← BACK TO FEED
data breachPaidworkHave I Been Pwnedcybercrimeinfosec

23 Million Paidwork Users' Data Dumped Online After Alleged March Breach

A data breach at microtask platform Paidwork has exposed the personal and financial information of over 23 million users, with a stolen 11 GB database first advertised on a cybercrime forum in April and later added to Have I Been Pwned in July. The leaked data is extensive, including bank account numbers, passwords, addresses, transaction records, and more, with the breach traced back to an intrusion in March. Paidwork has yet to publicly acknowledge the incident or respond to press inquiries, leaving affected users advised to change passwords, monitor their finances, and watch for phishing attempts.

A database reportedly stolen from microtask platform Paidwork has been dumped publicly online, exposing the personal and financial details of more than 23 million users. The breach was added to Troy Hunt's Have I Been Pwned service on July 19, covering 23,272,765 accounts tied to an intrusion that allegedly occurred back in March.

The stolen data first appeared in April, when a threat actor operating under the handle "HACKFORMETOME" posted what they described as an 11 GB production database dump on a cybercrime forum. The seller initially tried to auction it via Telegram and Tox, claiming records on over 22 million users.

The final tally, per Have I Been Pwned, is slightly higher. And the contents are grim. Beyond the usual names and email addresses, the exposed records reportedly include bank account numbers, phone numbers, home addresses, dates of birth, profile photos, IP addresses, device data, financial transaction histories, payout records, education levels, and passwords hashed with bcrypt.

Bcrypt is a decent algorithm, better than the MD5 and SHA-1 disasters we've seen in countless other breaches, but it's not magic. Weak or reused passwords remain crackable with enough patience and computing power.

For context, Paidwork is the kind of platform that pays users a few cents to play mobile games, watch ads, fill in surveys, test apps, or shop through cashback links. You need to accumulate at least $10 before you can withdraw anything. The irony of a platform built around penny-by-penny earnings now leaking users' bank account details is not lost.

At the time of writing, Paidwork has said nothing publicly about the alleged breach. The Register reached out for comment and got silence.

If you have an account, assume the worst. Change your password everywhere you reused it, watch your financial accounts closely, and treat any incoming emails as potentially crafted from a detailed profile of your personal life, because they might be.

READ NEXT
Dutch Police Nab Suspect Who Repeatedly Hacked Ajax Amsterdam's IT SystemsOne Hacker, Eight Dental PCs, and Google's Own AI Running the OperationEY Breach Exposes Client Tax Data Including SSNs and Card Numbers