23 Million Paidwork Users' Data Dumped Online After Alleged March Breach
A database reportedly stolen from microtask platform Paidwork has been dumped publicly online, exposing the personal and financial details of more than 23 million users. The breach was added to Troy Hunt's Have I Been Pwned service on July 19, covering 23,272,765 accounts tied to an intrusion that allegedly occurred back in March.
The stolen data first appeared in April, when a threat actor operating under the handle "HACKFORMETOME" posted what they described as an 11 GB production database dump on a cybercrime forum. The seller initially tried to auction it via Telegram and Tox, claiming records on over 22 million users.
The final tally, per Have I Been Pwned, is slightly higher. And the contents are grim. Beyond the usual names and email addresses, the exposed records reportedly include bank account numbers, phone numbers, home addresses, dates of birth, profile photos, IP addresses, device data, financial transaction histories, payout records, education levels, and passwords hashed with bcrypt.
Bcrypt is a decent algorithm, better than the MD5 and SHA-1 disasters we've seen in countless other breaches, but it's not magic. Weak or reused passwords remain crackable with enough patience and computing power.
For context, Paidwork is the kind of platform that pays users a few cents to play mobile games, watch ads, fill in surveys, test apps, or shop through cashback links. You need to accumulate at least $10 before you can withdraw anything. The irony of a platform built around penny-by-penny earnings now leaking users' bank account details is not lost.
At the time of writing, Paidwork has said nothing publicly about the alleged breach. The Register reached out for comment and got silence.
If you have an account, assume the worst. Change your password everywhere you reused it, watch your financial accounts closely, and treat any incoming emails as potentially crafted from a detailed profile of your personal life, because they might be.