Paidwork Data Breach Exposes 23 Million Users' Banking and Personal Data
Gig economy platform Paidwork has suffered a massive data breach, exposing the sensitive personal and banking information of over 23 million users, leaked publicly on dark web forums.

A significant data breach impacting the gig economy platform Paidwork has resulted in the exposure of sensitive banking and personal information belonging to more than 23 million users globally. The incident, which initially surfaced in March 2026 when threat actors attempted to sell the stolen data, escalated dramatically in July when a substantial portion of the compromised dataset was leaked publicly on dark web forums.
Threat actors first claimed responsibility for breaching Paidwork's systems in March 2026, offering the database for sale. However, the situation worsened significantly in July when the dataset, containing over 23 million unique email addresses, became freely available online. This leak includes a wide array of sensitive details, such as bank account numbers, dates of birth, addresses, payout histories, and even profile photos.
While passwords were protected using bcrypt hashing, a robust encryption method, the combination of financial and personal data presents a severe risk to affected users. The exposed information is comprehensive enough to facilitate targeted phishing campaigns, sophisticated financial fraud, and widespread identity theft. The inclusion of bank account numbers and payout histories is particularly valuable to cybercriminals, potentially enabling them to intercept payments or impersonate the platform.
Beyond financial details, the breach also exposed personal identifiers like names, physical addresses, dates of birth, and contact information. This rich profile data, combined with device and IP address information, could be leveraged for account takeover attempts, bypassing security measures that rely on recognizing familiar devices or locations. The exposure of education levels and personal interests further aids in crafting highly personalized and convincing social engineering attacks.
Paidwork, which connects freelance workers with clients, means the compromised data affects both the workers and potentially the clients they interact with. The platform's role in facilitating payments makes the exposure of financial transaction records and payout histories a critical concern for users relying on Paidwork for their income.
Security experts are urging affected users to take immediate action. This includes changing their Paidwork password and any other accounts that share the same credentials, enabling two-factor authentication wherever possible, and diligently monitoring bank accounts for any unauthorized transactions. Users should also be vigilant for phishing attempts that may reference their Paidwork profile details.
Given the severity of the exposed data, including direct banking information, users are advised to consider implementing a credit freeze or fraud alert with credit reporting agencies. This can help prevent new lines of credit from being opened in their name, mitigating the risk of identity theft.
The scale of this breach, affecting over 23 million users and exposing such a wide range of sensitive personal and financial data, underscores the persistent threats faced by platforms handling user financial information. It highlights the critical need for robust security measures and ongoing vigilance in protecting user data from malicious actors.
The data breach at microtask platform Paidwork, which exposed sensitive information of over 23 million users, was first advertised on a cybercrime forum in April 2026 by an individual using the alias "hackformetome." The leaked database, reportedly an 11GB dump, contained records on more than 22 million users, including full names, email addresses, phone numbers, home addresses, dates of birth, gender, education levels, bank account numbers, transaction records, device and IP information, profile photos, personal interests, and bcrypt-hashed passwords.