Skip to content
Cyber Security Firms
ConfirmedTechnology

Paidwork Data Breach (July 2026)

The gig economy platform Paidwork had records for 23,272,765 accounts posted publicly in July 2026 after a March intrusion, exposing names, contact details, bank account numbers, payout history and hashed passwords, per the Have I Been Pwned listing.

Disclosed Updated
Organization
Paidwork
Country
International
Incident date
March 29, 2026
Disclosed
July 19, 2026
Records affected
23.3 million
Attack type
Undisclosed
Status
Confirmed
Data exposed
  • Bank account numbers
  • Dates of birth
  • Device information
  • Education levels
  • Email addresses
  • Financial transactions
  • Genders
  • IP addresses
  • Names
  • Passwords
  • Personal interests
  • Phone numbers
  • Physical addresses
  • Profile photos
Timeline
  1. Date of the breach recorded on the Have I Been Pwned listing.
  2. Have I Been Pwned loads the verified records, 23,272,765 accounts in total.
  3. Malwarebytes reports that Paidwork has not publicly acknowledged the breach.

What Happened

Per the Have I Been Pwned entry, hackers claimed in March 2026 that they had obtained data from the gig economy platform Paidwork and listed it for sale. Almost 11GB of that data was subsequently posted publicly in July, and Have I Been Pwned loaded 23,272,765 accounts on July 19, 2026. The listing covers user profile data, banking information, payout history for workers and passwords stored as bcrypt hashes.

Malwarebytes reported on July 22, 2026, in a piece by Pieter Arntz, that the compromised information included full names, email and home addresses, phone numbers, dates of birth, gender, education details, bank account numbers, transaction records, device and IP information, profile photos, personal interests and hashed passwords. According to that report the intrusion happened in March 2026 and the database was first advertised on a cybercrime forum in April.

Malwarebytes reported that Paidwork had not publicly acknowledged the alleged breach. Neither source names a group behind the theft, and neither describes how the platform's production systems were reached, so the method here is undisclosed. The record count used in this report is the exact figure from the Have I Been Pwned listing rather than the rounded 23 million that appears in news coverage of the leak.

What Was Exposed

14 classes of data across 23,272,765 records, per Have I Been Pwned: Paidwork, 23,272,765 breached accounts: bank account numbers, dates of birth, device information, education levels, email addresses, financial transactions, genders, ip addresses, names, passwords, personal interests, phone numbers, physical addresses and profile photos.

Bank account numbers paired with payout history, device and IP data and a hashed password give an attacker both the raw material for financial fraud and a credible script for impersonating Paidwork's payments team to a worker who is expecting money.

What to Do If You Are Affected

The full sequence, and what to do in what order, is in what to do after a data breach.

What Is Not Known Yet

Paidwork has not publicly acknowledged the breach, and no source names the group responsible or explains how its production systems were reached. Nobody has said whether affected users have been contacted or asked to reset passwords.

Sources

  1. Have I Been Pwned: Paidwork, 23,272,765 breached accounts
  2. Malwarebytes: Paidwork breach exposes data of 23 million users: Check if you're affected, by Pieter Arntz, July 22, 2026
On this page
Reviewed by

Daniel Reyes

  • CISSP
  • 12 years in security operations
  • Austin, TX

Daniel Reyes is a CISSP who spent twelve years in security operations, most recently leading a detection and response team for a mid-sized healthcare group in Texas. He reviews every resource and breach report on Cyber Security Firms for technical accuracy before it publishes.

Most of the people he has trained arrived having been told too much: a dozen acronyms, six vendors, and no clear idea which risk was theirs. His approach is to explain what an attack actually does before naming the tool that stops it, on the basis that most breaches start with something a reader could have recognised.

Read the full bio and how we research →