ShellCodeX
Tools โ€ข Events โ€ข News โ€ข Insights
ShellCodeX Breach Report

Paidwork Data Breach

paidwork.com
Major exposure
Verified breach Passwords exposed
Accounts exposed 23,272,765
Breach date 29 Mar 2026
Added to tracker 19 Jul 2026
Data classes 14

What happened

In March 2026, hackers claimed they had obtained data from the gig economy platform Paidwork which they then listed for sale. Almost 11GB of data allegedly obtained from the platform was subsequently posted publicly in July and contained over 23M unique email addresses. The breach also included a broad range of other data relating to the operation of the platform including user profile data, banking information, payout history for workers and passwords stored as bcrypt hashes.

Exposed data

Bank account numbers Dates of birth Device information Education levels Email addresses Financial transactions Genders IP addresses Names Passwords Personal interests Phone numbers Physical addresses Profile photos

Recommended actions

  • Change your Paidwork password immediately, and update it anywhere you reused the same password.
  • Enable two-factor authentication on the affected account and on your critical services (email, banking).
  • Watch for targeted phishing emails referencing Paidwork โ€” attackers weaponise breach data quickly.
  • Monitor your bank and card statements closely and consider requesting a card replacement.
  • Stay alert for smishing (SMS phishing) and SIM-swap attempts using your phone number.
Am I affected? Check whether your email address appears in this breach.
Check on HIBP