Paidwork, an online platform that pays users small amounts of money to complete microtasks such as surveys, video-watching, and other short digital jobs, has confirmed to be at the center of a major data breach affecting more than 23 million users. Companies that collect this volume of personal and financial information from everyday users carry a significant responsibility to keep that data secure, and when that security fails, the people affected are the ones left to deal with the consequences.
Paidwork’s Data Breach Investigation
According to public breach reporting, a threat actor using the alias “hackformetome” began advertising an approximately 11GB database on a cybercrime forum in April 2026, claiming the data was pulled directly from Paidwork’s production systems and contained records on more than 22 million users. The stolen database was later posted publicly in July 2026, and cybersecurity researchers subsequently confirmed the leak included more than 23.2 million unique email addresses along with a wide range of other user information. Have I Been Pwned (HIBP), a widely used breach-notification service, added the incident to its database on July 19, 2026, listing the breach date as March 2026 and the number of affected accounts at approximately 23.3 million.
As of this writing, Paidwork has not issued any public acknowledgment or official statement regarding the breach, and no formal notification appears to have been sent directly to affected users through the company itself. Much of what is publicly known about this incident comes from independent security researchers and breach-monitoring services that identified and verified the leaked data rather than from a voluntary disclosure by the company.
Gig-economy and microtask platforms like Paidwork are attractive targets for cybercriminals precisely because they aggregate enormous volumes of sensitive personal and financial information in one place. Users often provide banking details for payouts, government-adjacent identifying information such as dates of birth, and other personal data as part of routine account verification and profile setup. When a platform of this kind is compromised, the exposure can affect not just account credentials but an unusually complete financial and personal profile of each user.
The combination of data types reportedly involved in this breach is especially concerning from a fraud standpoint. Names, email addresses, phone numbers, and home addresses can be combined to enable convincing phishing and social-engineering attacks. Bank account numbers and transaction histories can be used to attempt unauthorized transfers or to build a more complete financial profile for fraud. Dates of birth, gender, and education-level details add further specificity that criminals often use to pass identity-verification checks at other institutions. Even though the passwords involved were reportedly stored as bcrypt hashes — a stronger method than storing plain text — any password reused across multiple sites remains at risk if that hash is ever cracked.
Breaches that surface through dark web monitoring and third-party breach-notification services, rather than through a company’s own timely disclosure, often leave affected individuals without clear guidance on what specifically happened to their information or when. This gap between when a breach actually occurs and when the public becomes aware of it can extend the window during which stolen data circulates unnoticed, increasing the risk of downstream identity theft, account takeover, and financial fraud for those affected long before they receive any formal notice.
When Did This Breach Occur?
Public breach-reporting indicates the underlying intrusion occurred in March 2026. The stolen database first appeared for sale on a cybercrime forum in April 2026, and the full dataset was posted publicly in July 2026. Have I Been Pwned added the incident to its breach-notification database on July 19, 2026, based on the leaked data becoming publicly available. Paidwork itself has not issued a public statement confirming these dates or the scope of the incident.
What Information Was Breached?
The exposed data reportedly includes full names, email addresses, phone numbers, home addresses, dates of birth, gender, and education levels. It also reportedly includes bank account numbers and financial transaction records tied to user payouts, along with device and IP information, profile photos, personal interests, and passwords stored as bcrypt hashes. The scope of this data set is broader than a typical account-credential leak, combining financial, personal, and behavioral information in a single exposed database.
What You Can Do
If you have a Paidwork account, consider taking the following steps to protect yourself:
- Change your Paidwork password immediately, and change it on any other account where you reused the same password.
- Enable two-factor authentication on your Paidwork account and any other accounts that support it.
- Monitor your bank accounts and payout history closely for any transactions you do not recognize.
- Watch for phishing emails or messages that reference your Paidwork account, your name, or other personal details that may have been exposed.
- Consider placing a fraud alert or credit freeze with the major credit bureaus if you believe your financial information was compromised.
- Use a password manager to generate and store strong, unique passwords for each of your online accounts going forward.
File a Data Breach Lawsuit Against Paidwork
If your personal or financial information was exposed as a result of the Paidwork data breach, you may have legal options available to you. Companies that collect sensitive financial and personal data from millions of users are expected to maintain reasonable security safeguards, and when that data is exposed, affected individuals may be entitled to pursue compensation.
Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.