Here's the complete intel brief:
title: "Paidwork: 23 Million User Records Exposed in March Intrusion" date: 2026-07-20 slug: paidwork-data-breach-23m
Paidwork: 23 Million User Records Exposed in March Intrusion
Gig-economy platform Paidwork has suffered a major data breach exposing more than 23 million unique user email addresses alongside banking details and payout histories, confirmed on July 19, 2026 by breach notification service Have I Been Pwned (HIBP). Attackers claim they obtained and sold the dataset on March 23, 2026, before releasing the nearly 11GB archive publicly in July.
What Happened
Hackers claim to have compromised Paidwork's platform data and put it up for sale on March 23, 2026. Initial claims referenced roughly 22 million stolen addresses, a figure that grew as the full dataset surfaced. In July 2026, the actors released the complete archive publicly, and HIBP ingested and confirmed the breach on July 19. The leaked archive totals almost 11GB and contains 23,272,760+ unique email addresses tied to Paidwork users. The roughly four-month gap between the initial intrusion and public disclosure means affected users spent months exposed before any confirmation reached them.
What Was Taken
The breach is notable for its breadth, spanning platform operations from user profiles to financial transactions. According to HIBP, the exposed data includes:
- Bank account numbers
- Financial transactions and payout histories
- Dates of birth
- Names, genders, and phone numbers
- Physical addresses
- Email addresses
- Passwords stored as bcrypt hashes
- IP addresses and device information
- Education levels and personal interests
- Profile photos
Passwords were stored as bcrypt hashes rather than plaintext, which offers strong resistance to modern brute-force cracking. However, the combination of financial, personal, and behavioral data is what makes this leak dangerous. Bank account numbers and payout histories cannot be rotated the way a password can.
Why It Matters
Most gig-economy breaches leak contact information and credentials. Paidwork's exposure goes further by including full banking details and worker payout histories, giving fraudsters a ready-made profile for financial targeting. The breach echoes prior incidents such as the 2016 Uber breach affecting roughly 57 million users and the 2019 DoorDash breach, but the financial depth here raises the stakes for every affected worker. With 23 million records in circulation, defenders should expect a wave of targeted phishing, account takeover attempts, and financial fraud built on validated, real-world data.
The Attack Technique
The specific intrusion vector has not been disclosed. What is known is the timeline: the actors claimed possession and sale of the data on March 23, 2026, then released it publicly in July. The presence of bcrypt-hashed passwords indicates the attackers accessed backend credential storage, consistent with a database-level compromise rather than a scrape of public-facing profile pages. The breadth of fields, from device information to bank account numbers, points to access to core platform database tables rather than a single limited endpoint.
What Organizations Should Do
- Reset credentials and force re-authentication for any account that reused a Paidwork password, and treat all exposed accounts as compromised despite the bcrypt hashing.
- Monitor for targeted phishing and financial-fraud campaigns that leverage the leaked banking and payout data to impersonate the platform or financial institutions.
- Enroll affected users in credit and bank-account monitoring, since bank account numbers and transaction histories cannot be rotated.
- Audit database access controls, segment credential storage, and review logs back to March 2026 for signs of unauthorized bulk data access.
- Enforce multi-factor authentication across user and administrative accounts to blunt account-takeover attempts built on leaked credentials.
- Have users check their exposure through HIBP by entering the email tied to their Paidwork account, and communicate proactively rather than waiting for users to discover the leak themselves.
Sources: Paidwork Data Breach: 23M+ Emails and Financial Data Exposed - TechNadu