A massive data breach at gig economy platform Paidwork has compromised the personal and financial information of over 23 million users, marking one of the largest breaches to hit the gig work sector this year.
According to Have I Been Pwned, the exposed dataset includes banking details, extensive personal information, and password hashes, raising significant concerns for affected workers globally.
The breach first surfaced in March 2026, when threat actors claimed to have obtained data from Paidwork and listed it for sale on dark web forums.
The situation escalated in July 2026 when nearly 11GB of the allegedly stolen data was posted publicly, confirming over 23 million unique email addresses in the leaked cache.
Paidwork Data Breach Exposed
The public dump suggests the threat actors either failed to find a buyer or opted to release the data after monetizing it through private sales first, a common pattern in large-scale breach distribution.
The exposed dataset spans a wide range of sensitive categories tied to Paidwork’s platform operations. This includes bank account numbers and financial transaction records, along with payout history for gig workers.
Personal identifiers such as names, dates of birth, genders, email addresses, and phone numbers were also exposed, alongside physical addresses, IP addresses, and device information. The breach further included education levels, personal interests, profile photos, and passwords stored as bcrypt hashes.
While bcrypt is considered a reasonably strong hashing algorithm compared to weaker alternatives like MD5 or SHA-1, it doesn’t make passwords immune to compromise.
Attackers with sufficient computing resources can still attempt offline brute-force or dictionary attacks, particularly against weak or reused passwords, Have I Been Pwned said.
The combination of banking data, transaction histories, and personal identifiers creates a high-value dataset for fraud, phishing, and identity theft. Gig workers on platforms like Paidwork often rely on the platform for direct income deposits, making banking data exposure especially dangerous.
Attackers could use this information for account takeover attempts, social engineering targeting payout redirection, or synthetic identity fraud using the combined personal data.
The breadth of personal information exposed, including education levels, interests, and device details, also raises concerns about hyper-targeted phishing campaigns, since attackers can craft highly convincing pretexts using leaked profile details.
Mitigation
Affected users should change their password on Paidwork immediately, along with any other accounts where the same password was reused. Enabling two-factor authentication wherever supported adds a critical layer of protection beyond passwords alone.
Given the exposure of banking details, users should also monitor their bank accounts and financial statements closely for unauthorized transactions.
As of publication, Paidwork has not issued a public statement confirming the breach’s scope or notifying affected users directly. Security researchers continue to monitor dark web forums for further distribution of the dataset.
Prevent critical incidents and financial loss with stronger proactive defense. Integrate a live threat feed from 15K SOCs