• 2 min read
23M Paidwork accounts reportedly exposed online
A leaked database tied to Paidwork reportedly exposes 23,272,765 users, including bank details, payout histories, and hashed passwords.

Image: The Register
More than 23 million Paidwork users may have had personal and financial data exposed after a database allegedly stolen from the microtask platform was dumped online.
According to Have I Been Pwned, which added the incident on July 19, the breach affects 23,272,765 users and traces back to an intrusion in March. The database had surfaced earlier, in April, when a seller using the handle “HACKFORMETOME” posted what they claimed was an 11 GB dump from Paidwork’s production systems on a cybercrime forum. The seller said it contained records on more than 22 million users and tried to auction it via Telegram and Tox.
The breach listing says the exposed data goes far beyond basic account information. It reportedly includes:
- Bank account numbers
- Phone numbers
- Physical addresses
- Dates of birth
- Profile photos
- IP addresses
- Device information
- Financial transaction records
- Payout histories
- Education levels
- Passwords hashed with bcrypt
While bcrypt is significantly harder to crack than older password hashing methods, weak passwords can still be recovered.
At the time of writing, Paidwork had not publicly acknowledged the alleged breach. The Register said it asked the company to confirm whether the leaked data is authentic and explain what steps it has taken to notify affected users, but it had not received an immediate response.

Recommended reading
WordPress bugs are now under attack at scale
Paidwork pitches itself as a way to earn money through small online tasks such as playing mobile games, watching ads, completing surveys, testing apps, shopping through cashback offers, and referring other users. Most jobs pay only a few cents, and users must earn at least $10 before cashing out.
For anyone affected, the immediate risks are broader than account access alone: reused passwords should be changed, financial accounts should be monitored, and phishing attempts may become more convincing with so much personal data now allegedly in circulation.
Security Editor
Sophia unpacks the invisible wars happening on our networks. Covering cybersecurity, privacy legislation, and cryptography, she exposes how our data is weaponized and defended. Before joining for(geeks), she spent years as a penetration tester. She's the reason the rest of the team uses physical security keys.
via The Register


