Briev
Live
Technology

Paidwork data breach exposes personal and financial details of over 23 million users

A leak of Paidwork's database has made personal, financial and login information of more than 23 million accounts publicly available.

In March 2026, attackers announced they had obtained a large dataset from Paidwork, a platform that pays users for completing small online tasks. Approximately 11 GB of the data appeared publicly in July, prompting the breach-tracking site Have I Been Pwned to add the incident to its database on July 19, where it counted more than 23 million distinct email addresses. The leaked files also contain users' names, phone numbers, physical addresses, dates of birth, education levels, gender, profile photos, personal interests, bank account numbers, transaction histories, device IPs and bcrypt-hashed passwords.

Paidwork confirmed it is working with outside security specialists to investigate and will inform users as needed. Security experts warn that the information could be used for credential-stuffing attacks, sophisticated phishing, and fraud, especially if victims reuse passwords or have linked bank accounts. Users are advised to change passwords, enable two-factor authentication and monitor financial accounts closely.

Why it matters

The breach puts millions of everyday users at risk of fraud and identity theft due to exposed personal and banking data.

In this story

Paidworkdata breachbank account numberspassword hashescredential stuffingphishingHave I Been Pwnedcybersecurity