CHECKLEAKED.CC

Loading

Classic site

FORENSIC ANALYSIS

Paidwork breach exposes financial and personal data of 23 million accounts

An intrusion into production systems of gig economy platform Paidwork in March 2026 exposed data belonging to 23.2 million users. Stolen database records measuring nearly 11 GB surfaced for sale in April 2026 before being published publicly in July 2026. Exposed fields include full names, email addresses, phone numbers, home addresses, dates of birth, bank account numbers, worker payout histories, and passwords stored as bcrypt hashes.

Sources7Publishers7Cited claims12See the sources

What happened

An unauthorized intrusion into backend systems of the microtask platform Paidwork occurred in March 2026. A threat actor operating under the alias "hackformetome" obtained an 11 GB database dump allegedly taken directly from Paidwork's production infrastructure[1][5].

In April 2026, the actor advertised the stolen dataset for sale on a cybercrime forum, claiming it contained information associated with roughly 22 million users[2][5]. In July 2026, nearly the full 11 GB database was publicly posted online[5][6].

How it came to light

The security incident became public after threat actors posted the stolen database online. On July 19, 2026, data breach notification service Have I Been Pwned formally cataloged the compromise after analyzing the leaked dataset[3][4].

Analysis of the leaked files confirmed 23,272,765 unique email addresses involved in the breach[3][5]. Prior to the public leak and subsequent database indexing, Paidwork had not publicly disclosed or acknowledged the breach[3][5].

What was exposed

The breach exposed operational platform data alongside personal and financial records for over 23 million accounts. Specific compromised fields included user full names, email addresses, phone numbers, physical home addresses, dates of birth, genders, education levels, personal interests, profile photos, device information, and IP addresses[1][3][5].

Financial and operational data exposed included bank account numbers, financial transaction records, and worker payout histories[3][5][6]. User passwords were included in the database but were stored as bcrypt hashes rather than plaintext[3][5].

Root cause

The specific intrusion vector or system vulnerability exploited to gain unauthorized access to Paidwork's production database has not been disclosed.

What to do if you were affected

Affected users should immediately change their Paidwork account password and update any other service where the same password was reused.

Given the exposure of bank account numbers and worker payout records, impacted individuals should closely monitor bank statements and financial accounts for unauthorized transactions or suspicious activity[1][7].

Users should also remain vigilant against targeted phishing, SMS scams, and phone social engineering attempts that utilize exposed personal details, physical addresses, or payout history[1]. Enabling multi-factor authentication across sensitive accounts is strongly advised[3].

Sources

Every numbered marker above points at one of these. Links open in a new tab and are references, not endorsements.

  1. malwarebytes.com
  2. securityweek.com
  3. helpnetsecurity.com
  4. gblock.app
  5. mallory.ai
  6. cybersecuritynews.com
  7. cyberpress.org

Were you caught in this breach?

Search your email, phone number or username against every record CheckLeaked indexes.

Check my data