Paidwork Data Breach Exposes 23 Million Users’ Banking and Personal Data

A massive data breach has hit Paidwork, a popular gig economy platform, exposing sensitive banking and personal information belonging to more than 23 million users worldwide.

The incident, first surfacing in March 2026 when hackers listed the stolen data for sale, escalated significantly in July when nearly 11GB of the compromised dataset was leaked publicly on dark web forums.

According to Have I Been Pwned, threat actors initially claimed responsibility for breaching Paidwork’s systems in March 2026, putting the stolen database up for sale.

The situation worsened in July when the same dataset containing over 23 million unique email addresses appeared freely available online, as flagged by Dark Web Intelligence on X/Twitter.

Paidwork operates as a gig economy platform connecting freelance workers with clients, meaning the exposed data spans both personal identity information and sensitive financial records tied to worker payouts.

What Data Was Exposed

The leaked dataset reportedly includes a wide array of personal and financial information:

  • Bank account numbers and financial transaction records
  • Dates of birth and genders
  • Device and IP address information
  • Education levels and personal interests
  • Email addresses and phone numbers
  • Names and physical addresses
  • Payout history for gig workers
  • Profile photos
  • Passwords, stored as bcrypt hashes

While bcrypt hashing offers stronger protection than plaintext storage, it doesn’t make passwords immune to cracking, particularly for users with weak or reused credentials.

The combination of banking details and rich personal profiles makes this breach particularly dangerous. Unlike breaches limited to just email addresses or passwords, this incident hands attackers everything needed for targeted phishing campaigns, financial fraud, and identity theft.

Payout history and bank account numbers are especially valuable to cybercriminals, who could use this data to impersonate Paidwork or intercept future payments to gig workers.

The exposure of device and IP information also raises concerns about account takeover attempts, as attackers could potentially use this data to bypass certain security checks that rely on recognizing familiar devices or locations.

You can also check whether your personal information has been exposed in data breaches by visiting Have I Been Pwned.

What Affected Users Should Do

If you have a Paidwork account, security experts recommend taking these steps immediately:

  • Change your Paidwork password and any other accounts using the same credentials
  • Enable two-factor authentication wherever available
  • Monitor bank accounts and payout histories for unauthorized transactions
  • Watch for phishing emails referencing your Paidwork profile details
  • Consider a credit freeze or fraud alert if banking data was linked to your identity

 Strengthen Your SOC by Accelerating Threat Detection & Rapid Investigations. -> Integrate ANY.RUN With Your SOC Now.

The post Paidwork Data Breach Exposes 23 Million Users’ Banking and Personal Data appeared first on Cyber Security News.