23 Million Paidwork Users Have Their Banking and Personal Data Exposed

A massive data breach at gig economy platform Paidwork has exposed the personal and financial information of more than 23 million users, marking one of the largest breaches to hit the gig work sector to date.

In March 2026, threat actors claimed to have breached Paidwork, a gig economy platform, listing the stolen records for sale on cybercrime forums. The initial claims involved roughly 22 million user records.

The situation escalated significantly in July 2026 when nearly 11GB of data allegedly sourced from the platform was publicly leaked, confirming over 23 million unique email addresses in the dataset.

23 Million Paidwork Users Personal Data Exposed

Unlike many breaches limited to login credentials, this leak contained a comprehensive trove of operational data, including detailed worker payout histories, banking details, and full user profiles.

Passwords were stored using bcrypt hashing which offers stronger protection than unsalted alternatives though affected users must still treat their accounts as compromised due to elevated credential theft risks.

The exposure record has since been verified and added to the official Have I Been Pwned database, allowing individuals to verify if their email addresses were included.

The exposed dataset spans a wide range of sensitive personal, financial, and behavioral categories:

Information CategorySpecific Data Exposed
Financial DetailsBank account numbers, payout histories, detailed financial transaction records
Personal IdentityFull names, dates of birth, gender, profile photos
Contact DataEmail addresses, phone numbers, physical home addresses
Technical MetadataDevice information, recorded IP addresses
Account CredentialsBcrypt-hashed passwords, education levels, personal interest profiles

Gig economy platforms like Paidwork frequently serve users in emerging markets who rely on the service for primary income, making banking details especially lucrative to attackers.

The combination of financial data with personal identifiers creates multiple avenues for targeted social engineering:

  • Targeted Phishing: Cybercriminals can craft highly believable phishing messages referencing real past payout history and transaction figures.
  • Account Takeovers: Fraudulent account recovery attempts can be initiated using exposed birthdates, physical addresses, and security identifiers.
  • Identity Theft: Stolen device profiles and banking details can be cross-referenced to target users on secondary platforms.

These combined risks underscore the critical importance of enforcing strict mobile data protection measures across personal and financial accounts.

Affected users should take immediate defensive steps to limit potential exposure:

  • Change Passwords Immediately: Reset your password on Paidwork and any other platform where credentials were reused.
  • Enable Two-Factor Authentication (2FA): Add an extra layer of protection beyond standard passwords wherever supported.
  • Monitor Financial Accounts: Review bank statements closely for unauthorized transactions or unusual micro-deposits.
  • Exercise Caution with Messages: Watch for suspicious communications referencing specific Paidwork transaction details.
  • Adopt a Password Manager: Generate and store unique, complex passwords for every online account to neutralize credential-stuffing attacks.
Status Update: Paidwork has not yet issued an official public statement regarding the breach or confirmed formal remediation steps for affected platform users.

Trending News

Related Stories