S.01HR, recruitment and payroll

Penetration testing for recruitment firms, HR teams and payroll providers.

A recruitment firm or HR department holds the identity, salary, health and bank data of everyone it has ever hired or considered, behind candidate portals, applicant-tracking systems, HRIS and payroll platforms that must be open to the outside. Darkmoon tests those systems the way an attacker would and proves which paths lead to a mass CV leak or a diverted payroll. Managed end to end by ASC-IT's security experts, legal framework included.

€5 M
CNIL fine against France Travail (22 Jan 2026) for authentication, logging and access-rights failures
72 h
GDPR Art. 33 window to notify a personal-data breach
€799
flat rate per managed engagement
50
specialist AI agents, 142 tools

S.03Professional services
Why HR data is the easiest personal data to steal in bulk.

HR systems exist to collect: a CV, a copy of an ID, a bank form, a medical certificate. They are reachable by candidates, managers, payroll clerks and vendors, and they rarely get the security attention of the finance stack.

FindingsCVSS
SQL injection9.8
SSRF to metadata9.1
Broken access control8.7
JWT signature bypass7.5
Path traversal6.9

A CV database is an identity-theft kit

Full name, date of birth, address, national identity numbers, career history, sometimes a passport scan and a bank form: everything needed to open accounts or run convincing phishing against the person and their employer. One applicant-tracking account exposes all of it.

New engagement
Targetapp.acme.test
Scopeweb · API · cloud
Window5 business days
Flat rate€799

Payroll is a money movement with a known date

A payroll run pays everyone on the same day from bank details stored in the HRIS or payroll platform. An attacker who changes a few records the day before, through a stolen manager or payroll-clerk account, is paid before the first employee complains.

$darkmoon run --scope identity
→AS-REP roast · 3 accounts
→Kerberoast · svc_sql cracked
→NTLM relay → DCSync
✓Domain Admin, proven

Candidate portals must be open to strangers

Anyone can create an account and upload files to a career site or an ATS portal. Authorization flaws between candidates, file-upload handling and password-reset flows are tested by attackers daily, because the portal is built to be reached by people the firm has never met.

Attack surfaceexposure

Regulators judge the controls, not the attacker

In January 2026 the CNIL fined France Travail €5 M for GDPR Article 32 failures after the March 2024 breach of jobseeker data: insufficient authentication, inadequate logging to detect abnormal behaviour and over-broad access rights. The decision describes the level of control a data-protection authority expects from any large HR data holder.

S.04Attack surface
Six systems where HR data or salaries leave the building.

Darkmoon starts from the external portals, then follows the identity of recruiters, managers and payroll staff through every application that trusts it.

ATS / career portal
Applicant-tracking systems and candidate portals

Career sites, candidate accounts, interview scheduling, assessment integrations: authorization between candidates, CV download endpoints, file uploads, password resets and the recruiter back office.

HRIS
Human-resources information systems

Employee records, contracts, absences, health and disability data, manager self-service: role separation between employees, managers and HR, exports, API integrations with payroll and benefits providers.

Payroll
Payroll platforms and pay-slip portals

Payroll runs, bank-detail change workflows, pay-slip and tax-document portals, bank file exports: the systems that move money on a fixed date and keep every employee's account number.

Email / M365
Email and identity tenant

Microsoft 365 or Google Workspace with MFA gaps, legacy protocols, forwarding rules and OAuth grants: where CV attachments, offer letters and bank forms travel, and where payroll fraud starts.

Cloud storage
Shared drives and CV exports

Spreadsheets of candidates, interview notes and ID scans in shared drives, folders shared by link with hiring managers or clients, exports that never got deleted.

Third-party SaaS
Job boards, assessment, video-interview and background-check vendors

Dozens of SaaS tools with standing access to candidate data through API keys and OAuth grants, plus benefits and insurance providers fed from the HRIS: each one a path back into the firm's data.

S.05Attack paths

From a candidate account to the payroll file.

The chains we walk in an engagement, each step kept as evidence. Candidate names, hostnames and credentials are tokenized before anything reaches the model.

01
Candidate account to every other candidate's CV

A free candidate account on the portal, a download endpoint that checks the session but not the owner of the file, an identifier that increments. Darkmoon confirms the authorization gap on test candidates only and shows how far enumeration would go.

How the engine works

S.06What Darkmoon tests
What Darkmoon tests in an HR and payroll engagement.

Fifty specialist agents and 142 tools behind a build-enforced allow-list, on the scope you authorize. Every finding is qualified EXPLOITED, CONFIRMED or UNCONFIRMED with the request, payload or screenshot that proves it.

Web / API
FindingsCVSS
SQL injection9.8
SSRF to metadata9.1
Broken access control8.7
JWT signature bypass7.5
Path traversal6.9

Candidate portals, ATS and HRIS web applications

Authorization between candidates, employees and managers, CV and document download endpoints, file uploads, password-reset and account flows, exports, and the APIs behind ATS, HRIS and payroll integrations.

M365 / payroll
$darkmoon run --scope identity
→AS-REP roast · 3 accounts
→Kerberoast · svc_sql cracked
→NTLM relay → DCSync
✓Domain Admin, proven

Identity, email and payroll accounts

MFA coverage and bypass paths, legacy protocols, mailbox rules and OAuth grants, credential reuse between the tenant and payroll platforms, bank-detail change approval and logging.

Cloud / SaaS / AD
Attack surfaceexposure

Cloud storage, vendors and internal paths

Shared-drive and link exposure, standing API keys and OAuth grants of job-board and assessment vendors, Active Directory and cloud paths from a recruiter workstation to the HR file servers and backups.

S.07How an engagement works

From order to report, in five steps.

A process designed to be simple for the client and rigorous on the security side.

01
Describe your target

A guided form: target type, scope and objectives.

How the engine works

S.08Evidence & reporting
Concrete, actionable deliverables.

Not just an automated scan: a structured, validated and debriefed audit.

ranked
FindingsCVSS
SQL injection9.8
SSRF to metadata9.1
Broken access control8.7
JWT signature bypass7.5
Path traversal6.9

Detailed pentest report

Vulnerabilities ranked by severity, technical evidence, business impact and prioritized remediation guidance.

email + OTP
New engagement
Targetapp.acme.test
Scopeweb · API · cloud
Window5 business days
Flat rate€799

Secure client space

Access by email and OTP code. Contractual documents, report and exchanges centralized, available whenever you need them.

video call
Attack surfaceexposure

Debrief meeting

A video call with an expert to walk through the findings, answer questions and guide you on the fixes.

S.09Where your data goes
Your data stays on your side of the line.

The Privacy Gateway tokenizes every sensitive value (IPs, hostnames, URLs, emails, credentials, internal paths) on your machine before anything reaches the model, and rehydrates it locally. Self-host the whole engine with a local LLM, or let our experts run the managed engagement: in both cases the evidence stays in a space you control.

S.10Regulatory context
Not a NIS2 sector, judged on GDPR Article 32.

HR departments, recruitment firms and payroll providers are not a sector listed in NIS2 Annex I or II. Their security duties come from data-protection law, from labour law where it regulates recruitment, and from clients that are themselves regulated.

GDPR and UK GDPR: Articles 5, 6, 32 and 33

Data minimisation and lawfulness (Articles 5 and 6) limit what HR may collect; Article 32 requires appropriate technical and organisational measures; Article 33 requires breach notification within 72 hours. Health and disability data are special categories under Article 9. US state privacy and breach-notification laws impose comparable duties on employers and staffing firms, with state-specific rules.

What a regulator checks: the France Travail decision

On 22 January 2026 the CNIL fined France Travail €5 M (decision SAN-2026-003) for Article 32 failures after the March 2024 breach of jobseeker data: insufficient authentication for partner advisers, inadequate logging to detect abnormal behaviour, over-broad access rights, with an injunction and a daily penalty. A penetration test checks the same three controls from the attacker's side.

Recruitment rules: the French example

In France, Code du travail L1221-6 limits the information requested from a candidate to what assesses ability and aptitude, L1221-8 requires candidates to be informed of the methods used and keeps results confidential, and L1221-9 forbids collection through undisclosed devices. The CNIL's recruitment guide (30 January 2023) details the expected practices. Other jurisdictions regulate candidate data through employment and privacy law.

Clients that are NIS2 entities

A staffing or payroll provider serving an essential or important entity may receive supply-chain security requirements under NIS2 Article 21(2)(d): questionnaires, audit clauses, evidence of testing. The directive itself does not list HR or payroll firms. Cyber insurers ask similar questions before quoting.

This section describes the legal context as of October 2026 and is not legal advice: confirm your obligations with counsel and your data protection officer. Darkmoon does not certify compliance; it produces documented, reproducible findings you can present to management, clients, insurers or a supervisory authority as part of your evidence base.

S.11Use case
A staffing firm before a client's data-protection audit.

An industrial client, itself a NIS2 entity, asks its staffing partner for evidence that candidate and contractor data are protected. The firm orders a managed engagement on its career portal and ATS back office, its HRIS, the payroll platform accounts used for contractors and its Microsoft 365 tenant. Darkmoon finds a CV download endpoint that serves any candidate's file to any logged-in candidate, a payroll account without a second factor, and a shared drive of ID scans reachable by link.

Outcome

Exploited findings with evidence, a debriefed report in the secure client space, a fix list for the ATS vendor and the IT provider, and an answer to the client's audit that rests on a test rather than a policy document.

Pentest on Demand
€799/ engagement
  • Full penetration test on the defined scope
  • Legal framework and authorizations included
  • Detailed report with evidence and recommendations
  • Secure client space with OTP access
  • Video debrief meeting with an expert
  • Personalized scoping by our team
S.12Pricing

A clear flat rate, shown upfront.

The price is known before payment. No quote, no surprise. Indicative price, adjusted to the final scope. If the scoping call changes the scope and the price, you are told before anything starts.

Legal framework & authorizations included

S.13Frequently asked
What an HR director or a staffing-firm CEO asks first.

Can you test a candidate portal without exposing real candidates?

Yes. Authorization gaps are confirmed on test candidate accounts and test records created for the engagement, never by downloading real CVs. The scope and the test data are agreed at scoping, the evidence stays in a client space you control, and the Privacy Gateway tokenizes names, hostnames and credentials before anything reaches the model.

Does NIS2 apply to HR departments, recruitment firms or payroll providers?

They are not a sector listed in NIS2 Annex I or II. The directive reaches them indirectly when a client is an essential or important entity and passes supply-chain requirements down under Article 21(2)(d). The direct security duty is GDPR Article 32, and the CNIL's France Travail decision shows what a regulator checks.

Our ATS, HRIS and payroll are SaaS. What can you test?

What your organisation controls: accounts and roles, authorization between users, integrations and API keys, exports, single sign-on and MFA configuration, and the portal flows exposed to candidates and employees. The vendor's own infrastructure is outside the scope unless the vendor authorizes it.

Can you test the bank-detail change and payroll approval workflow without touching a live run?

Yes. We use test employee records and, where available, a payroll test environment or a read-only account: the agents check who can edit a bank account, whether a second approval is enforced before the run, whether the change is logged and visible, and whether the same credentials open the payroll platform from a phished mailbox. Live payroll runs and real bank files are never modified; the scoping call fixes the window so nothing overlaps a pay date.

How much does it cost and how long does it take?

The Pentest on Demand flat rate is €799 per engagement, shown upfront and adjusted to the final scope after the scoping call. The timeline is set in the contractual framework and typically runs a few business days after scoping.

What do we need to provide?

A written authorization for the targets in scope (the legal framework you sign at order time), the URLs, hostnames or network ranges to test, test accounts where authenticated testing matters, and a contact for the scoping call. Our experts confirm the scope and the constraints with you before the engagement starts.

Can we share the report with our insurer, clients or auditors?

Yes. The report is yours. It documents each finding with its evidence, severity and remediation guidance, so it can be handed to a cyber-insurer, a client's procurement team or an auditor as a dated, factual description of what was found. It is evidence, not a certification.

What happens after the report?

You get a prioritised fix list with the evidence for each finding, a debrief call to walk through it, and the option to retest once the fixes are in. Teams that self-host can schedule recurring campaigns (Pro) so the same checks run after each change; the Pro remediation agent can also open sandbox-validated fix pull requests for your developers to review.

S.14Related
Go deeper

S.15Next
Find out who can read your CVs before a regulator asks.

Order a managed engagement on your candidate portal, HRIS and payroll accounts, or talk to the team about the scope first.