Paidwork Data Breach Exposes 23 Million Users’ Banking and Personal Data
Key Takeaways A significant data breach has impacted Paidwork, a prominent gig economy platform. The incident compromised the sensitive banking and personal data of over 23 million users globally....
Key Takeaways
- A significant data breach has impacted Paidwork, a prominent gig economy platform.
- The incident compromised the sensitive banking and personal data of over 23 million users globally.
- Exposed information includes bank account numbers, names, addresses, emails, phone numbers, and bcrypt-hashed passwords.
- The breach facilitates severe risks such as financial fraud, identity theft, and targeted phishing attacks.
Paidwork, a widely used platform connecting freelance workers with clients, has suffered a substantial data breach, compromising the sensitive personal and financial information of more than 23 million users worldwide.
Table Of Content
The incident first came to light in March 2026 when threat actors offered the stolen data for sale on dark web forums. The situation escalated dramatically in July of the same year, with nearly 11GB of the compromised dataset subsequently leaked publicly.
According to reports compiled by Have I Been Pwned, malicious actors initially claimed responsibility for infiltrating Paidwork’s systems in March 2026, listing the purloined database on illicit marketplaces. The severity of the breach intensified in July when the identical dataset, containing over 23 million distinct email addresses, became freely accessible online, a fact highlighted by Dark Web Intelligence on X/Twitter.
Given Paidwork’s operational model as a gig economy facilitator, the exposed data encompasses both standard personal identifying information and highly sensitive financial records directly linked to worker payouts.
What Data Was Exposed
The leaked information is reported to include an extensive range of personal and financial details:
- Bank account numbers and comprehensive financial transaction records
- Dates of birth and declared genders
- Specific device and IP address information
- Educational background and personal interests
- Email addresses and associated phone numbers
- Full names and physical residential addresses
- Complete payout history for gig workers
- User profile photos
- Passwords, secured with bcrypt hashing
While bcrypt hashing offers a more robust protection mechanism compared to storing passwords in plaintext, it does not render them invulnerable to cracking, particularly if users have opted for weak or previously compromised credentials.
The convergence of banking details with rich personal profiles renders this breach particularly hazardous. Unlike incidents limited to merely email addresses or passwords, this event provides attackers with a comprehensive toolkit for launching highly targeted phishing campaigns, executing financial fraud, and perpetrating identity theft.
Specifically, payout histories and bank account numbers represent extremely valuable assets for cybercriminals. This data could be leveraged to impersonate Paidwork, deceive users, or even intercept future payments intended for gig workers.
Furthermore, the exposure of device and IP information raises significant concerns regarding potential account takeover attempts. Attackers could potentially exploit this data to circumvent security protocols that rely on recognizing familiar devices or geographical locations.
Individuals concerned about the exposure of their personal information in this or other data breaches can verify their status by visiting Have I Been Pwned.
What You Should Do
If you possess a Paidwork account, cybersecurity experts strongly advise taking the following immediate actions:
- Promptly change your Paidwork password and update any other accounts where you may have reused the same credentials.
- Activate two-factor authentication (2FA) on your Paidwork account and any other online services that offer this critical security feature.
- Diligently monitor your bank accounts and payout histories for any suspicious or unauthorized transactions.
- Remain vigilant for phishing emails that attempt to leverage your Paidwork profile details or financial information.
- Consider initiating a credit freeze or placing a fraud alert with credit bureaus, especially if banking data was directly linked to your identity.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.