A Microtask Platform's Data Finally Surfaces on HIBP
On July 19, 2026, the gig economy platform Paidwork was added to Have I Been Pwned (HIBP), the widely used breach notification service that lets people check whether their personal information has been exposed. The listing confirmed what security researchers had been tracking for months: an 11 GB database containing records for 23,272,765 unique users had been compiled and circulated, apparently stemming from a breach first claimed back in March 2026.
Paidwork operates as a microtask platform, connecting users to short, gig-style jobs, often paid out through digital wallets or bank transfers. That payment infrastructure is precisely what makes this breach more concerning than a typical email-and-password leak. When hackers first claimed to have obtained Paidwork's data, they listed it for sale on cybercrime forums. By the time it reached HIBP months later, the dataset had been verified and made searchable, meaning affected users can now check their own exposure directly.
What Data Was Exposed
The Paidwork breach is notable for the sheer scale, over 23 million unique user records, and for the categories of information involved. Reporting on the incident indicates the leaked data included full names, email addresses, phone numbers, account passwords, and financial or banking details tied to user payouts. For a platform built around paying real people for completed tasks, that financial data component raises the stakes considerably compared to breaches that expose only login credentials.
This combination of contact information, authentication data, and financial details creates a particularly useful package for criminals running phishing campaigns, credential stuffing attacks, or targeted financial fraud. Our earlier coverage of the Paidwork breach detailed how the nearly 11GB dataset put millions of users' emails and banking information directly into the hands of attackers, a scale that puts this incident among the larger platform breaches disclosed in 2026.
Why the Timeline Matters
One detail worth understanding is the gap between when the breach reportedly occurred and when it became publicly searchable. Hackers claimed to have Paidwork's data as early as March 2026, listing it for sale before it was formally added to HIBP in July. That four-month window is significant: it represents a period during which stolen data may have already been changing hands among criminal buyers, long before most affected users had any way of knowing their information was compromised.
This pattern isn't unique to Paidwork, but it underscores a persistent challenge in breach response. Verification, negotiation with breach notification services, and public disclosure all take time, while the underlying data may already be in circulation. For users of any platform that handles payment information, this is a reminder that breach notifications often arrive well after the actual exposure.
What This Means For You
If you have ever used Paidwork, or a similar microtask or gig platform, treat this breach as a prompt to review your account security posture broadly, not just for this one service. Start by checking your email address against HIBP to confirm whether your data appears in the Paidwork listing. If it does, assume that your password, phone number, and any financial details tied to that account may be in the hands of people who did not have your permission to access them.
Because financial data was reportedly part of this leak, monitor your bank statements and payment accounts for unfamiliar transactions in the weeks ahead. Also watch for an uptick in phishing emails or text messages that reference Paidwork specifically, since attackers often use breached platform names to make scam messages look more credible.
Practical Steps to Take Now
A breach of this size means individual vigilance matters more than ever. Here's what to prioritize:
- Change your Paidwork password immediately, and update it anywhere else you may have reused it. Password reuse is one of the easiest ways a single breach turns into multiple compromised accounts.
- Enable two-factor authentication wherever it's offered, particularly on email and financial accounts, since a leaked password alone shouldn't be enough to grant access if a second factor is required.
- Check Have I Been Pwned directly to see if your email appears in the Paidwork dataset, and consider setting up ongoing breach monitoring for your primary addresses.
- Be skeptical of unsolicited messages referencing Paidwork, gig payments, or account verification requests, since these are common vectors for follow-up phishing attempts after a breach becomes public.
- Review your bank and payment app activity regularly over the coming months, not just immediately after the news breaks, since stolen financial data can be used well after initial disclosure.
The Paidwork breach is a reminder that platforms handling both personal identity data and financial payouts carry outsized risk when security fails. Taking a few minutes now to update passwords, enable stronger authentication, and monitor your accounts can meaningfully reduce your exposure to the fallout from this incident.




