A massive security failure at Paidwork, a platform known for allowing users to earn small amounts of money by completing microtasks, has resulted in the exposure of data belonging to over 23 million accounts. According to Fox News β Tech, the incident became public after stolen database files appeared online in July. The breach, which was originally claimed by hackers in March 2026, involves a vast cache of sensitive information that poses significant risks to anyone who has ever utilized the service to earn supplemental income.
The scope of the compromised data is extensive. Analysis by the breach notification service Have I Been Pwned confirms that the leaked files contain more than 23 million unique email addresses. Beyond simple contact information, the dataset includes full names, telephone numbers, physical addresses, and birth dates. Perhaps more concerning for users is that the leak reportedly contains banking details, payout histories, and transaction records. Additionally, the files include metadata such as IP addresses, device information, and passwords protected by bcrypt hashing, which, while robust, can still be vulnerable to brute-force attacks depending on password complexity.
Paidwork has acknowledged the severity of the situation and confirmed they are currently working with external cybersecurity experts to investigate the intrusion. The company is in the process of implementing security measures to safeguard existing accounts and is reportedly notifying affected individuals. Users who have interacted with the platform should remain vigilant against phishing attempts or suspicious communications that may utilize this leaked information to target them for identity theft or financial fraud.
Reader Discussion & Insights