Jul 24, 2026 · 5 min read
Paidwork Breach Exposes Bank Data of 23 Million Users
A database stolen from Paidwork in March 2026 surfaced on a cybercrime forum in April and became public on July 19, when Have I Been Pwned confirmed the breach hit more than 23 million accounts, according to Help Net Security and Malwarebytes. The 11GB file includes bank account numbers, government ID details, and bcrypt hashed passwords tied to the widely downloaded microtask app.
Paidwork pays users a few cents at a time to watch ads, test mobile apps, and fill out surveys, the kind of task built around idle minutes and small rewards. Signing up meant handing over a full name, home address, date of birth, and a bank account number so Paidwork could send the payout. That trade, pocket change for a bank account number, just got expensive for more than 23 million people.
A threat actor using the alias hackformetome first advertised an 11GB database on a cybercrime forum in April 2026, claiming it came from an intrusion into Paidwork's production systems the previous month. The file sat there largely unnoticed until Have I Been Pwned added it to its breach database on July 19, confirming 23,272,765 exposed accounts, according to reporting from Help Net Security and Malwarebytes. Paidwork has not issued a public statement acknowledging the incident.
Key Takeaways
- Have I Been Pwned confirmed the Paidwork breach on July 19, 2026, cataloging 23,272,765 exposed accounts.
- The stolen 11GB database was first advertised on a cybercrime forum in April 2026 by a threat actor using the alias hackformetome, a month after the initial March 2026 intrusion.
- Exposed records include bank account numbers, transaction history, dates of birth, home addresses, phone numbers, education details, and bcrypt hashed passwords, according to Malwarebytes.
- Paidwork, a widely downloaded microtask app, has not publicly acknowledged the breach as of this writing.
- At 23.3 million accounts, the Paidwork breach alone exceeds the combined total of two other breaches reported this month: AssuranceAmerica's 6.9 million driver's license records and KDDI's 14 million email logins.
What Happened in the Paidwork Breach?
Attackers breached Paidwork's backend systems in March 2026, then quietly resold the stolen data a month later instead of dumping it for free. According to Help Net Security's review of the leaked file, the intrusion reached Paidwork's production database directly rather than a third party vendor or a misconfigured storage bucket, the kind of root cause behind many of 2026's larger breaches. The roughly 11GB database first surfaced for sale on a cybercrime forum in April, priced for buyers rather than leaked for free, a sign the seller expected the banking data inside to hold real resale value. It took three more months before the file reached Have I Been Pwned and the breach went public, a gap that gave attackers a running head start against anyone whose bank account number and identity profile sat inside it.
What Data Did Paidwork Lose?
The database goes well beyond an email and password pair, according to Malwarebytes' analysis, handing an attacker nearly everything needed to impersonate a user at their own bank. The leaked fields include:
- Bank account numbers and transaction records
- Full names, home addresses, and phone numbers
- Dates of birth, gender, and education level
- Device details and IP addresses
- Profile photos and stated personal interests
- Passwords stored as bcrypt hashes
Bcrypt hashing means the passwords are hard to reverse directly, but everything else on that list is already plaintext and permanent. A password can be reset in seconds. A bank account number cannot.
Why Did a Microtask App Need This Much Data?
Paidwork asked for banking details and a full identity profile to pay out rewards that typically amount to small fractions of a dollar per completed ad view or survey. The platform needs to verify who it is paying and where the money goes to make that model work, which is why signup asks for a bank account number, a birth date, and a home address up front. The mismatch is stark: a service built around minutes of low value work ended up sitting on a dataset valuable enough that a cybercriminal chose to sell it on a forum rather than give it away. That imbalance between a trivial reward and a valuable dataset is a pattern GBHackers' analysis of the breach flagged directly, and it applies to any company collecting financial verification data for small, frequent payouts.
Why Email Users Should Care
An email address paired with a real name, home address, and bank account number is exactly the ammunition phishing campaigns need to feel legitimate. Generic phishing gets caught by spam filters and healthy skepticism. A message that references your actual bank, your correct home address, or the right last four digits of an account number is a different problem, and it is exactly the kind of pretext scammers build from breach data like this.
Expect Paidwork's 23 million exposed email addresses to show up in targeted phishing and smishing campaigns over the coming months. Malwarebytes specifically urges affected users to prepare for phishing attempts built from this data, since email is the most common delivery channel for exactly that kind of follow on attack. Anyone who reused a Paidwork password on their email account should treat that inbox as compromised until proven otherwise, since email access is usually the master key attackers use to reset everything else.
What Should Affected Users Do Right Now?
Anyone who signed up for Paidwork should assume their bank details are already circulating and act accordingly:
- Change your Paidwork password immediately, and change it anywhere else you reused it, since bcrypt hashing slows attackers down but does not stop them.
- Turn on two factor authentication for your email and banking accounts, the two services attackers pivot to first after a breach like this.
- Monitor bank statements and transaction alerts closely for the next several months, not just the next few weeks.
- Treat unexpected texts or emails referencing Paidwork, your bank, or your personal details as phishing attempts until you verify them independently.
- Check your exposure through Have I Been Pwned or Malwarebytes' Digital Footprint Scanner, and consider identity theft protection if your bank account number was included.
Password reuse is what turns one breach into ten. If a Paidwork password overlaps with credentials already circulating in unrelated stealer log dumps, like the 24 billion credentials exposed in an infostealer dump reported in June, that overlap is exactly what automated credential stuffing tools are built to exploit.
Sources: Help Net Security, Malwarebytes, GBHackers, and Have I Been Pwned.