Gig-economy platform Paidwork has been linked to a significant data breach that affects 23.3 million accounts. This breach, involving an approximately 11GB dataset, was publicly released in July 2026.
The incident was added to the Have I Been Pwned (HIBP) breach database on July 19, with the compromise reportedly occurring in March 2026.
Paidwork Data Breach
The breach first came to light in March when a threat actor advertised a database claiming to contain information on roughly 22 million Paidwork users on a hacking forum.
At that time, researchers reviewed only a limited SQL dump sample. They could not independently verify the seller’s claims regarding the number of victims or the completeness of the dataset. Paidwork had neither confirmed nor denied the alleged breach when contacted for comment.
The subsequent public release of the data significantly increased the severity of the incident. According to HIBP, the exposed archive contained over 23 million unique email addresses, along with a wide array of personal, operational, and financial information.
The breach description identifies compromised data categories that include bank account numbers, financial transaction details, worker payout histories, names, email addresses, phone numbers, physical addresses, dates of birth, gender, education levels, personal interests, profile photographs, IP addresses, and device information.
The exposure of banking-related records and payout information poses an immediate fraud risk for Paidwork users, particularly freelancers and microtask workers who might receive earnings through linked bank accounts or payment platforms.
Attackers can use identity data, contact details, transaction records, and employment information to craft convincing phishing schemes, impersonate support staff, target account recovery processes, or attempt payment diversion scams.
Cybernews cautioned that even partial datasets like this can facilitate identity theft, social engineering, financial fraud, and reconnaissance for subsequent attacks.
Password data was reportedly stored as bcrypt hashes rather than in plaintext. Bcrypt is a password-hashing scheme designed to make large-scale offline cracking more computationally expensive; however, it does not eliminate the risk. Weak, predictable, or previously exposed passwords can still be recovered through offline password-guessing attacks.
Therefore, any Paidwork password that has been reused for email, banking, social media, or other services should be considered compromised, and users are advised to change them immediately.
Affected users should reset their Paidwork passwords and replace any reused credentials with unique, randomly generated passwords stored in a password manager.
They should also enable multi-factor authentication wherever available, monitor bank accounts and payout histories for any suspicious activity, and treat unexpected messages referencing their Paidwork history, earnings, account balances, or personal details as potential phishing attempts. HIBP recommends that users change affected passwords across all accounts where they were used and enable two-factor authentication.
Organizations that use Paidwork for workforce engagement or advertising should notify potentially affected personnel, review payment change verification procedures, and increase monitoring for business email compromise and payroll redirection attempts.
The combination of detailed identity information and financial context makes this breach particularly valuable to criminals seeking to create fraudulent communications that appear legitimate.
Strengthen Your SOC by Accelerating Threat Detection & Rapid Investigations. -> Integrate ANY.RUN With Your SOC Now.





