A data breach linked to Paidwork, an online microtask platform that pays users for completing surveys and testing apps, has exposed records tied to more than 23 million accounts. The disclosure has drawn concern because the leaked material reportedly reaches far beyond email addresses and includes bank account details, names, addresses and other personal information.
Have I Been Pwned, a breach notification service that tracks data leaks, said it had analyzed files connected to the platform and identified more than 23 million unique email addresses. The service added the incident to its database on July 19. Attackers first claimed in March that they had obtained Paidwork data, and a file of nearly 11 GB allegedly taken from the platform appeared publicly in July.
Paidwork said it is actively investigating the reported breach, working with external security specialists and taking steps to protect affected accounts and notify users as appropriate.
According to the analysis, the exposed dataset includes names, phone numbers, physical addresses, dates of birth, education levels, gender, profile photos and personal interests. The files also reportedly contain bank account numbers, transaction information and payout histories, as well as device information and IP addresses. Password data is said to be stored in bcrypt hashes, a method that is more resistant to cracking than weaker formats, although short or predictable passwords can still be at risk.
The scale of the leak matters because Paidwork accounts can hold low balances but are linked to real identity and banking data. Security experts say criminals can combine details such as a user's address and payout history to make phishing messages look convincing. A fraudster might send an email that references a real payment before claiming a bank transfer failed, or use a stolen address to lend credibility to a fake security alert.
Another major risk is password reuse. If attackers succeed in cracking a Paidwork password, they can try that same password on banking portals, email providers and social networks, a technique known as credential stuffing. A compromised email address is particularly dangerous because it can be used to reset passwords for other services. Bank account numbers and transaction histories also provide useful material for convincing fraud attempts.
Those who have used the platform are advised to change passwords for Paidwork and any other services where the same password was reused, and to secure email and financial accounts first. Since the leaked records may appear in public breach databases, users can check the email address they used on the platform through the Have I Been Pwned service, but should only use the official website. Criminals sometimes create fake breach-checking pages designed to harvest additional personal details, and no legitimate breach search tool will ask for a password or bank details.
Experts also recommend reducing the amount of personal data shared with side-income platforms. Before signing up, users should review what information the company collects and whether old payout methods or profiles can be deleted after an account is closed. Optional profile fields should be left blank when possible. Connecting a primary bank account to a service used only occasionally carries extra risk, and a separate account or payment method may be safer.
The Paidwork incident is listed by Have I Been Pwned as affecting 23.3 million accounts. A check that returns no results does not necessarily mean an email address is safe, because public breach databases can be incomplete. As with any significant data exposure, the priority is to stop password reuse, secure primary accounts and limit the amount of sensitive information available to attackers.
