Paidwork breach reportedly exposes data of 23 million users
2026-07-22A database allegedly taken from the microtask/reward platform Paidwork is circulating on cybercrime forums. Reports put the exposure at more than 23 million users and say it includes full names, email and home addresses, phone numbers, dates of birth, bank account numbers, transaction records, device/IP data, and passwords stored as hashes. Paidwork has not publicly confirmed the incident, so treat it as reported rather than verified.
What you should do: If you or anyone on your team ever signed up for Paidwork, change that password there and anywhere you reused it, turn on multi-factor authentication for email and banking, and watch your bank statements and inbox for targeted phishing. Use the self-check tools below to see whether your email shows up in known breach data.
Malwarebytes write-up ↗