Paidwork Database Leak Allegedly Exposes 22 Million User Records

A database allegedly stolen from Paidwork has reportedly been released publicly months after it was first advertised for sale, with the breach now listed in Have I Been Pwned.
Screenshot of a cybercrime forum post claiming to publish the full Paidwork database, alleging an 11 GB SQL dump containing approximately 22 million user records, including user, payment, and employee information.
A forum post claims to have publicly released the full Paidwork database after it was previously advertised for sale.

A database allegedly stolen from microtask platform Paidwork has reportedly been released publicly months after it was first advertised for sale on a cybercrime forum, potentially exposing the personal and financial information of millions of users.

The database was initially offered for sale in March 2026, when a threat actor claimed to possess approximately 11 GB of data belonging to the platform. At the time, the claims could not be independently verified. In July, however, another forum post purported to publish the full SQL database, describing it as a “fresh dump” containing roughly 22 million user records.

Public release follows earlier sale listing

According to the latest forum post, the leaked archive is approximately 11 GB and allegedly contains user account information, employee records, payment-related data, email addresses, phone numbers, and passwords stored as bcrypt hashes. The post also claims the database includes information relating to user payouts.

While the exact origin of the leaked data has not been independently confirmed, the public release marks a significant escalation from the earlier sale listing, making the dataset far more accessible if authentic.

Have I Been Pwned adds the breach

Further credibility was added after Have I Been Pwned (HIBP) incorporated the incident into its breach database. According to HIBP, the dataset contains more than 23.2 million unique email addresses and includes user profile information, banking details, payout history, device information, IP addresses, phone numbers, physical addresses, and passwords stored as bcrypt hashes.

HIBP states the breach originated from a March 2026 compromise and that the data was subsequently leaked publicly in July, allowing affected users to determine whether their email addresses were included in the exposed dataset.

Potential risks for affected users

Although bcrypt provides significantly stronger password protection than outdated hashing algorithms, users who reused weak passwords across multiple services may still face credential stuffing or offline password cracking attempts. The reported inclusion of banking information, payout history, contact details, and other personal information also increases the risk of phishing, identity theft, and financial fraud.

Users who have created a Paidwork account should consider changing any reused passwords, enabling multi-factor authentication where available, and monitoring financial accounts for suspicious activity.

No public statement

Paidwork had not issued any public statement regarding the alleged public release of the database at time of publication. While the company has not publicly confirmed the incident, the addition of the dataset to Have I Been Pwned indicates that breach data is now circulating publicly and has been analyzed by the breach notification service.

Picture of m00s3c

m00s3c

Moose (@m00s3c) is the author of BreachNews, focusing on data breach intelligence, dark web monitoring, and threat analysis. His work involves analyzing breach claims, reviewing leaked datasets, and tracking threat actor activity to provide clear, factual reporting.

Latest News

BREACHNEWS.COM/SUPPORT/

Support Independent News.

Help support breach monitoring, investigations, infrastructure, and reporting.

Support the site
INTEL.BREACHNEWS.COM

Live Cyber
Threat Map

Explore live cyber activity, recent breach reports, KEV alerts, and public threat feeds from a single interactive dashboard.

Launch Threat Map