Paidwork Data Breach Exposes 23 Million Users’ Banking and Personal Data

Home News Data Breach Reports Paidwork Data Breach Exposes 23 Million Users’ Banking and Personal Data
Paidwork Data Breach Exposes 23 Million Users' Banking and Personal Data, Infosec Federation

Gig-economy platform Paidwork has had the personal and financial data of more than 23 million users exposed after a nearly 11GB dataset was publicly leaked in July 2026, confirming claims that threat actors first made on a cybercrime forum back in March, according to cyberpress.org. The leaked records include bank account numbers, payout histories, and bcrypt-hashed passwords, and the exposure has since been verified and added to the Have I Been Pwned database. Paidwork has not issued a public statement or confirmed any remediation steps, the outlet reported.

What happenedA nearly 11GB dataset from gig platform Paidwork was leaked publicly, confirming data first offered for sale on a cybercrime forum
ScaleMore than 23 million unique email addresses confirmed in the leaked cache
Data exposedNames, dates of birth, phone numbers, addresses, IP and device data, bank account numbers, payout histories, bcrypt password hashes
TimelineListed for sale March 2026; dumped publicly July 2026
VerificationAdded to the Have I Been Pwned breach registry
Company responseNo public statement or confirmation from Paidwork as of publication

What Happened in the Paidwork Breach?

Cyberpress.org reports that threat actors first claimed to have breached Paidwork in March 2026, listing roughly 22 million user records for sale on a cybercrime forum. The claim escalated in July 2026 when nearly 11GB of data allegedly sourced from the platform was publicly leaked in full, a release that confirmed more than 23 million unique email addresses in the dataset. The gap between the initial forum listing and the public leak is a pattern security teams have seen repeatedly this year, most recently with the Accenture breach in July 2026, where stolen data also surfaced on criminal forums well before it was confirmed publicly.

What Data Was Exposed?

According to cyberpress.org, the leak is unusually comprehensive for a breach of its kind. Rather than being limited to login credentials, it contains a full trove of operational and financial data tied to Paidwork’s gig workers, including:

  • Full names, email addresses, phone numbers, and home addresses
  • Dates of birth, gender, education levels, and personal interests
  • Profile photos, device information, and IP addresses
  • Bank account numbers and payout or transaction histories
  • Bcrypt-hashed passwords

Cyberpress.org notes that payout history and bank account numbers are especially valuable to criminals because they give attackers everything needed to impersonate Paidwork directly to its own users, or to attempt to intercept future payments.

Why Does a Breach at a Gig Platform Carry Outsized Risk?

Paidwork is a gig-economy platform whose users, per cyberpress.org, are concentrated in emerging markets and often depend on the platform for their primary income. That dependency changes the risk calculus. A worker who receives a message that looks like it comes from Paidwork, referencing their real payout history and bank details, has strong reason to trust it and act on it quickly, since a delayed payment can mean a missed bill or rent payment. That combination of financial urgency and verified personal detail is exactly the setup that makes phishing and account takeover attempts succeed, a dynamic covered in our guide to security awareness training versus human risk management.

The exposure of full identity profiles alongside financial data also raises identity theft risk well beyond the platform itself, a pattern seen in other recent breaches where employee or user data was later used for follow-on fraud, as our coverage of the Estée Lauder breach and its identity theft fallout detailed.

How Did the Breach Come to Light?

Cyberpress.org reports that the exposure was verified and added to the Have I Been Pwned database following the July 2026 public leak, and Help Net Security’s coverage corroborates the scale of the exposure, giving affected users a way to check whether their email address is included. The four-month gap between the initial forum sale in March and the public confirmation in July meant the data may have already circulated among criminal buyers before most users had any way to know they were exposed, a lag that continues to be a defining feature of large-scale breaches this year, as we tracked in our roundup of the biggest data breaches of 2026 so far.

How long stolen data stayed out of public view, incidents covered by Infosec Federation this month

Estée Lauder (intrusion to discovery)
10 months
Paidwork (forum sale to public dump)
4 months

What Should Affected Users Do Now?

For anyone who holds a Paidwork account, the exposure of banking details alongside personal identity data calls for immediate action rather than a wait-and-see approach. Practical steps include:

  • Check Have I Been Pwned to confirm whether your email address is in the dataset
  • Change your Paidwork password and any other account where you reused it
  • Enable two-factor authentication wherever it is available
  • Monitor bank statements closely for unauthorized transactions
  • Treat unexpected messages referencing Paidwork payouts or account details with suspicion, even if they include accurate personal information

Because bcrypt-hashed passwords were included in the leak rather than plaintext ones, cracking them at scale is harder than with weaker hashing schemes, but users who reused a Paidwork password elsewhere should still rotate it as a precaution.

What Should Security Leaders Take From This?

For CISOs and risk leaders whose organizations rely on gig, freelance, or contractor platforms for any part of their workforce, the Paidwork breach is a reminder that third-party platforms holding financial and identity data on your people are effectively an extension of your own attack surface. That’s a theme we’ve explored in depth in our 2026 CISO perspective on what security leaders need to know, and it applies just as directly to platforms used by contingent workers as it does to core enterprise systems.

The breach also underscores a point made repeatedly this year in breach coverage across sectors, including the Canva and Instructure breaches tied to ShinyHunters: attackers are increasingly targeting platforms that sit downstream of an organization’s direct control but still hold sensitive data about its people. Reviewing which third-party platforms your workforce, contractors, or gig workers use, and what financial or identity data those platforms hold, is a reasonable next step for any security team reading this report. For teams building or refreshing that foundational understanding, our complete guide to cybersecurity for 2026 is a useful starting point.

As of cyberpress.org’s report, Paidwork had not issued a public statement addressing the breach, confirmed how the initial access occurred, or detailed what remediation or notification steps it plans to take for affected users.

Frequently asked questions

How many people were affected by the Paidwork data breach?

According to cyberpress.org, the breach exposed more than 23 million unique user records, up from an initial claim of around 22 million when threat actors first advertised the data on a cybercrime forum in March 2026.

What kind of data was exposed in the Paidwork leak?

The exposed dataset includes bank account numbers, payout and transaction histories, full names, dates of birth, gender, email addresses, phone numbers, home addresses, education levels, profile photos, device and IP information, and bcrypt-hashed passwords, cyberpress.org reported.

Has Paidwork responded to the breach?

As of the cyberpress.org report, Paidwork had not issued an official public statement about the breach or confirmed what remediation steps it has taken. The exposure has been verified and added to the Have I Been Pwned database.

Leave a Reply

Your email address will not be published.