convincing approach.

6

Treat recruiter mail as untrusted for the next few months. Open the company’s own careers page and apply there rather than following a link, and do not fill in a “verification” form that asks for a date of birth, a national insurance or Social Security number, or bank details before a job exists.

What trips people up with Glassdoor

  • The claim is unverified and may stay that way, so treat this as a reason to fix a reused password rather than as a confirmed leak. Nobody outside the negotiation knows whether files exist, and acting on a headline as though a dump had landed is how people end up handing details to the next person who emails them about it.
  • Glassdoor and Indeed share one login. Both sit under the same owner and the account settings say so plainly, which means a password you change in one place is the password that opens the other, and a stranger who has it reaches your job applications as well as your reviews.
  • Your reviews were never anonymous to Glassdoor itself, only to the people reading them. Since 2024 profiles carry real names, and the account behind a review has always been linked to it internally, so a leaked account table would connect a person to what they wrote about an employer in a way the public site never does.
  • A jobs site is the perfect cover for recruiter phishing, and this is the moment to expect it. Messages about an interview, an offer, a background check or a “verification” form will arrive quoting a real employer from your history, and the tell is the same as always: the link goes somewhere that is not the company’s own domain.
  • Deleting your account does not pull back anything already taken, and it does remove your reviews from the site. If the account is what worries you, close it deliberately rather than in a hurry, and remember that a copy sitting in someone else’s file is not affected by a deletion request made afterwards.

Was Glassdoor hacked, or is this a name on a leak site?

So far it is a name on a leak site. The Gentlemen is a ransomware operation that appeared in 2026 and grew quickly, and its method is the usual one: break in, take files, post the victim’s name with a countdown, and hope the deadline does the negotiating. Glassdoor went up at the end of August with 172 hours on the clock. What did not go up was any evidence. No sample records, no screenshots of internal systems, no figure for how many accounts, not even a list of what kind of data is supposed to be in the pile. Glassdoor has said nothing publicly, which is common while lawyers and incident responders work, and equally common when there is nothing to say.

That leaves two honest readings and no way for anyone outside to pick between them yet. Either files really were taken and the negotiation is still running, in which case something usually surfaces within a few weeks of a missed deadline, or the listing is pressure built on data that came from somewhere else. Both happen. The one thing that would settle it is a published sample, and as of 7 September 2026 there is not one. If a dump does appear, the questions worth asking are which system it came from and how old it is, because a file scraped from public review pages and a file pulled from an account database are very different things wearing the same headline.

What makes people nervous about this particular name is not payment data, because Glassdoor holds very little of it for ordinary users. It is the pairing of an identity with opinions about an employer. A profile can carry your email address, the companies you say you worked for, job titles, salary figures you submitted, saved searches, applications you sent and, on many accounts, your real name, which Glassdoor began attaching to profiles in 2024 after folding in the Fishbowl network it had bought three years earlier. Users found out when the names appeared, and the support answer at the time was that removing yours meant deleting the account. Reviews are published without a name attached, but the account behind them is not anonymous in the company’s own systems, and that gap is the thing a leak would close for anyone holding the file.

Locked out of Glassdoor — email or phone was changed

This is the worst-case scenario and the most common complaint: the attacker changed the account email, phone number or password so the normal reset flow emails them, not you. Do NOT keep triggering password resets — they go to the hacker. Go straight to Glassdoor's dedicated recovery flow (link above), which is built for exactly this case: it verifies you by your original signup details, previous passwords, linked devices or a government ID / selfie check, bypassing the stolen email. Watch for the security notice Glassdoor sent to your OLD email when the address was changed — it usually contains a "revert this change" link that works for a limited time and is the fastest way back in.

Still logged in? Lock the account down now

If you can still get in, you're racing the attacker. In this order: change the password to a long, unique one; sign out all other sessions/devices (the setting exists in Glassdoor's security settings); confirm the recovery email and phone number are yours (attackers quietly add their own so they can "recover" the account later); remove unfamiliar linked apps or API access; and turn on two-factor authentication. Only then deal with anything the attacker posted, sent or bought.

Got a "new login" alert from Glassdoor?

Treat it as real but verify it the safe way: never tap the link in the message itself (fake login alerts are a top phishing template for Glassdoor). Open the app or type the address yourself, check the active-sessions list in security settings, and if you see a device or location you don't recognize, sign it out and change your password immediately. If the alert was genuine, that password is burned — assume it's circulating and change it everywhere else you reused it.

The hacker is messaging your contacts

Attackers monetize a stolen Glassdoor account by hitting your contacts — typically 7 in 10 victims see the hacker impersonate them with "help me out" payment requests, crypto pitches or malicious links. Warn people through another channel (text, email, another platform) as soon as you know you're compromised, and tell them not to click anything "you" sent. It protects your friends and creates a paper trail that helps your recovery and any ban appeal.

Why this happened — and how to make sure it can’t again

About a third of account takeovers are credential stuffing: a password you used on Glassdoor (or the email behind it) leaked in some other company’s breach, and attackers replayed it here automatically. The FBI’s IC3 logged over 5,100 account-takeover complaints with $262M in losses in 2025 alone (IC3). Even when Glassdoor itself was never breached, your reused password from another site opens it.

So after recovery, check what’s already out there: our free scanner shows which known breaches and dark-web dumps include your email — and whether passwords were exposed with it.

Check my exposure — free →

After you recover: three doors to close

  1. Unique password + 2FA. A password manager plus app-based two-factor (official Glassdoor setup) stops both stuffing and phishing replays.
  2. Reset everywhere you reused that password — email first (it’s the master key), then bank, then the rest.
  3. Shrink your public footprint. Attackers research targets on data-broker sites (your address, phone, relatives — enough to social-engineer support lines). Our free opt-out guide covers 190 of them, step by step.
Common questions

Hacked Glassdoor account, answered

How did my Glassdoor account get hacked?

The most common cause isn't a hack of Glassdoor itself — it's credential stuffing: a password you used on Glassdoor leaked from some other site's breach, and attackers tried it here automatically. Roughly a third of account takeovers happen this way, with phishing (fake Glassdoor login pages and alerts) close behind. That's why the first fix is a unique password, not just a new one.

Can I get my Glassdoor account back?

Usually yes. Use the official recovery flow (https://help.glassdoor.com/s/article/Account-Settings-and-Security?language=en_US) — it can verify you even when the attacker changed the email and password. Be patient and respond quickly to follow-ups so the case stays open.

Should I just make a new Glassdoor account instead?

Not until you've tried recovery. The old account keeps your history and contacts — and while the attacker controls it, it will be used to scam people who trust you. Recover it, or at minimum report it as compromised so Glassdoor can lock it, before you start over.

Was Glassdoor hacked in 2026?

Nobody has shown that it was. A ransomware group called The Gentlemen listed Glassdoor on its extortion site at the end of August 2026 with a 172-hour countdown that expired on 6 September, then published nothing. The listing carried no sample data, no record count and no description of what was supposedly taken, and Glassdoor has not confirmed an incident or notified users. That is the full state of it as of 7 September 2026.

Are my Glassdoor reviews still anonymous if the data leaked?

Reviews stay published without a name on the public site, and a leak would not change that. What a leak would change is the link between an account and its reviews, which exists inside Glassdoor’s systems regardless of what readers see. Since 2024 profiles also carry real names, added after the Fishbowl network was folded in, so the identity sitting behind a review is a good deal less abstract than it was when many of those reviews were written.

Do I need to change my password if nothing has been published?

Change it if you used it anywhere else, and then it does not matter how this claim resolves. Reused passwords are what actually cost people accounts, and a password that exists in only one place is worth nothing to whoever might be holding a file. If the password is unique and two-factor is on, there is no urgency here beyond that.

Does this affect my Indeed account as well?

It affects it in the sense that the two share a login. Glassdoor and Indeed sit under the same owner and use one set of credentials, which the help centre describes directly, so anyone with your Glassdoor password has your Indeed account too. Change the password once and check both profiles: applications sent, stored CV files, and the email address on each.

Should I delete my Glassdoor account?

It is a reasonable thing to want and a poor emergency measure. Deletion removes your reviews from the site along with the profile, and it has no effect on a copy of data that has already left, so it does not undo anything if the claim turns out to be real. If you want to leave, do it because you want to leave, and clear the CV files and salary entries out of the account first.

I am getting recruiter emails about a Glassdoor breach. Are they real?

Glassdoor has not written to users about this, so a message telling you it did is worth nothing on its own. The pattern to expect after any jobs-site headline is an approach that quotes a real employer from your history and steers you to a form, and the giveaway is the destination rather than the wording. Open Glassdoor or the employer’s careers page yourself and look for the same message there.

How do I stop my Glassdoor account being hacked again?

Three things close most of the doors: a unique password (a manager makes this painless), app-based two-factor authentication (official setup: https://help.glassdoor.com/s/article/Manage-Two-Factor-Authentication?language=en_US), and shrinking your exposed footprint — checking your email against known breach databases and removing your personal data from data-broker sites that attackers use to research targets.