A database containing the personal and financial records of 23,272,765 Paidwork users has been dumped on the open internet, according to breach notification service Have I Been Pwned. The leak, which traces back to an intrusion in March, was publicly released earlier this month after circulating in cybercrime circles for months.
The incident adds Paidwork to a growing list of gig economy platforms that have failed to protect the very workers who earn pennies per task. For users who signed up hoping to make spare change from surveys and mobile games, the breach may have handed attackers the keys to their entire digital identity.
What the Leaked Database Contains
The exposed data goes far beyond the usual email and password combination. According to the breach listing, the 11 GB dump includes:
- Bank account numbers and financial transaction records
- Phone numbers, physical addresses, and dates of birth
- Profile photographs and education levels
- IP addresses and device information
- Payout histories and referral data
- Passwords stored as bcrypt hashes
While bcrypt hashing makes bulk password cracking significantly slower than older methods like MD5, users with weak or reused passwords remain at risk. Attackers with sufficient time and resources can still recover credentials through targeted brute force, especially for common passwords.
How the Data Surfaced
The database first appeared in April on a popular cybercrime forum, where a user going by the handle "HACKFORMETOME" advertised the dump. The seller claimed it came straight from Paidwork's production systems and initially tried to auction it through Telegram and Tox, messaging platforms favored by cybercriminals for their encryption and anonymity.
After failing to sell the database privately, the attacker released it publicly. Troy Hunt, the security researcher behind Have I Been Pwned, added the incident to his breach notification service earlier this month, confirming the scale of the exposure.
Paidwork's Silence
As of this writing, Paidwork has not publicly acknowledged the breach. The company did not respond to requests for comment on the authenticity of the data or what steps it has taken to notify affected users. This silence leaves millions of gig workers in the dark about whether their information has been compromised.
Paidwork operates a microtask platform where users earn money by watching ads, testing apps, completing surveys, and referring friends. Most tasks pay only a few cents, and workers must accumulate at least $10 before they can cash out. The platform attracts users in developing economies and among students looking for side income, demographics that may lack the resources to recover from identity theft.
What Users Should Do Now
Anyone with a Paidwork account should act immediately, even if they have not received a notification from the company. Security experts recommend three urgent steps:
- Change your password on Paidwork and any other site where you reused it
- Monitor bank and payment accounts for unauthorized transactions
- Watch for phishing emails that reference personal details from the breach, such as your address or payout history
The risk is not theoretical. Attackers can combine data points from this leak to craft highly convincing phishing messages, impersonating banks, payment processors, or even Paidwork itself.
The Bigger Picture for Gig Workers
This breach highlights a structural problem in the gig economy. Platforms like Paidwork collect vast amounts of sensitive data from workers who have little bargaining power and even less recourse when things go wrong. Unlike traditional employers, these companies often operate across jurisdictions with weak data protection enforcement, leaving users to clean up the mess when security fails.
The timing is notable. Regulators in the European Union and several U.S. states have tightened breach notification laws, yet many microtask platforms fly under the radar until an incident forces them into the spotlight. Paidwork's apparent decision to stay silent, if it continues, could draw scrutiny from data protection authorities.
For now, the 23 million affected users are left to protect themselves. The few cents they earned per task could end up costing them far more in time, stress, and potential financial loss.
Watch for whether Paidwork breaks its silence in the coming days, and whether regulators step in to force accountability.