Paidwork leak reportedly exposed personal and banking data for 23 million users
THE BRIEF
The intrusion was reported to have occurred in March 2026, with an 11-gigabyte database advertised the following month and later released publicly. Paidwork had not confirmed the incident when the independent reports were published. That absence means the dataset’s origin and every listed field cannot be treated as company-verified. The exposure is especially consequential because users joined the service to earn small amounts through surveys, games and online tasks but may have supplied extensive identity and payment information. Bcrypt makes password recovery harder, but weak or reused passwords can still create risk. The core dataset is independently documented, while precise authenticity and company response remained unresolved. For affected people, the practical response should follow confirmed notices rather than speculation. Organizations should preserve records, identify responsible owners and communicate clearly about the known scope. Individuals should use official contact channels, review relevant accounts or devices and be cautious of follow-up messages that exploit publicity around the incident.
WHY IT MATTERS
People seeking small supplemental earnings may accept a poor trade-off between payment and privacy without realizing how durable the information becomes. A few cents earned from a task can leave bank details, addresses and identity information exposed for years. Criminals can combine these fields for targeted phishing, credential stuffing and false account recovery. Platforms collecting financial information should minimize fields and explain retention clearly. Users should isolate low-value services from important accounts by using unique passwords and, where possible, separate payment details.
WHO SHOULD CARE
Paidwork users, gig workers, families sharing devices and banks monitoring account takeover should care. The reported dataset combines contact, identity and financial information that could make later scams convincing even if password hashes are not immediately cracked.
WHAT TO DO NOW
- Change any password reused on Paidwork, starting with email and financial accounts.
- Enable multifactor authentication on email, banking and other accounts linked to the same address.
- Monitor the bank account supplied to Paidwork for unexpected transfers or verification attempts.
- Check Have I Been Pwned using the email address associated with the service.
- Treat messages mentioning Paidwork earnings, payouts or breach compensation as potential phishing.
VERIFICATION NOTE
Partially verified through matching reports from Malwarebytes, The Register and Have I Been Pwned’s dataset listing. The reported record count and data fields are independently documented, but Paidwork had not publicly confirmed the breach when those reports appeared. The brief therefore attributes the database to Paidwork and does not claim every record or field was independently authenticated.