By T.O. Mercer · July 22, 2026 · 8 min read
Paidwork Breach: 23 Million Users Exposed
Imagine earning a few cents at a time watching ads and filling out surveys, and then finding out your bank account details are sitting in an 11GB file on a cybercrime forum. That is the situation for 23,272,765 people caught in the Paidwork data breach right now. The gig platform was breached in March 2026, the stolen database went up for sale in April, and in July the entire thing was dumped publicly for anyone to download. Have I Been Pwned indexed it on July 19.
Most of the people affected joined Paidwork to make small money on the side. The data they lost is worth far more to criminals than anything those microtasks ever paid out. I want to walk you through exactly what leaked, why the "passwords were hashed" reassurance only goes so far, and the five things you should do in the next ten minutes if you ever had a Paidwork account.
What Happened, and When
The timeline matters because it shows how long this data circulated before anyone could act on it:
- March 2026: Attackers breach Paidwork's production systems. A threat actor using the alias "hackformetome" later claims the intrusion happened on March 23.
- April 2026: The database surfaces for sale on a well-known cybercrime forum, advertised as an 11GB dump covering more than 22 million users.
- July 2026: The full dataset gets posted publicly. Either the seller never found a buyer, or they already monetized it privately and released it afterward. Both happen constantly with large breaches.
- July 19, 2026: Have I Been Pwned adds the breach, confirming 23,272,765 unique email addresses.
That means affected users spent roughly four months exposed with no notification. As I write this, Paidwork still has not published a statement or directly notified its users. If you had an account, nobody was going to tell you. You have to check yourself, and I explain how below.
What Actually Leaked
This one stings more than a typical credentials-only leak. According to Have I Been Pwned and multiple security outlets, the dataset includes:
- Email addresses (23.2 million unique)
- Full user profile information
- Banking details tied to worker payouts
- Complete payout histories
- Device and IP address data
- Passwords stored as bcrypt hashes
The combination is what makes this dangerous. An attacker who knows your name, your email, your bank details, and your exact payout history can write a phishing email that references a real transaction you actually received. "We noticed an issue with your $4.17 payout from June 3" reads very differently when the number is correct. Expect exactly that kind of targeted phishing against Paidwork users in the coming weeks.
The device and IP data adds another problem: some services use familiar device and location signals as a soft security check. Attackers holding that data have an easier time impersonating you during account recovery flows.
About That "Bcrypt" Reassurance
Every breach writeup mentions that Paidwork stored passwords with bcrypt, and that this is better than plaintext. True. Bcrypt is deliberately slow to compute, which makes mass cracking expensive.
But I have watched too many people read "hashed with bcrypt" and decide they can skip changing their password. That is a mistake, for two reasons:
First, bcrypt protects strong passwords well and weak passwords barely at all. If your password was "sunshine2024" or your dog's name plus a birth year, an attacker running a dictionary attack against the hash will crack it. Slowness only helps when the attacker needs billions of guesses. Common passwords fall within the first few million.
Second, cracking is a batch operation. Criminals do not crack one account at a time. They run the entire 23-million-row table against wordlists and previously leaked passwords, then take every hit and stuff it into banking sites, email providers, and PayPal. If you reused your Paidwork password anywhere else, the breach at a microtask site becomes a breach of your whole digital life.
I covered the same dynamic in the Hugging Face breach: hashing buys you time, not immunity. Use that time.
How to Check If You Were Affected
Two minutes, one step:
- Go to haveibeenpwned.com and enter the email address you used on Paidwork.
- If the results list "Paidwork," your data is in the dump. Assume everything listed above is in criminal hands.
Check every email address you might have registered with. Microtask platforms attract throwaway accounts, and people forget which address they signed up with years ago.
5 Steps to Take Right Now
1. Change your Paidwork password. Even with bcrypt, treat it as burned. Generate a new one with our free password generator. Twenty characters minimum, fully random.
2. Hunt down every account where you reused that password. This is the step people skip and the step that costs them. Email, PayPal, banking, other gig platforms. Change each one to something unique. If you cannot remember where you reused it, that itself is the problem a password manager solves.
3. Turn on two-factor authentication. On Paidwork if available, and definitely on your email and any account that touches money. 2FA is the difference between a cracked password and a compromised account.
4. Watch your bank account. The leak included banking details and payout data. Review statements for unauthorized transactions and unfamiliar micro-deposits, which fraudsters sometimes use to verify account numbers before larger theft.
5. Treat every Paidwork-related email as hostile until proven otherwise. Real transaction details in a message no longer prove the sender is legitimate, because attackers now have those details too. Never click a password reset link you did not request. Type the site address yourself.
The Bigger Lesson for Gig Workers
Gig and microtask platforms hold a nasty combination of data: your identity, your bank account, and your behavioral history. Yet they rarely face the security scrutiny that banks do. Paidwork's four months of silence after the breach tells you how much you can rely on these platforms to protect you or even to warn you.
You cannot control a platform's security. You can control whether one breached site takes down your entire online life. That comes down to one habit: a unique, random password for every single account, stored somewhere you do not have to memorize it.
I recommend NordPass for this because it does the two things breach victims actually need. It generates and stores unique passwords so a Paidwork-style leak stops at Paidwork, and its Data Breach Scanner continuously monitors whether your emails and credentials show up in new dumps like this one. You find out when your data leaks, instead of four months later when a journalist does.
If a password manager feels like too much today, at least start replacing your reused passwords with unique ones from our password generator. Reuse is what turns one breach into ten.
FAQ
Was Paidwork hacked?
Yes. Attackers breached the platform in March 2026 and stole data on more than 23 million users. The full database was leaked publicly in July 2026.
What data was exposed in the Paidwork breach?
Email addresses, user profiles, banking details, payout histories, device and IP data, and bcrypt-hashed passwords for over 23.2 million accounts.
How do I check if my Paidwork data was leaked?
Enter your email at haveibeenpwned.com. If Paidwork appears in the results, change your password there and on any site where you reused it, then enable 2FA.
Are bcrypt-hashed passwords safe after a breach?
Safer than plaintext, but not safe. Weak and reused passwords can still be cracked offline. Replace any password that was in a leaked database.
Has Paidwork responded to the breach?
As of July 22, 2026, Paidwork has not published a public statement or directly notified affected users.
Is Paidwork safe to use in 2026?
I would not hand Paidwork sensitive data right now. The platform lost banking details and profiles for 23 million users, then stayed silent for four months while the data circulated on criminal forums. Until it publicly explains what happened and what changed, sign up with a unique password, a dedicated email address, and the minimum personal information possible.