Paidwork data leak added to Have I Been Pwned with 23.3M users listed
Have I Been Pwned says an alleged Paidwork breach exposed personal, financial and account data tied to 23,272,765 users.
By Dominic Okoye · Staff Writer
· 3 min read
Have I Been Pwned has added an alleged Paidwork breach affecting 23,272,765 users after a database said to come from the microtask platform was published online. The listing matters because the exposed records reportedly include not only account identifiers, but bank account numbers, transaction data and payout histories tied to people using the service to earn small sums from online tasks.
Troy Hunt’s breach notification service says the incident traces back to an intrusion in March. The data was added to Have I Been Pwned on July 19, after the alleged database was publicly released earlier in the month.
The first public sign of the dataset appeared in April, when a user going by “HACKFORMETOME” advertised what they claimed was an 11 GB dump from Paidwork’s production systems on a cybercrime forum. The seller claimed at the time that the database included more than 22 million user records and tried to sell it through Telegram and Tox, according to the account of the incident.
What data is reportedly exposed
According to Have I Been Pwned, the compromised fields go well beyond the usual email-and-password breach set. The listing says the exposed data includes names, email addresses, phone numbers, physical addresses, dates of birth, profile photographs, IP addresses and device information.
The financial exposure is the sharper issue for users. Have I Been Pwned says the dataset also contains bank account numbers, financial transaction records and payout histories. Education levels are also listed among the exposed fields.
Passwords were reportedly stored as bcrypt hashes. That is better than storing passwords in plaintext or with weaker legacy hashing methods, but it does not eliminate risk. Users who chose weak or reused passwords may still be exposed if attackers crack individual hashes and test those credentials on other services.
Paidwork has not publicly confirmed the breach
Paidwork had not publicly acknowledged the alleged breach at the time it was reported. The Register said it asked the company to confirm whether the leaked database was authentic and to detail any user notification steps, but did not receive an immediate response.
That leaves several material questions unanswered: whether the data is complete, whether the March intrusion date is accurate, what systems were accessed, whether bank account data was protected in any additional way, and whether affected users have been directly notified. No remediation plan, regulatory notice or forensic summary has been disclosed by the company in the available reporting.
Paidwork markets a consumer gig platform where users can earn money by completing small online activities, including playing mobile games, watching ads, filling out surveys, testing apps, shopping through cashback offers and referring other users. Individual tasks often pay only a few cents, and users must reach at least $10 before cashing out.
For a platform built around low-value payouts, the alleged breach creates a disproportionate security problem for users. Anyone who reused a Paidwork password should change it on every site where it appears, monitor bank and payout accounts, and treat unsolicited messages referencing Paidwork account details as potential phishing attempts.
This story draws on original reporting from The Register.