Paidwork: 23 million accounts from the microtask platform dumped on a cybercriminal forum - radio silence from the publisher

Cybersecurity 13 h agoAdd to bookmarks

Paidwork: 23 million accounts from the microtask platform dumped on a cybercriminal forum - radio silence from the publisher
Illustration : Momiji Shirogane

A 11 GB dump containing the data of over 23 million Paidwork users was put up for sale on a hacking forum and then added to Have I Been Pwned on July 19, 2026. Bank accounts, addresses, dates of birth, and bcrypt: the inventory is heavy. Paidwork has yet to react publicly.

The facts

Paidwork is an online microtask platform (playing mobile games, watching ads, answering surveys, testing apps, cashback, referral) monetizing the attention and time of its users. According to Have I Been Pwned (HIBP), which added the breach to its database on July 19, 2026, a dump concerns 23,272,765 users.

Chronology reconstructed by The Register from the actor's announcements:

  • March 2026: effective breach (date declared in the HIBP file).
  • April 2026: the database is publicly put up for sale on a cybercriminal forum.
  • July 19, 2026: integration into HIBP.

The seller, under the pseudonym HACKFORMETOME, put the 11 GB dump up for sale on a hacking forum and attempted to monetize it via Telegram and Tox. No individual researcher is named as the discoverer; The Register indicates that Paidwork had not responded to its solicitations at the time of publication.

What is exposed

According to HIBP:

  • Bank account numbers
  • Phone numbers
  • Physical addresses
  • Dates of birth
  • Profile photos
  • IP addresses
  • Device information
  • Financial transaction and payout history
  • Education level
  • Passwords in bcrypt hash

The analysis

The only somewhat reassuring point in this dump is the storage of passwords in bcrypt (with a correct cost, bcrypt remains resistant to offline brute force for non-trivial passwords). Everything else is catastrophic. The combination date of birth + physical address + phone number + bank statement + payout history constitutes a ready-to-use identity theft kit, particularly for:

  • Account takeovers (call banks, SIM swap on the exposed number).
  • Hyper-personalized phishing targeting with proof of knowledge of the real account.
  • Fraud to the detriment of third parties with complete identity theft.

The fact that a database has been publicly for sale since April 2026 and that the platform has not communicated by the publication date is at least a moral failing, potentially legal depending on the jurisdictions of the users concerned (GDPR article 34: notification to the persons concerned "without undue delay" in case of high risk).

What to do now

If you have a Paidwork account or have had one:

  1. Check on HIBP: haveibeenpwned.com - enter the email used.
  2. Change the password everywhere it was reused (especially if you were not using a manager).
  3. Enable MFA everywhere possible, not SMS (prefer TOTP or passkey) - the exposed number makes SIM swap plausible.
  4. Monitor attempts at bank fraud; consider a credit freeze depending on the jurisdiction.
  5. Phishing vigilance: the coming months will see credible emails and SMS circulating using the exposed data.

For security teams: integrate the dump into threat intel identity monitoring flows if employees are listed (the social engineering kit against them becomes much more dangerous).

Resources, try it

Article produced by artificial intelligence, reviewed under human editorial control.

Our newsroom
Was this article helpful?

20 people liked this article

Like
K
Kenji AraiCybersecurity expert
Cybersecurity expert, methodical watcher, never alarmist, always actionable.
Share:
LIVERadio Geek Kitsune
Tap to listen, the same sound for everyone
0··
// Schedule
// all stations
// share a track →
Topics
Explore
Information