Paidwork Data Breach Confirmed at 23 Million Records
A Paidwork data breach that first surfaced on cybercrime forums earlier this year has now been formally verified. Have I Been Pwned (HIBP), the widely used breach-notification service, added the incident to its database on July 19, confirming that 23,272,765 user records were compromised. The confirmation closes the gap between early speculation and verified fact, giving affected users a reliable way to check whether their information was involved.
According to reporting on the incident, the intrusion itself occurred in March 2026, though the stolen data didn't appear publicly until April. At that time, a threat actor using the alias "hackformetome" advertised the trove on a well-known cybercrime forum, describing it as an 11GB dump pulled directly from Paidwork's production systems. The original listing claimed more than 22 million affected users; HIBP's confirmed figure now sits slightly higher, at just over 23.27 million.
Inside the Paidwork Data Dump
Paidwork is a gig-economy platform where users complete small tasks in exchange for payment, which means the data collected on its systems goes well beyond basic account details. Reporting on the leak indicates the exposed dataset included banking and payment information alongside standard account records, a combination that raises the stakes considerably compared to a typical email-and-password leak. As covered in earlier reporting on the Paidwork breach that leaked emails and banking data, the presence of financial details in the dump makes this incident particularly attractive to fraud-focused criminals rather than just spam operations.
The roughly four-month gap between the actual intrusion in March and HIBP's public confirmation in July is worth noting. That window gave the data time to circulate on forums, get scraped by other actors, and potentially get folded into larger combined credential lists before most users even knew their information was at risk. This is a recurring pattern in breach timelines: the initial theft, the underground sale, and the eventual public confirmation rarely happen close together, which is exactly why proactive monitoring tools like HIBP matter.
Why Banking Data in a Breach Changes the Calculus
Most breach coverage focuses on passwords, and for good reason, since password reuse remains one of the biggest drivers of account takeover. But when banking or payment information is part of the exposed dataset, the risk profile shifts from "someone might log into your old forum account" to "someone might attempt financial fraud using your real payment details." That distinction matters for how seriously users should treat this particular incident compared to lower-stakes leaks.
The detailed breakdown of what data was exposed in the Paidwork leak is a useful reference point for anyone trying to understand exactly what categories of information were included, since not every breach exposes the same fields, and the specifics determine what precautions actually make sense.
What This Means For You
If you have ever used Paidwork, or if you reused a Paidwork password on another account, treat this as a signal to act rather than a reason to panic. Data breaches involving financial information typically lead to a wave of follow-up scams: phishing emails referencing the breach, fake "account verification" texts, or attempts to use leaked banking details directly. None of that requires sophisticated hacking on the criminal's part; it just requires patience and a large enough list of victims to work through.
The good news is that the response to a breach like this is fairly straightforward, even if it takes a bit of effort. Checking whether your email address appears in the confirmed dataset, changing any reused passwords, and keeping an eye on bank statements for unfamiliar activity will address the overwhelming majority of realistic follow-on risks.
Actionable Takeaways
A few concrete steps are worth taking now if you believe you may be affected by this Paidwork data breach:
- Search your email address on Have I Been Pwned to confirm whether your account was part of the confirmed 23.27 million records.
- Change your Paidwork password immediately, and change it anywhere else you may have reused it.
- Monitor bank and payment accounts closely for the next several weeks, since financial data exposure often leads to delayed rather than immediate fraud attempts.
- Enable multi-factor authentication wherever it's offered, particularly on financial and payment-linked accounts.
- Be skeptical of any unsolicited emails or texts referencing Paidwork or account verification, as breach data is frequently reused in follow-up phishing campaigns.
Breaches involving payment data tend to have a longer tail of risk than simple credential leaks, so it's worth staying alert over the coming months rather than treating this as a one-time check. Taking the small, practical steps above now is the most effective way to limit the damage from this incident.




