Critical

Paidwork Breach: 23M Accounts - Email & Password Leaked (2026)

In March 2026, hackers claimed they had obtained data from the gig economy platform Paidwork which they then listed for sale . Almost 11GB of data allegedly obtained from the platform was subsequently posted publicly in July and contained over 23M unique email addresses. The breach also included a b...

Overview

In March 2026, hackers claimed they had breached the gig economy platform Paidwork, listing the stolen data for sale. The full dataset - nearly 11GB - was later posted publicly in July 2026, exposing over 23 million unique email addresses. Paidwork, a platform connecting workers with micro-tasks and payouts, suffered a catastrophic data leak that goes far beyond typical account credentials: it includes banking information, payout histories, and bcrypt-hashed passwords. The breach has been reported to Have I Been Pwned, making it easy for affected users to check.

What Was Exposed

This breach is unusually comprehensive for a gig economy platform. The leaked data includes:

  • 23.2 million unique email addresses - directly usable for phishing and credential-stuffing attacks.
  • Passwords stored as bcrypt hashes - bcrypt is strong, but weak or reused passwords remain crackable.
  • User profile data - names, account details, and personal information that can fuel identity theft.
  • Banking information - payout details linked to worker accounts, which can be used for financial fraud.
  • Payout history - records of earnings, which attackers can exploit for social engineering.

Because the data includes financial records and personal identifiers, the risk is elevated beyond a standard credential leak.

How the Breach Happened

The attackers claimed to have stolen the data in March 2026, but the full dump was not published until July. The original method of intrusion has not been confirmed, but the sheer size - 11GB covering user accounts, banking data, and operational records - suggests either a compromised admin account, an insecure API, or a vulnerability in the platform’s backend. No specific CVE has been publicly tied to this breach, but it aligns with patterns seen in other gig economy cybersecurity news incidents where lax access controls or misconfigured databases were the root cause.

Identity Theft and Financial Risks

The exposure of banking information is the most critical element. Unlike a typical email-and-password breach, this data gives attackers direct paths to fraud. Affected workers could face:

  • Phishing campaigns targeting their bank or payment accounts, using leaked payout history as bait.
  • Account takeover on Paidwork itself, if weak passwords are cracked.
  • Identity theft from the combination of name, email, and financial records.

Workers should monitor bank statements and credit reports closely for any unusual activity.

What to Do Right Now

If you have a Paidwork account, take these steps immediately:

  1. Change your Paidwork password - even though passwords are bcrypt-hashed, they can still be cracked. Create a strong, unique password.
  2. Enable two-factor authentication on any financial accounts linked to Paidwork, if supported.
  3. Contact your bank to flag the potential exposure of your banking information. Consider freezing your credit if you suspect fraud.
  4. Be vigilant against phishing - emails referencing your Paidwork payout history are highly likely to be scams.
  5. Use a password manager to generate and store unique passwords across all services.

How to Check If You’re Affected

Visit Have I Been Pwned and enter your email address. The site will confirm if your account appears in the Paidwork breach. If you do, treat your account as compromised and follow the steps above.

Security Insight

This breach reveals a systemic failure in data minimization: Paidwork retained banking details and payout histories unnecessarily long, creating a single point of failure. Unlike a simple credential dump, this leak arms attackers with financial profiles that can be weaponized for years. The lesson for gig economy platforms is clear - strip sensitive financial data from operational databases and segment storage to limit blast radius in future incidents.

Further Reading

Investigate Breaches Safely with NordVPN

Researching exposed data, paste sites, or threat actor infrastructure? Route your OSINT traffic through a VPN to avoid attribution and keep your investigation IP separate from your corporate network.

Get NordVPN for Research

Affiliate link — we may earn a commission at no extra cost to you.

Share:

Never miss a data breach report

Get real-time security alerts delivered to your preferred platform.

Related Breach Reports

Never Miss a Critical Alert

CVE advisories, breach reports, and threat intel — delivered daily to your inbox.