Paidwork Breach: 23M Accounts - Email & Password Leaked (2026)
In March 2026, hackers claimed they had obtained data from the gig economy platform Paidwork which they then listed for sale . Almost 11GB of data allegedly obtained from the platform was subsequently posted publicly in July and contained over 23M unique email addresses. The breach also included a b...
Overview
In March 2026, hackers claimed they had breached the gig economy platform Paidwork, listing the stolen data for sale. The full dataset - nearly 11GB - was later posted publicly in July 2026, exposing over 23 million unique email addresses. Paidwork, a platform connecting workers with micro-tasks and payouts, suffered a catastrophic data leak that goes far beyond typical account credentials: it includes banking information, payout histories, and bcrypt-hashed passwords. The breach has been reported to Have I Been Pwned, making it easy for affected users to check.
What Was Exposed
This breach is unusually comprehensive for a gig economy platform. The leaked data includes:
- 23.2 million unique email addresses - directly usable for phishing and credential-stuffing attacks.
- Passwords stored as bcrypt hashes - bcrypt is strong, but weak or reused passwords remain crackable.
- User profile data - names, account details, and personal information that can fuel identity theft.
- Banking information - payout details linked to worker accounts, which can be used for financial fraud.
- Payout history - records of earnings, which attackers can exploit for social engineering.
Because the data includes financial records and personal identifiers, the risk is elevated beyond a standard credential leak.
How the Breach Happened
The attackers claimed to have stolen the data in March 2026, but the full dump was not published until July. The original method of intrusion has not been confirmed, but the sheer size - 11GB covering user accounts, banking data, and operational records - suggests either a compromised admin account, an insecure API, or a vulnerability in the platform’s backend. No specific CVE has been publicly tied to this breach, but it aligns with patterns seen in other gig economy cybersecurity news incidents where lax access controls or misconfigured databases were the root cause.
Identity Theft and Financial Risks
The exposure of banking information is the most critical element. Unlike a typical email-and-password breach, this data gives attackers direct paths to fraud. Affected workers could face:
- Phishing campaigns targeting their bank or payment accounts, using leaked payout history as bait.
- Account takeover on Paidwork itself, if weak passwords are cracked.
- Identity theft from the combination of name, email, and financial records.
Workers should monitor bank statements and credit reports closely for any unusual activity.
What to Do Right Now
If you have a Paidwork account, take these steps immediately:
- Change your Paidwork password - even though passwords are bcrypt-hashed, they can still be cracked. Create a strong, unique password.
- Enable two-factor authentication on any financial accounts linked to Paidwork, if supported.
- Contact your bank to flag the potential exposure of your banking information. Consider freezing your credit if you suspect fraud.
- Be vigilant against phishing - emails referencing your Paidwork payout history are highly likely to be scams.
- Use a password manager to generate and store unique passwords across all services.
How to Check If You’re Affected
Visit Have I Been Pwned and enter your email address. The site will confirm if your account appears in the Paidwork breach. If you do, treat your account as compromised and follow the steps above.
Security Insight
This breach reveals a systemic failure in data minimization: Paidwork retained banking details and payout histories unnecessarily long, creating a single point of failure. Unlike a simple credential dump, this leak arms attackers with financial profiles that can be weaponized for years. The lesson for gig economy platforms is clear - strip sensitive financial data from operational databases and segment storage to limit blast radius in future incidents.
Further Reading
Investigate Breaches Safely with NordVPN
Researching exposed data, paste sites, or threat actor infrastructure? Route your OSINT traffic through a VPN to avoid attribution and keep your investigation IP separate from your corporate network.
Get NordVPN for ResearchAffiliate link — we may earn a commission at no extra cost to you.
Never miss a data breach report
Get real-time security alerts delivered to your preferred platform.
Related Breach Reports
On 18 June 2026, the latest phase of Operation Endgame targeted the SocGholish malware operation , a prolific malware distribution network used to compromise systems and facilitate further cybercrime. Coordinated by international law enforcement agencies with support from Europol and Eurojust, the o...
In June 2026, a collection of accumulated stealer logs from various sources was added to HIBP. The corpus comprised 56M unique email addresses across hundreds of millions of stealer log records. The data also contained 124M unique passwords, which have been added to Pwned Passwords and are now searc...
In January 2026, the automotive research and car-shopping platform Edmunds was listed by the ShinyHunters hacking group as having been breached . Data purportedly obtained in the incident was later published publicly and included 178k unique email addresses, usernames, passwords, IP addresses, phone...
In May 2026, the GTA V and CS2 cheat service Atlas Menu suffered a data breach. An attacker claimed to have gained access to all Atlas systems and published the service's database to a public GitHub repository. The incident exposed 64k unique email addresses along with usernames, IP addresses, suppo...